FCSS_CDS_AR-7.6 · Question #70
Refer to the exhibit. Your team notices an unusually high volume of traffic sourced at one of the organizations FortiGate EC2 instances. They create a flow log to obtain and analyze detailed…
The correct answer is D. Create a new flow log at the interface level. VPC flow logs can be created at the VPC, subnet, or network interface (ENI) level. If you create them at the VPC level (as shown in the exhibit), the logs will include traffic from all resources in that VPC. To capture logs only for the FortiGate EC2 instance, you must create a…
Question
Refer to the exhibit. Your team notices an unusually high volume of traffic sourced at one of the organizations FortiGate EC2 instances. They create a flow log to obtain and analyze detailed information about this traffic. However, when they checked the log, they found that it included traffic that was not associated with the FortiGate instance in question. What can they do to obtain the correct logs?
Exhibit
Options
- AChange the maximum aggregation time to 1 minute.
- BSend the logs to Amazon Data Firehose instead to get more granular information.
- CEnsure that the flow log data is not mixed with the rest of the traffic.
- DCreate a new flow log at the interface level.
How the community answered
(20 responses)- A15% (3)
- B5% (1)
- C5% (1)
- D75% (15)
Explanation
VPC flow logs can be created at the VPC, subnet, or network interface (ENI) level. If you create them at the VPC level (as shown in the exhibit), the logs will include traffic from all resources in that VPC. To capture logs only for the FortiGate EC2 instance, you must create a new flow log at the specific network interface (ENI) level of that instance.
Topics
Community Discussion
No community discussion yet for this question.
