nerdexam
Amazon

SOA-C02 · Question #115

A company has created a NAT gateway in a public subnet in a VPC. The VPC also contains a private subnet that includes Amazon EC2 instances. The EC2 instances use the NAT gateway to access the internet

The correct answer is C. Use CloudWatch Logs Insights to identify the top five internet destinations.. https://docs.aws.amazon.com/AmazonCloudWatch/latest/logs/CWL_QuerySyntax-examples.html

Submitted by parkjh· Mar 30, 2026Monitoring, Logging, and Remediation

Question

A company has created a NAT gateway in a public subnet in a VPC. The VPC also contains a private subnet that includes Amazon EC2 instances. The EC2 instances use the NAT gateway to access the internet to download patches and updates. The company has configured a VPC flow log for the elastic network interface of the NAT gateway. The company is publishing the output to Amazon CloudWatch Logs. A SysOps administrator must identify the top five internet destinations that the EC2 instances in the private subnet communicate with for downloads. What should the SysOps administrator do to meet this requirement in the MOST operationally efficient way?

Options

  • AUse AWS CloudTrail Insights events to identify the top five internet destinations.
  • BUse Amazon CloudFront standard logs (access logs) to identify the top five internet destinations.
  • CUse CloudWatch Logs Insights to identify the top five internet destinations.
  • DChange the flow log to publish logs to Amazon S3. Use Amazon Athena to query the log files in

How the community answered

(27 responses)
  • A
    11% (3)
  • B
    4% (1)
  • C
    81% (22)
  • D
    4% (1)

Explanation

https://docs.aws.amazon.com/AmazonCloudWatch/latest/logs/CWL_QuerySyntax-examples.html

Topics

#VPC flow logs#CloudWatch Logs Insights#NAT gateway traffic#network destination analysis

Community Discussion

No community discussion yet for this question.

Full SOA-C02 Practice