passdrill
AWS SAA-C03 · VPC & Networking · Card 015/024 easy

An engineer creates a VPC Flow Log for a subnet and wants it to record only traffic that was rejected by a security group or network ACL, then have that data queryable with Amazon Athena. Which combination of settings and destination supports this?

  1. Set the traffic filter to REJECT and publish the flow log to Amazon S3
  2. Set the traffic filter to ACCEPT and publish the flow log to Amazon CloudWatch Logs
  3. Flow logs can only capture ALL traffic, never REJECT-only, so a separate security tool is required
  4. Set the traffic filter to REJECT, but flow logs can only be queried through the EC2 console, not Athena
Next card → Shuffle