Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Amazon SOA-C03 Exam - Topic 3 Question 16 Discussion

A company's CloudOps engineer is troubleshooting communication between the components of an application. The company configured VPC flow logs to be published to Amazon CloudWatch Logs. However, there are no logs in CloudWatch Logs.What could be blocking the VPC flow logs from being published to CloudWatch Logs?
A) The IAM policy attached to the IAM role for the flow log is missing the logs:CreateLogGroup permission.
B) The IAM policy attached to the IAM role for the flow log is missing the logs:CreateExportTask permission.
C) The VPC is configured for IPv6 addresses.
D) The VPC is peered with another VPC in the AWS account.

Amazon SOA-C03 Exam - Topic 3 Question 16 Discussion

Actual exam question for Amazon's SOA-C03 exam
Question #: 16
Topic #: 3
[All SOA-C03 Questions]

A company's CloudOps engineer is troubleshooting communication between the components of an application. The company configured VPC flow logs to be published to Amazon CloudWatch Logs. However, there are no logs in CloudWatch Logs.

What could be blocking the VPC flow logs from being published to CloudWatch Logs?

Show Suggested Answer Hide Answer
Suggested Answer: A

VPC Flow Logs require permissions to create log groups and log streams in Amazon CloudWatch Logs. If the IAM role associated with the flow log lacks the logs:CreateLogGroup permission, CloudWatch Logs cannot be created and no logs will appear.

Option B is unrelated because CreateExportTask is used for exporting logs, not publishing them. IPv6 configuration and VPC peering do not prevent flow logs from being delivered.

Ensuring the IAM role has the correct CloudWatch Logs permissions resolves the issue.


Contribute your Thoughts:

0/2000 characters

Currently there are no comments in this discussion, be the first to comment!


Save Cancel