Courseiva
Question 119 of 1,621
Network Management and OperationseasyMultiple ChoiceObjective-mapped

ANS-C01 Network Management and Operations Practice Question

A company has a VPC with public and private subnets. The public subnets have a NAT gateway for outbound internet access. The private subnets route all 0.0.0.0/0 traffic to the NAT gateway. The network team wants to centrally log all outbound internet traffic from the private subnets. They enable VPC Flow Logs and publish them to Amazon S3. However, they notice that the flow logs are capturing only traffic between instances within the VPC, not the NAT gateway traffic. What should the team do to capture outbound internet traffic?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Enable VPC Flow Logs specifically for the NAT gateway's elastic network interface.

VPC Flow Logs capture traffic at the network interface level. Traffic from private subnets to the NAT gateway is captured by flow logs on the private subnet instances' ENIs, but the NAT gateway's outbound traffic goes through its own ENI. To log the actual outbound internet traffic, you must enable flow logs on the NAT gateway's ENI. Option A correctly identifies this. Option B would not capture NAT gateway egress because flow logs are per-ENI. Option C (CloudTrail) logs API calls, not network traffic. Option D is incorrect because the destination (S3 vs CloudWatch) does not affect what traffic is captured.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Enable VPC Flow Logs specifically for the NAT gateway's elastic network interface.

    Why this is correct

    Captures traffic through the NAT gateway.

  • Enable VPC Flow Logs for all subnets in the VPC.

    Why it's wrong here

    Already enabled; missing NAT gateway interface.

  • Use AWS CloudTrail to log NAT gateway traffic.

    Why it's wrong here

    CloudTrail logs API calls, not network traffic.

  • Enable VPC Flow Logs for the VPC and publish to CloudWatch Logs instead of S3.

    Why it's wrong here

    Does not change what traffic is captured.

Visual reference

Inside (Private) PC-A 10.0.0.1 PC-B 10.0.0.2 NAT Router Outside (Public) 203.0.113.1 Inside Global Server PAT: many private IPs share one public IP via unique port numbers

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

Courseiva creates original exam-style practice questions with explanations and wrong-answer analysis. It does not publish real exam questions, exam dumps, or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on ANS-C01

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. A company has a VPC with public and private subnets. The private subnets have a route to a NAT gateway for outbound internet access. The security team wants to audit all traffic from the private subnets to the internet. Which TWO steps should be taken to capture this traffic?

medium
  • A.Enable VPC Flow Logs on the internet gateway.
  • B.Create a VPC Flow Log for the VPC and filter by the NAT gateway's network interface.
  • C.Enable VPC Flow Logs on the NAT gateway's elastic network interface.
  • D.Set up an AWS Site-to-Site VPN to route traffic through a third-party logging appliance.
  • E.Enable AWS CloudTrail for the NAT gateway.

Why B: To capture traffic from private subnets to the internet through a NAT gateway, you need to enable VPC Flow Logs on the NAT gateway's elastic network interface (option C). Additionally, you can create a VPC Flow Log for the VPC and filter by the NAT gateway's network interface (option B) to capture the same traffic. Option A is incorrect because VPC Flow Logs on the internet gateway capture traffic that reaches the internet gateway, but traffic from private subnets goes through the NAT gateway, not directly through the internet gateway. Option D is incorrect because a Site-to-Site VPN is not used for outbound internet traffic from private subnets; it is for connecting to on-premises networks. Option E is incorrect because AWS CloudTrail logs API calls, not network traffic.

Last reviewed: Jun 20, 2026

Question Discussion

Share a tip, memory trick, or ask about the reasoning behind this question. Do not post real exam questions, leaked content, braindumps, or copyrighted exam material. Comments are moderated and may be removed without notice.

Loading comments…

Sign in to join the discussion.

This ANS-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the ANS-C01 exam.