A company uses AWS Organizations with multiple accounts. The security team wants to centrally aggregate and analyze VPC Flow Logs from all accounts. Which solution is MOST efficient and scalable?
VPC Flow Logs can be streamed directly to Amazon Kinesis Data Firehose in each account, and Firehose can then deliver nearly real-time data to a centrally owned Amazon OpenSearch Service domain cross-account. This is a fully managed, serverless pipeline that scales automatically with flow-log volume and avoids installing agents or operating log forwarders. A central OpenSearch cluster provides unified querying and visualization across all accounts' VPC traffic, making it the correct architecture for centralized real-time network analysis.
Why this answer
Amazon Kinesis Data Firehose can directly receive VPC Flow Logs from each account and deliver them to a centralized Amazon OpenSearch Service domain, enabling near-real-time aggregation and analysis without intermediate storage or replication overhead. This architecture is serverless, scales automatically, and avoids the complexity of managing cross-account S3 replication or EC2 instances, making it the most efficient and scalable solution for centralized log analysis.
Exam trap
The trap here is that candidates often default to S3-based solutions (Option A) because they are familiar with S3 for log storage, but they overlook that Kinesis Data Firehose provides a more direct, serverless pipeline for real-time analysis without the latency and complexity of S3 replication.
How to eliminate wrong answers
Option A is wrong because S3 Cross-Region Replication adds latency, requires managing replication rules and IAM permissions across accounts, and does not provide native querying or analysis capabilities—logs would need additional services like Athena or OpenSearch for analysis. Option B is wrong because launching EC2 instances to run tcpdump is inefficient, introduces management overhead, scales poorly across many accounts, and tcpdump captures raw packets rather than VPC Flow Logs, which are already a structured log format. Option C is wrong because cross-account CloudWatch dashboards only visualize logs stored in each account's CloudWatch Logs; they do not centrally aggregate the logs into a single store, and querying across accounts requires complex cross-account log group subscriptions or additional infrastructure.