Soru

Zorluk: OrtaVPC Flow Logs and Network Monitoring

A SysOps Administrator needs to determine whether application traffic between Amazon EC2 instances in a VPC and an Amazon S3 bucket is routing through an AWS Transit Gateway, an Amazon S3 Gateway Endpoint, or over the public internet. The administrator decides to create a custom VPC Flow Log to capture this information. Which custom log format field must the administrator include in the VPC Flow Log configuration to directly identify the routing path used by the traffic?

  1. traffic-pathCevap
  2. B
    flow-direction
  3. C
    pkt-dstaddr
  4. D
    action

Cevap

traffic-path
The traffic-path custom field indicates the path taken by egress/ingress traffic (such as through an Internet Gateway, NAT Gateway, Transit Gateway, or VPC Endpoint) using specific integer codes, allowing the SysOps Administrator to directly verify the routing path.

Adım Adım Çözüm

1
Analyze the requirements for identifying the routing mechanism (Transit Gateway, S3 Gateway Endpoint, or Internet Gateway) of the VPC traffic.
Identify that the default VPC Flow Logs format does not include specific routing metadata.
Default fields such as source/destination IP address and action do not explicitly indicate the path or gateway traversed by the packets.
2
Review the available custom VPC Flow Log fields that record routing metadata.
Identify the traffic-path field as the one that captures the egress or ingress transit path.
The traffic-path field records a single-digit integer representing the routing path (e.g., 1 for Internet Gateway, 5 for Transit Gateway, 7 for VPC Endpoint).
3
Select the correct field to configure in the custom log format.
The traffic-path field must be selected.
Including traffic-path directly resolves the administrator's requirement without needing complex reverse IP-to-resource lookups.

Anahtar Kavram

VPC Flow Logs Custom Format and Routing Paths
Tahmini Süre:1m 30s
Bu soruyu puanla