VPC Flow Logs Secondary IP Address Capture

A network engineer needs to provide a list of IP addresses that are sending traffic to an Amazon EC2 instance. VPC flow logs are enabled. The EC2 instance has a single network interface and two assigned IP addresses. However, the flow logs are logging traffic only for the primary IP address. The network engineer needs to determine whether any traffic is being sent to the second IP address of the EC2 instance. What should the network engineer do to locate the traffic flow for the second IP address?

  1. Create a new flow log that includes the pkt-dstaddr field to capture the original destination IP address of the traffic. Source Reference Answer
  2. Create a new flow log that includes the dstaddr field to capture the original destination IP address of the traffic.
  3. Create a new flow log that includes the pkt-srcaddr field to capture the original destination IP address of the traffic.
  4. Create a new flow log that includes the srcaddr field to capture the original destination IP address of the traffic.

Community Votes

A
100%

100% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

The question tests the distinction between dstaddr (primary interface IP) and pkt-dstaddr (original packet destination), a common trap when managing multi-IP network interfaces.

When an EC2 instance has multiple secondary IPs, standard VPC flow logs only log traffic to the primary IP in the dstaddr field. To capture traffic destined for secondary IPs, you must enable the pkt-dstaddr field.

Choosing B (dstaddr) is incorrect because AWS documentation explicitly states that dstaddr will show the primary private IPv4 address even if traffic is sent to a secondary one, making it useless for this specific requirement.

Community Discussion (3 comments)

exampb007 👍 1 Selected: A
A is the correct one
woorkim 👍 3 Selected: A
https://docs.aws.amazon.com/vpc/latest/userguide/flow-logs-limitations.html If your network interface has multiple IPv4 addresses and traffic is sent to a secondary private IPv4 address, the flow log displays the primary private IPv4 address in the dstaddr field. To capture the original destination IP address, create a flow log with the pkt-dstaddr field.
makanju 👍 1 Selected: A
Amazon VPC Flow Logs are used to capture network traffic information for interfaces in a VPC. By default, flow logs capture data for the primary private IP address of the network interface. However, to capture traffic for secondary IP addresses assigned to an interface, additional fields such as pkt-dstaddr are necessary.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

According to AWS VPC Flow Logs documentation, when a network interface has multiple IPv4 addresses, the dstaddr field defaults to displaying the primary private IPv4 address. To accurately identify traffic sent to secondary private IPv4 addresses, the pkt-dstaddr field must be included in the flow log configuration. This field captures the original destination IP address of the packet before any NAT or interface translation occurs.

Why the Other Options Are Wrong

Option B (dstaddr) is incorrect because it specifically refers to the primary IP address of the network interface, failing to distinguish traffic for secondary IPs. Option C (pkt-srcaddr) captures the source IP, not the destination. Option D (srcaddr) captures the source IP of the interface, which is irrelevant for identifying the destination of incoming traffic to a secondary IP.

Community Comment Notes

Comments consistently cite the official AWS documentation regarding VPC Flow Logs limitations. The consensus highlights that while dstaddr shows the primary IP, pkt-dstaddr is required to see the actual destination IP for secondary addresses attached to the same ENI.

Official Reference

Array

Exam Strategy

Memorize the specific fields for VPC Flow Logs, particularly pkt-srcaddr vs srcaddr and pkt-dstaddr vs dstaddr. Understand that 'pkt-' prefixed fields refer to the original packet headers, which is crucial for troubleshooting traffic involving NAT or secondary IPs.

Related Analysis

Practice All ANS-C01 Questions

Access 137 questions with complete answers and detailed explanations.

View Full ANS-C01 Practice Test →

← Back to ANS-C01 Study Guide