Publish VPC Flow Logs to CloudWatch Logs and count RDP sessions with a log group metric filter
A company runs a fleet of Amazon EC2 instances in a VPC. The company's employees remotely access the EC2 instances by using the Remote Desktop Protocol (RDP). The company wants to collect metrics about how many RDP sessions the employees initiate every day. Which combination of steps will meet this requirement? (Choose three.)
Community Votes
100% of anonymous learners picked answer CDE. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
VPC Flow Logs are the only listed source that captures the actual network connections, and they publish to CloudWatch Logs, so the flow log, its CloudWatch Logs destination, and a metric filter over that log group together produce a countable daily metric (C, D, E). Options A and B route through EventBridge on EC2 instance state-change events, which describe instance state transitions rather than network sessions, so they cannot count RDP connections at all; luisfsm_111 made this point explicitly.
Counting daily RDP sessions requires a record of the connections themselves, and VPC Flow Logs capture the network metadata for traffic to and from the VPC interfaces, which includes the RDP connections on TCP port 3389. Creating a CloudWatch Logs log group as the flow log destination puts that data into CloudWatch, and a log group metric filter counts the matching RDP connection records so the daily session count is available as a metric.
Using an EventBridge rule on EC2 Instance State-change Notification events with a CloudWatch Logs target (A and B) — instance state-change events report instance start, stop, and terminate transitions, not network connections, so counting RDP sessions is impossible from that source. Using a subscription filter to Kinesis, Lambda, or Firehose instead of a metric filter (the alternative raised by nqg54118) — that would move the data somewhere for further processing, but the requirement is a metric count, which a metric filter on the log group provides directly with no downstream consumer.
Community Discussion (6 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
To count how many RDP sessions employees initiate each day, the solution must capture the network connections themselves. Creating a VPC Flow Log records traffic metadata for the network interfaces in the VPC, which includes the RDP connections on TCP port 3389 (C). Amazon CloudWatch Logs is a supported flow log destination, so specifying a CloudWatch Logs log group as the destination places that flow log data into CloudWatch where it can be queried (D). Creating a log group metric filter over that log group counts the records matching the RDP session pattern and emits a metric, which is what provides the daily session count (E). C, D, and E together form the data path from network capture to a countable metric.Why the Other Options Are Wrong
A creates an EventBridge rule reacting to EC2 Instance State-change Notification events and B adds a CloudWatch Logs log group as that rule's target. Instance state-change events capture instance lifecycle transitions such as running, shutting down, and terminated, not network connections, so neither can produce a count of RDP sessions; luisfsm_111 explicitly noted that no EventBridge is needed. nqg54118 suggested a subscription filter targeting Kinesis Data Streams, Lambda, or Firehose, which would stream the log events to another service for processing, but the requirement is a metric count for the log data already in CloudWatch, which a metric filter produces without any additional consumer. C, D, and E are the correct combination.Community Comment Notes
Community voted C,D,E (90). Srikantha and Ky_24 explained that VPC Flow Logs capture traffic including RDP on TCP port 3389 and are the way to detect session activity from a network perspective. luisfsm_111 pointed out that no EventBridge rule is needed at all, which eliminates A and B. One comment referenced an unrelated ECR pull through cache scenario, which does not apply here.Official Reference
Related Analysis
Practice All DOP-C02 Questions
Access 85 questions with complete answers and detailed explanations.
View Full DOP-C02 Practice Test →