Question 119 of 1,621
ANS-C01 Network Management and Operations Practice Question
A company has a VPC with public and private subnets. The public subnets have a NAT gateway for outbound internet access. The private subnets route all 0.0.0.0/0 traffic to the NAT gateway. The network team wants to centrally log all outbound internet traffic from the private subnets. They enable VPC Flow Logs and publish them to Amazon S3. However, they notice that the flow logs are capturing only traffic between instances within the VPC, not the NAT gateway traffic. What should the team do to capture outbound internet traffic?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Enable VPC Flow Logs specifically for the NAT gateway's elastic network interface.
VPC Flow Logs capture traffic at the network interface level. Traffic from private subnets to the NAT gateway is captured by flow logs on the private subnet instances' ENIs, but the NAT gateway's outbound traffic goes through its own ENI. To log the actual outbound internet traffic, you must enable flow logs on the NAT gateway's ENI. Option A correctly identifies this. Option B would not capture NAT gateway egress because flow logs are per-ENI. Option C (CloudTrail) logs API calls, not network traffic. Option D is incorrect because the destination (S3 vs CloudWatch) does not affect what traffic is captured.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Enable VPC Flow Logs specifically for the NAT gateway's elastic network interface.
Why this is correct
Captures traffic through the NAT gateway.
- ✗
Enable VPC Flow Logs for all subnets in the VPC.
Why it's wrong here
Already enabled; missing NAT gateway interface.
- ✗
Use AWS CloudTrail to log NAT gateway traffic.
Why it's wrong here
CloudTrail logs API calls, not network traffic.
- ✗
Enable VPC Flow Logs for the VPC and publish to CloudWatch Logs instead of S3.
Why it's wrong here
Does not change what traffic is captured.
Visual reference
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
About these practice questions
Courseiva creates original exam-style practice questions with explanations and wrong-answer analysis. It does not publish real exam questions, exam dumps, or protected exam content. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on ANS-C01
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. A company has a VPC with public and private subnets. The private subnets have a route to a NAT gateway for outbound internet access. The security team wants to audit all traffic from the private subnets to the internet. Which TWO steps should be taken to capture this traffic?
medium- A.Enable VPC Flow Logs on the internet gateway.
- ✓ B.Create a VPC Flow Log for the VPC and filter by the NAT gateway's network interface.
- ✓ C.Enable VPC Flow Logs on the NAT gateway's elastic network interface.
- D.Set up an AWS Site-to-Site VPN to route traffic through a third-party logging appliance.
- E.Enable AWS CloudTrail for the NAT gateway.
Why B: To capture traffic from private subnets to the internet through a NAT gateway, you need to enable VPC Flow Logs on the NAT gateway's elastic network interface (option C). Additionally, you can create a VPC Flow Log for the VPC and filter by the NAT gateway's network interface (option B) to capture the same traffic. Option A is incorrect because VPC Flow Logs on the internet gateway capture traffic that reaches the internet gateway, but traffic from private subnets goes through the NAT gateway, not directly through the internet gateway. Option D is incorrect because a Site-to-Site VPN is not used for outbound internet traffic from private subnets; it is for connecting to on-premises networks. Option E is incorrect because AWS CloudTrail logs API calls, not network traffic.
Last reviewed: Jun 20, 2026
This ANS-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the ANS-C01 exam.
Question Discussion
Share a tip, memory trick, or ask about the reasoning behind this question. Do not post real exam questions, leaked content, braindumps, or copyrighted exam material. Comments are moderated and may be removed without notice.
Sign in to join the discussion.