ANS-C01 exam dumps

ANS-C01 practice question 185 of 513

AWS Certified Advanced Networking - Specialty. Expert level, Amazon Web Services. Free question with the correct answer and a full explanation.

ANS-C01 Question 185

Select 3

Your organization operates a multi-account AWS environment managed via AWS Organizations. The security team has mandated that VPC Flow Logs must be enabled for all VPCs across all accounts to ensure compliance. Additionally, the logs should be centralized in a single S3 bucket in the security account. Which of the following steps must be taken to implement this solution while adhering to best practices?

  1. A

    Create an S3 bucket in the security account, and configure a bucket policy to allow all accounts in the organization to write logs to it.

  2. B

    Enable VPC Flow Logs for each VPC in every account, and specify the centralized S3 bucket in the security account as the destination.

  3. C

    Use AWS Config to create a rule that ensures VPC Flow Logs are enabled for all VPCs across all accounts.

  4. D

    Use AWS CloudFormation StackSets to deploy a configuration to enable VPC Flow Logs in all member accounts.

  5. E

    Set up an AWS Lambda function in the security account to automatically create VPC Flow Logs for new VPCs in member accounts.

Show answer and explanation

Correct answers: A, C, D

Explanation

To centralize VPC Flow Logs and ensure compliance across all AWS accounts in an organization, you should create a centralized S3 bucket in the security account with a bucket policy allowing other accounts to write logs. AWS Config should be used to enforce that VPC Flow Logs are enabled for all VPCs, and AWS CloudFormation StackSets can efficiently deploy this configuration across all accounts. This approach aligns with AWS best practices for scalability and compliance.

  • A. Correct.

    Correct: Creating an S3 bucket in the security account with an appropriate bucket policy allows all member accounts to centralize their VPC Flow Logs into this bucket.

  • B. Incorrect.

    Incorrect: While specifying the S3 bucket as a destination is part of enabling VPC Flow Logs, this step alone doesn't ensure compliance across all accounts or automate the process.

  • C. Correct.

    Correct: AWS Config can enforce compliance by ensuring that VPC Flow Logs are enabled for every VPC in all accounts.

  • D. Correct.

    Correct: AWS CloudFormation StackSets is a best practice for deploying consistent configurations, such as enabling VPC Flow Logs, across multiple accounts in an organization.

  • E. Incorrect.

    Incorrect: Using a Lambda function to create VPC Flow Logs may work, but it is not a best practice compared to leveraging native AWS services like AWS Config and CloudFormation.

Timed practice exam

Take a ANS-C01 practice test under exam conditions

65 questions in 170 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam