Courseiva
Network Management and OperationsmediumMultiple SelectObjective-mapped

ANS-C01 Network Management and Operations Practice Question

A company has a VPC with public and private subnets. The private subnets have a route to a NAT gateway. The network team wants to monitor DNS queries from EC2 instances in private subnets to a custom DNS resolver on-premises over a VPN. Which TWO services can capture this traffic?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

VPC Flow Logs

VPC Flow Logs capture IP traffic at the network interface level, including DNS queries (port 53) to any destination, such as a custom on-premises resolver over VPN. AWS Network Firewall can inspect and log DNS traffic that passes through it, including queries to custom resolvers. Option A (Route 53 Resolver query logs) is incorrect because it only logs queries made to Amazon Route 53 Resolver, not to custom on-premises resolvers. Option B (CloudWatch) is incorrect because CloudWatch does not directly capture network traffic; it can aggregate logs but cannot capture raw DNS packets. Option E (CloudTrail) is incorrect because it logs API calls to AWS services, not network traffic.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Amazon Route 53 Resolver query logs

    Why it's wrong here

    Resolver query logs capture queries to Route 53, not custom on-premises resolvers.

  • Amazon CloudWatch

    Why it's wrong here

    CloudWatch is for monitoring metrics and logs, not capturing traffic directly.

  • VPC Flow Logs

    Why this is correct

    Flow logs capture all IP traffic, including DNS queries.

  • AWS Network Firewall

    Why this is correct

    Network Firewall can log traffic including DNS based on stateful rules.

  • AWS CloudTrail

    Why it's wrong here

    CloudTrail records API calls, not network traffic.

Visual reference

Inside (Private) PC-A 10.0.0.1 PC-B 10.0.0.2 NAT Router Outside (Public) 203.0.113.1 Inside Global Server PAT: many private IPs share one public IP via unique port numbers

About these practice questions

Courseiva writes every ANS-C01 question from scratch — 1,621 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This ANS-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the ANS-C01 exam.