CertKeen

AWS Solutions Architect Associate (SAA-C03) · Free practice question 2 of 12

VPC Flow Logs for connectivity troubleshooting

Users report that an application server at Birchfield Clinics intermittently cannot reach a database in another subnet of the same VPC. The network team wants to see whether the traffic is being accepted or rejected by security groups or network ACLs, including source and destination IPs and ports. Which feature should they enable?

  1. A.AWS CloudTrail data events
  2. B.Amazon Route 53 Resolver query logging
  3. C.Elastic Load Balancing access logs
  4. D.VPC Flow Logs on the relevant subnets or network interfaces
Show answer and explanation

Correct answer: D. VPC Flow Logs on the relevant subnets or network interfaces

Why: VPC Flow Logs capture metadata about IP traffic to and from network interfaces, including addresses, ports, and whether traffic was accepted or rejected. CloudTrail records API calls rather than packet flows, Resolver query logs show DNS queries, and load balancer access logs only cover requests that pass through a load balancer.

More free AWS Solutions Architect Associate (SAA-C03) questions