VPC Flow Logs Flashcards
1
Q
What are VPC Flowlogs?
A
VPC Flow Logs is a feature that enables you to capture information about the IP traffic going to and from network interfaces in your VPC. Flow log data can be published to Amazon CloudWatch Logs or Amazon S3.
2
Q
Name the three levels that Flow Logs can be created at?
A
- VPC
- Subnet
- Network Interface Level
3
Q
Name the VPC Flow Log Exam Tips
A
- You cannot enable flow logs for VPCs that are peered with your VPC unless the peer VPC is in your accounts.
- You can tag flow logs.
- After you’ve created a flow log, you cannot change it’s config; for example, you can’t associate a different IAM role with the flow log.
- Not all IP traffic is monitored. These are not monitored…
- Traffic generated by instances when they contact Amazon DNS sever. If you use your own DNS server, then all traffic to that DNS server is logged.
- Traffic generated by a Windows instance for Amazon Windoes Licence activation.
- Traffic to and from 169.245.169.254 for instance metadata
- DHCP traffic