Courseiva
Design Secure Architectures →mediumMultiple Choice

SAA-C03 Design Secure Architectures Practice Question

A company is experiencing unauthorized network traffic in their VPC. They need to inspect traffic patterns between subnets to identify the source of the traffic. Which tool should they use?

⚠ Common exam trap

Candidates often confuse VPC Flow Logs with AWS CloudTrail. CloudTrail logs API calls (management plane), whereas VPC Flow Logs capture network traffic metadata (data plane).

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

VPC Flow Logs.

VPC Flow Logs capture information about the IP traffic going to and from network interfaces in the VPC. By analyzing these logs, administrators can identify blocked connections, traffic spikes, or unusual destination patterns. This data is essential for security auditing, troubleshooting connectivity issues, and detecting potential malicious activity within the network perimeter, providing the visibility needed to strengthen security policies and Network ACLs.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    AWS CloudTrail.

    Why it's wrong here

    CloudTrail logs AWS API calls and management actions. It does not provide visibility into the packet-level flow of network traffic between EC2 instances or subnets. While useful for auditing who did what in the account, it is not the correct tool for analyzing network-level traffic patterns or security incidents.

  • ✗

    AWS Config.

    Why it's wrong here

    AWS Config is for resource configuration history and compliance auditing. It tracks changes to security groups and ACLs, but it does not capture the actual network traffic logs required to analyze traffic patterns. Using Config for traffic monitoring is outside of its functional scope and will not provide the necessary data.

  • ✓

    VPC Flow Logs.

    Why this is correct

    VPC Flow Logs provide a detailed view of all network traffic flowing through the VPC's network interfaces. This allows security teams to monitor for anomalous patterns, identify unauthorized traffic, and verify that security groups and NACLs are behaving as expected, making it the correct tool for this specific scenario.

  • ✗

    AWS Trusted Advisor.

    Why it's wrong here

    Trusted Advisor provides automated recommendations for cost optimization, security, performance, and fault tolerance based on best practices. It does not provide real-time or historical network traffic logging or analysis for specific subnets. Therefore, it cannot be used to identify unauthorized traffic patterns as requested in the scenario.

Visual reference

192.168.1.0 /24 256 addresses (254 usable) 192.168.1.0 /25 Subnet A 128 addr (126 usable) 192.168.1.128 /25 Subnet B 128 addr (126 usable) Borrowing 1 bit from host portion creates 2 subnets (/25)

About these practice questions

This SAA-C03 question is part of Courseiva's 149-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This SAA-C03 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAA-C03 exam.