VPC Flow Logs capture information about the IP traffic going to and from network interfaces in your VPC — the tool for troubleshooting connectivity and monitoring network traffic.
What they answer
Flow Logs show accepted and rejected traffic, which helps you diagnose why traffic is or isn’t reaching a resource (e.g., a security-group or NACL blocking it) and detect unusual network patterns. They can publish to CloudWatch Logs or S3. The tell is “troubleshoot why traffic is blocked” or “capture network traffic metadata.”
Test yourself
Instances in a subnet can’t be reached and you need to see whether traffic is being accepted or rejected at the network level. What do you enable?
- CloudTrail
- VPC Flow Logs
- AWS Config
- GuardDuty
👉 Click to reveal the answer & explanation
Correct answer: B. VPC Flow Logs record accepted/rejected IP traffic for network interfaces, revealing whether a security group or NACL is blocking traffic. CloudTrail (A) logs API calls; Config (C) tracks configuration; GuardDuty (D) detects threats, not per-flow accept/reject detail.
Related topics
Amazon VPC · Security groups vs NACLs · Amazon CloudWatch
Ready to pass the AWS Solutions Architect Associate (SAA-C03)?
Stop guessing whether you’re ready. Our full-length, exam-realistic practice exams put you through the exact question style you’ll face — with a detailed explanation behind every answer, so you learn why, not just what.
- ✓ 6 full-length practice exams
- ✓ A detailed explanation for every single question
- ✓ Realistic, scenario-based questions — not memory dumps
- ✓ Lifetime access, kept current for 2026
Get the SAA-C03 Practice Exams →or try 25 free questions first