Network and Content Delivery
CoreVPC Flow Logs
Explicit networking-log evidence for troubleshooting.
Key points
- Flow Logs record network-flow metadata and ACCEPT or REJECT disposition at an ENI, subnet, or VPC scope.
Best-known use cases
- D2.1, D2.2, and D5.1: locate a named network rejection or confirm a flow path without expecting packet or HTTP payloads.
What candidates often confuse it with
- Flow Logs expose network metadata; load-balancer, WAF, CloudFront, and application logs expose request-layer behavior.
Key takeaway
Use Flow Logs to diagnose network acceptance, then move to the log produced by the next request-processing layer.
Related services
- Amazon Application Recovery Controller
- AWS Client VPN
- Amazon CloudFront
Relevant exam tasks
- D2.1 — Task 2.1: Implement scalability and elasticity.
- 2.1.1 — Configure and manage scaling mechanisms in compute environments.
- D2.2 — Task 2.2: Implement highly available and resilient environments.
- 2.2.1 — Configure and troubleshoot Elastic Load Balancing (ELB) and Amazon Route 53 health checks.
- D5.1 — Task 5.1: Implement and optimize networking features and connectivity.
- 5.1.1 — Configure a VPC (for example, subnets, route tables, network ACLs, security groups, NAT gateways, internet gateway, egress-only internet gateway).