Which TWO AWS services can be used to monitor and troubleshoot network connectivity issues between EC2 instances? (Choose two.)
Trap 1: Amazon Inspector.
Amazon Inspector scans EC2 instances and container images for software vulnerabilities and unintended network exposure; it does not trace packet paths or reachability between instances. It is tempting because it reports network-related findings, and would be correct for vulnerability assessment, not for diagnosing connectivity failures.
Trap 2: AWS CloudTrail.
CloudTrail records API activity and management events in the account; it captures no packet-level or flow-level data between EC2 instances, so it cannot show where connectivity breaks. It is tempting because it is a core monitoring service, and would be correct for auditing who changed security groups or routes, not for tracing live traffic.
Trap 3: AWS Config.
AWS Config records resource configuration changes and evaluates compliance against rules; it does not capture packet-level flow logs or reachability paths between instances. It is tempting because it inventories network resources such as security groups, which is useful for auditing drift, but connectivity troubleshooting requires VPC Flow Logs and Reachability Analyzer.
- A
Amazon Inspector.
Why it fails: Amazon Inspector scans EC2 instances and container images for software vulnerabilities and unintended network exposure; it does not trace packet paths or reachability between instances. It is tempting because it reports network-related findings, and would be correct for vulnerability assessment, not for diagnosing connectivity failures.
- B
AWS CloudTrail.
Why it fails: CloudTrail records API activity and management events in the account; it captures no packet-level or flow-level data between EC2 instances, so it cannot show where connectivity breaks. It is tempting because it is a core monitoring service, and would be correct for auditing who changed security groups or routes, not for tracing live traffic.
- C
AWS Config.
Why it fails: AWS Config records resource configuration changes and evaluates compliance against rules; it does not capture packet-level flow logs or reachability paths between instances. It is tempting because it inventories network resources such as security groups, which is useful for auditing drift, but connectivity troubleshooting requires VPC Flow Logs and Reachability Analyzer.
- D
VPC Reachability Analyzer.
VPC Reachability Analyzer performs static configuration analysis across ENIs, security groups, NACLs, route tables and gateways, tracing the exact hop where connectivity breaks without sending traffic. This satisfies the stem's troubleshooting requirement by pinpointing misconfigured components between EC2 instances, rather than merely reporting packet loss or flow logs.
- E
VPC Flow Logs.
VPC Flow Logs capture IP traffic metadata for elastic network interfaces, subnets and VPCs, recording accepted and rejected packets with source and destination addresses, ports and protocol. This directly satisfies the requirement to monitor and troubleshoot connectivity between EC2 instances, revealing security group or NACL blocks.