ANS-C01 exam dumps

ANS-C01 practice question 460 of 513

AWS Certified Advanced Networking - Specialty. Expert level, Amazon Web Services. Free question with the correct answer and a full explanation.

ANS-C01 Question 460

Select 3

Your organization has deployed a VPC with multiple subnets and EC2 instances hosting sensitive data. To ensure compliance with security policies, you need to validate and audit the network traffic for unauthorized access attempts and unusual patterns. Which combination of AWS services should you use to effectively monitor and log network activity?

  1. A

    Amazon VPC Flow Logs

  2. B

    AWS CloudTrail

  3. C

    AWS WAF

  4. D

    Amazon CloudWatch Logs

  5. E

    AWS Network Firewall

Show answer and explanation

Correct answers: A, B, D

Explanation

To validate and audit network security, you need services that provide detailed logging and monitoring capabilities. Amazon VPC Flow Logs allow you to capture network traffic data, AWS CloudTrail logs API actions for auditing resource changes, and Amazon CloudWatch Logs aggregates logs for analysis. Together, these services effectively meet the requirements for monitoring and auditing in the scenario. AWS WAF and AWS Network Firewall are security tools but are not primarily designed for logging and monitoring in this context.

  • A. Correct.

    Amazon VPC Flow Logs capture detailed information about the IP traffic going to and from network interfaces in your VPC. This is essential for monitoring and auditing network activity.

  • B. Correct.

    AWS CloudTrail logs API activity and provides visibility into actions taken on AWS resources, including networking configuration changes, which is critical for auditing.

  • C. Incorrect.

    AWS WAF is used to protect web applications from attacks like SQL injection and cross-site scripting. While it provides security, it is not a logging or monitoring service for general network activity.

  • D. Correct.

    Amazon CloudWatch Logs enable you to aggregate and analyze logs from various AWS services, including VPC Flow Logs, making it valuable for auditing and monitoring purposes.

  • E. Incorrect.

    AWS Network Firewall is a managed firewall service that helps protect your VPCs. While it enhances security, it does not provide direct logging and monitoring functionality like the other services in this context.

Timed practice exam

Take a ANS-C01 practice test under exam conditions

65 questions in 170 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam