SOA-C02 Networking and Content Delivery Practice Question
A SysOps Administrator is configuring VPC Flow Logs to monitor network traffic. Which THREE pieces of information are included in VPC Flow Log records?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Protocol number
VPC Flow Logs capture metadata about network traffic, including source IP address (C), destination IP address (E), and protocol number (B). They do not include HTTP status codes (A) or DNS query names (D), as those are application-layer details beyond the scope of network flows.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
HTTP status code
Why it's wrong here
VPC Flow Logs capture metadata about network traffic at Layers 3 and 4 of the OSI model, such as IP addresses, ports, and protocol numbers. They do not perform deep packet inspection or parse application-layer payloads, so an HTTP status code (a Layer 7 concept) is never present in a flow log record. To monitor HTTP status codes, you would need to enable webserver access logs or use an agent-based solution like Amazon CloudWatch Agent.
- ✓
Protocol number
Why this is correct
The protocol number field in a VPC Flow Log record identifies the IP protocol used for the traffic, using IANA-assigned numbers (e.g., 6 for TCP, 17 for UDP, 1 for ICMP). This numeric value is captured directly from the IP header, independent of the application layer. Flow log records include this field regardless of whether the traffic is TCP, UDP, or another protocol, making it a reliable attribute for filtering and analyzing traffic types.
- ✓
Source IP address
Why this is correct
VPC Flow Logs record the source IP address in the 'srcaddr' field, which is the IPv4 or IPv6 address that originated the traffic. This field is captured from the packet's IP header, so it always exists for accepted, rejected, and no-data flow records that represent actual traffic. You can use it to identify the origin of communications, such as a specific EC2 instance's private IP or a public IP from the internet.
- ✗
DNS query name
Why it's wrong here
DNS query names are application-layer data carried in the payload of DNS packets sent to port 53, typically over UDP or TCP. VPC Flow Logs do not inspect packet payloads; they only log flow metadata like IP addresses, ports, and protocol numbers. To capture DNS query names, you must use separate DNS logging features such as Amazon Route 53 Resolver query logging or configure your own DNS server logs.
- ✓
Destination IP address
Why this is correct
The destination IP address is stored in the 'dstaddr' field of a VPC Flow Log record and represents the IP address to which the traffic was sent. Similar to the source IP, this value is extracted from the IP header and is always present for traffic flows recorded in the log. It is essential for determining which resource received the communication, such as an EC2 instance, an internet gateway, or another private IP within the VPC.
Visual reference
Go deeper
Related to this question
About these practice questions
Courseiva writes every SOA-C02 question from scratch — 1,169 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SOA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SOA-C02 exam.