SAA-C03 Design Secure Architectures Practice Question
A company is experiencing unauthorized network traffic in their VPC. They need to inspect traffic patterns between subnets to identify the source of the traffic. Which tool should they use?
⚠ Common exam trap
Candidates often confuse VPC Flow Logs with AWS CloudTrail. CloudTrail logs API calls (management plane), whereas VPC Flow Logs capture network traffic metadata (data plane).
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
VPC Flow Logs.
VPC Flow Logs capture information about the IP traffic going to and from network interfaces in the VPC. By analyzing these logs, administrators can identify blocked connections, traffic spikes, or unusual destination patterns. This data is essential for security auditing, troubleshooting connectivity issues, and detecting potential malicious activity within the network perimeter, providing the visibility needed to strengthen security policies and Network ACLs.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
AWS CloudTrail.
Why it's wrong here
CloudTrail logs AWS API calls and management actions. It does not provide visibility into the packet-level flow of network traffic between EC2 instances or subnets. While useful for auditing who did what in the account, it is not the correct tool for analyzing network-level traffic patterns or security incidents.
- ✗
AWS Config.
Why it's wrong here
AWS Config is for resource configuration history and compliance auditing. It tracks changes to security groups and ACLs, but it does not capture the actual network traffic logs required to analyze traffic patterns. Using Config for traffic monitoring is outside of its functional scope and will not provide the necessary data.
- ✓
VPC Flow Logs.
Why this is correct
VPC Flow Logs provide a detailed view of all network traffic flowing through the VPC's network interfaces. This allows security teams to monitor for anomalous patterns, identify unauthorized traffic, and verify that security groups and NACLs are behaving as expected, making it the correct tool for this specific scenario.
- ✗
AWS Trusted Advisor.
Why it's wrong here
Trusted Advisor provides automated recommendations for cost optimization, security, performance, and fault tolerance based on best practices. It does not provide real-time or historical network traffic logging or analysis for specific subnets. Therefore, it cannot be used to identify unauthorized traffic patterns as requested in the scenario.
Visual reference
About these practice questions
This SAA-C03 question is part of Courseiva's 149-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This SAA-C03 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAA-C03 exam.