Most Cost-Effective VPC Flow Log Analytics Solution?

Answer Correct answer: D — Publish flow logs to Amazon S3 in Apache Parquet format and query them with Amazon Athena to minimize storage and scan costs.

An online retail company has an application that runs on Amazon EC2 instances that are in a VPC. The company wants to collect flow logs for the VPC and analyze network traffic. Which solution will meet these requirements MOST cost-effectively?

  1. Publish flow logs to Amazon CloudWatch Logs. Use Amazon Athena for analytics.
  2. Publish flow logs to Amazon CloudWatch Logs. Use an Amazon OpenSearch Service cluster for analytics.
  3. Publish flow logs to Amazon S3 in text format. Use Amazon Athena for analytics.
  4. Publish flow logs to Amazon S3 in Apache Parquet format. Use Amazon Athena for analytics. Correct Answer

Community Votes

D
100%

100% of anonymous learners picked answer D. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

Tests choosing between CloudWatch Logs and S3 destinations plus Athena or OpenSearch analytics; the common trap is overlooking how the destination format changes Athena bytes scanned and overall cost.

This DEA-C01 question asks for the most cost-effective way to collect VPC flow logs and analyze network traffic. Publishing flow logs to Amazon S3 in Apache Parquet format and using Amazon Athena (D) minimizes both storage and query costs.

Choosing CloudWatch Logs with Athena or S3 text with Athena because those also work; the Parquet columnar compression is what makes Athena queries and S3 storage cheapest.

Community Discussion (5 comments)

tgv 👍 6 Selected: D
Flow Logs can be published to S3 in Parquet format: https://docs.aws.amazon.com/vpc/latest/userguide/flow-logs-s3.html#flow-logs-s3-path
PGGuy 👍 5 Selected: D
Publishing flow logs to Amazon S3 in Apache Parquet format and using Amazon Athena for analytics (D) is the most cost-effective solution. This approach minimizes storage costs due to the efficient compression of Parquet, and optimizes query performance and cost in Athena due to the reduced data size and optimized columnar storage.
jyrajan69 👍 2
The question says clearly most cost effective, so on comparison between C and D, has to be C
LR2023 👍 1 Selected: B
Flow logs acn be published to S3 but then option D sas in Parquet format - it is not automatically converted into parquet.... https://aws.amazon.com/solutions/implementations/centralized-logging-with-opensearch/
HunkyBunky 👍 2 Selected: D
Apache parquet and S3 = most cost-effective solution

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

Option D sends VPC flow logs to Amazon S3, which avoids the per-GB ingestion and long-term retention charges that CloudWatch Logs would incur for high-volume network telemetry. Storing the data in Apache Parquet format gives columnar compression, so both the S3 footprint and the number of bytes Athena scans per query are reduced. Athena charges primarily by data scanned, making Parquet the lowest-cost analytics format for repeated traffic analysis. AWS VPC flow logs can be delivered directly to S3 in Parquet without building a separate conversion pipeline, so D meets the requirement with minimal operational overhead.

Why the Other Options Are Wrong

Option A publishes to CloudWatch Logs and then queries with Athena, but Athena does not query CloudWatch Logs natively; an export step is required, and CloudWatch Logs ingestion/retention is more expensive than S3. Option B adds an Amazon OpenSearch Service cluster, which introduces fixed compute and storage costs even when nobody is analyzing traffic, so it cannot be the MOST cost-effective. Option C works and is cheaper than A or B, but text-format flow logs force Athena to scan far more bytes than Parquet, raising query cost. The small storage savings of text are outweighed by the repeated scanning cost of network traffic analysis.

Community Comment Notes

Most learners converged on D. tgv stated, "Flow Logs can be published to S3 in Parquet format," which directly supports the delivery mechanism in option D. PGGuy explained that Parquet minimizes storage costs through efficient compression and optimizes Athena query cost through reduced data size and columnar storage. HunkyBunky summarized the same idea: "Apache parquet and S3 = most cost-effective solution." LR2023 raised a fair concern that Parquet is "not automatically converted into parquet" from S3 text, but VPC flow logs can be configured with Parquet as the direct S3 output format, so no conversion is needed. jyrajan69 favored C based on comparing only S3 options, yet missed the lower Athena bytes-scanned and storage footprint that Parquet provides.

Official Reference

Exam Strategy

When a DEA-C01 question asks for the MOST cost-effective analytics solution, compare both storage and query engines, then prefer columnar formats like Parquet in Amazon S3 with Athena over log-ingestion services or always-on search clusters. Verify whether the source service can write the format directly before assuming a conversion tool is required.

Frequently Asked Questions

Why is S3 Parquet with Athena cheaper than S3 text with Athena?

Parquet is columnar and compressed, so Athena reads fewer bytes per query and S3 stores less data. Because Athena charges by data scanned, this lowers analytics cost.

Can VPC flow logs be delivered directly to S3 in Parquet?

Yes. When you create a flow log with an S3 destination, you can choose Parquet as the output format, so no separate conversion service is required.

Related Analysis

Practice All DEA-C01 Questions

Access 100 questions with complete answers and detailed explanations.

View Full DEA-C01 Practice Test →

← Back to DEA-C01 Study Guide