How Should You Configure an NLB Target for VPC Traffic Mirroring?
A company needs to capture and log traffic for Nitro-based Amazon EC2 instances to comply with regulations. The company's network team has prepared a solution that enables VPC traffic mirroring and sends traffic to a second set of EC2 instances in an Auto Scaling group. The network team has added a Network Load Balancer (NLB) in front of the EC2 instances the traffic will be sent to. However, the solution does not send any mirrored traffic to the EC2 instances that are behind the NLB. How should the network team configure traffic mirroring to use the NLB endpoint?
Community Votes
100% of anonymous learners picked answer D. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
The exam tests whether you know that VPC Traffic Mirroring encapsulates mirrored traffic in UDP (VXLAN port 4789) and that the NLB must be the target, not the source, so a UDP listener is the only valid configuration.
VPC Traffic Mirroring for Nitro-based EC2 instances requires the NLB to be configured as a target with a UDP listener. This is because mirrored traffic uses VXLAN UDP encapsulation on port 4789, as confirmed by the 100% community vote for option D.
Selecting option C (TCP listener) is the most common mistake. Candidates assume load balancers use TCP for health and forwarding, but VPC Traffic Mirroring is UDP-based; a TCP listener cannot process VXLAN-encapsulated mirrored traffic.
Community Discussion (3 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
Option D is correct because AWS VPC Traffic Mirroring uses VXLAN encapsulation, which relies on UDP port 4789. The NLB must be selected as the target for traffic mirroring, not the source. A single UDP listener on the NLB is sufficient to forward the encapsulated mirrored traffic to the EC2 instances. Community comment [2] explicitly notes that Traffic mirroring requires UDP for VXLAN encapsulation and that a single UDP listener is sufficient.Why the Other Options Are Wrong
Option A fails because the NLB is not a traffic source; the Nitro-based EC2 instances are. Option B includes a TCP listener, which is unnecessary and cannot handle the UDP-based VXLAN encapsulation used by traffic mirroring. Option C is incorrect because a TCP listener would drop the UDP packets from the mirror source. The community vote is unanimous: 100% of voters selected D, reinforcing that only a UDP listener works.Community Comment Notes
The comments consistently emphasize the protocol details: comment [1] states VxLAN UDP Port 4789 is used for traffic mirroring, while comment [3] explains that the mirrored traffic is always sent using UDP encapsulation. Comment [2] adds that the NLB must be configured as a target, not a source. These insights align with the AWS documentation and simplify the decision: look for UDP and target.Official Reference
Exam Strategy
On the exam, remember that VPC Traffic Mirroring uses VXLAN over UDP port 4789. When an NLB is used as a traffic mirror target, configure a UDP listener—never a TCP listener or the NLB as a source.
Related Analysis
Practice All ANS-C01 Questions
Access 137 questions with complete answers and detailed explanations.
View Full ANS-C01 Practice Test →