Courseiva
Network Management and OperationshardMultiple SelectObjective-mapped

ANS-C01 Network Management and Operations Practice Question

A company has a multi-account AWS environment using AWS Transit Gateway with multiple VPC attachments. The network team wants to centralize logging of all network traffic crossing the Transit Gateway. Which TWO services can be used together to achieve this?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

VPC Flow Logs published to a central Amazon S3 bucket

VPC Flow Logs can be published to a central Amazon S3 bucket, aggregating traffic logs from different VPCs attached to the Transit Gateway. Option D is correct because AWS Transit Gateway Network Manager allows centralized monitoring and can integrate flow logs. Option B is incorrect because Site-to-Site VPN does not generate its own flow logs; VPN traffic is captured by VPC Flow Logs on the VPN attachment. Option C is incorrect because Direct Connect Gateway does not have flow logs; traffic is logged via VPC Flow Logs on the virtual interfaces. Option E is incorrect because AWS CloudTrail records API actions, not network traffic.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • VPC Flow Logs published to a central Amazon S3 bucket

    Why this is correct

    VPC Flow Logs capture traffic; publishing to a central S3 bucket allows aggregation.

  • AWS Site-to-Site VPN flow logs

    Why it's wrong here

    VPN flow logs are not a service; VPN traffic is logged via VPC Flow Logs.

  • AWS Direct Connect Gateway flow logs

    Why it's wrong here

    Direct Connect does not provide flow logs for Transit Gateway.

  • AWS Transit Gateway Network Manager

    Why this is correct

    Network Manager can collect and centralize flow logs from multiple VPCs.

  • AWS CloudTrail for Transit Gateway events

    Why it's wrong here

    CloudTrail records API calls, not network traffic flows.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

One of 1,621 original ANS-C01 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This ANS-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the ANS-C01 exam.