VPC Flow Logs Secondary IP Address Capture
A network engineer needs to provide a list of IP addresses that are sending traffic to an Amazon EC2 instance. VPC flow logs are enabled. The EC2 instance has a single network interface and two assigned IP addresses. However, the flow logs are logging traffic only for the primary IP address. The network engineer needs to determine whether any traffic is being sent to the second IP address of the EC2 instance. What should the network engineer do to locate the traffic flow for the second IP address?
Community Votes
100% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
The question tests the distinction between dstaddr (primary interface IP) and pkt-dstaddr (original packet destination), a common trap when managing multi-IP network interfaces.
When an EC2 instance has multiple secondary IPs, standard VPC flow logs only log traffic to the primary IP in the dstaddr field. To capture traffic destined for secondary IPs, you must enable the pkt-dstaddr field.
Choosing B (dstaddr) is incorrect because AWS documentation explicitly states that dstaddr will show the primary private IPv4 address even if traffic is sent to a secondary one, making it useless for this specific requirement.
Community Discussion (3 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
According to AWS VPC Flow Logs documentation, when a network interface has multiple IPv4 addresses, thedstaddr field defaults to displaying the primary private IPv4 address. To accurately identify traffic sent to secondary private IPv4 addresses, the pkt-dstaddr field must be included in the flow log configuration. This field captures the original destination IP address of the packet before any NAT or interface translation occurs.Why the Other Options Are Wrong
Option B (dstaddr) is incorrect because it specifically refers to the primary IP address of the network interface, failing to distinguish traffic for secondary IPs. Option C (pkt-srcaddr) captures the source IP, not the destination. Option D (srcaddr) captures the source IP of the interface, which is irrelevant for identifying the destination of incoming traffic to a secondary IP.Community Comment Notes
Comments consistently cite the official AWS documentation regarding VPC Flow Logs limitations. The consensus highlights that whiledstaddr shows the primary IP, pkt-dstaddr is required to see the actual destination IP for secondary addresses attached to the same ENI. Official Reference
Exam Strategy
Memorize the specific fields for VPC Flow Logs, particularly pkt-srcaddr vs srcaddr and pkt-dstaddr vs dstaddr. Understand that 'pkt-' prefixed fields refer to the original packet headers, which is crucial for troubleshooting traffic involving NAT or secondary IPs.
Related Analysis
Practice All ANS-C01 Questions
Access 137 questions with complete answers and detailed explanations.
View Full ANS-C01 Practice Test →