Publish VPC Flow Logs to CloudWatch Logs and count RDP sessions with a log group metric filter

Answer Correct answer: C, D, E — publish VPC Flow Logs to a CloudWatch Logs log group and count RDP sessions with a metric filter.

A company runs a fleet of Amazon EC2 instances in a VPC. The company's employees remotely access the EC2 instances by using the Remote Desktop Protocol (RDP). The company wants to collect metrics about how many RDP sessions the employees initiate every day. Which combination of steps will meet this requirement? (Choose three.)

  1. Create an Amazon EventBridge rule that reacts to EC2 Instance State-change Notification events.
  2. Create an Amazon CloudWatch Logs log group. Specify the log group as a target for the EventBridge rule.
  3. Create a flow log in VPC Flow Logs. Correct Answer
  4. Create an Amazon CloudWatch Logs log group. Specify the log group as a destination for the flow log. Correct Answer
  5. Create a log group metric filter. Correct Answer

Community Votes

CDE
100%

100% of anonymous learners picked answer CDE. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

VPC Flow Logs are the only listed source that captures the actual network connections, and they publish to CloudWatch Logs, so the flow log, its CloudWatch Logs destination, and a metric filter over that log group together produce a countable daily metric (C, D, E). Options A and B route through EventBridge on EC2 instance state-change events, which describe instance state transitions rather than network sessions, so they cannot count RDP connections at all; luisfsm_111 made this point explicitly.

Counting daily RDP sessions requires a record of the connections themselves, and VPC Flow Logs capture the network metadata for traffic to and from the VPC interfaces, which includes the RDP connections on TCP port 3389. Creating a CloudWatch Logs log group as the flow log destination puts that data into CloudWatch, and a log group metric filter counts the matching RDP connection records so the daily session count is available as a metric.

Using an EventBridge rule on EC2 Instance State-change Notification events with a CloudWatch Logs target (A and B) — instance state-change events report instance start, stop, and terminate transitions, not network connections, so counting RDP sessions is impossible from that source. Using a subscription filter to Kinesis, Lambda, or Firehose instead of a metric filter (the alternative raised by nqg54118) — that would move the data somewhere for further processing, but the requirement is a metric count, which a metric filter on the log group provides directly with no downstream consumer.

Community Discussion (6 comments)

Srikantha 👍 1 Selected: CDE
C. VPC Flow Logs Flow logs capture network traffic in your VPC, including RDP traffic (TCP port 3389). This is the only way to detect RDP session attempts from a network perspective without needing to install agents on the instances. D. CloudWatch Logs destination for flow logs To analyze flow logs, you must send them somewhere — CloudWatch Logs is a common destination. Once in CloudWatch Logs, you can search and filter for RDP traffic patterns. E. Metric filter on the log group You can create a CloudWatch metric filter to count log events that match RDP connections. Filter pattern would look for destination port 3389 and action "ACCEPT".
Ky_24 👍 3 Selected: CDE
C. Create a flow log in VPC Flow Logs. • Why? VPC Flow Logs capture information about the traffic to and from network interfaces in your VPC. This is crucial for identifying and analyzing RDP sessions, which use TCP port 3389 by default. D. Create an Amazon CloudWatch Logs log group. Specify the log group as a destination for the flow log. • Why? The captured VPC Flow Logs must be stored in a destination to enable analysis. Specifying a CloudWatch Logs log group allows for centralized storage and querying of logs. E. Create a log group metric filter. • Why? A metric filter enables you to extract specific metrics from the flow logs. You can filter for traffic using port 3389 (RDP) and create a metric to count the sessions.
luisfsm_111 👍 3 Selected: CDE
I see CDE, no need for EventBridge
nqg54118 👍 2 Selected: CDE
You can use a subscription filter with Amazon Kinesis Data Streams, AWS Lambda, or Amazon Data Firehos https://docs.aws.amazon.com/ja_jp/AmazonCloudWatch/latest/logs/SubscriptionFilters.html
f4b18ba 👍 1 Selected: CE
By using an Amazon ECR pull through cache rule (Option C) and setting up the necessary VPC endpoints for private ECR (Option E) and S3 (Option F), the company can: Eliminate Internet Access: Remove NAT gateways and internet gateways from the VPC. Maintain Image Access: Allow ECS tasks to pull images from both private and public ECR repositories without internet access. Ensure Image Updates: Automatically receive updates to public images within 24 hours via the pull through cache. Minimize Operational Overhead: Avoid complex setups with additional services like CodeBuild, Lambda, or custom scripts.
uncledana 👍 1
The best approach for collecting metrics about RDP sessions is to use VPC Flow Logs, send them to CloudWatch Logs, and then create a metric filter to extract the relevant information (such as RDP traffic on port 3389). Option B, D, and E cover the necessary steps for implementing this solution.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

To count how many RDP sessions employees initiate each day, the solution must capture the network connections themselves. Creating a VPC Flow Log records traffic metadata for the network interfaces in the VPC, which includes the RDP connections on TCP port 3389 (C). Amazon CloudWatch Logs is a supported flow log destination, so specifying a CloudWatch Logs log group as the destination places that flow log data into CloudWatch where it can be queried (D). Creating a log group metric filter over that log group counts the records matching the RDP session pattern and emits a metric, which is what provides the daily session count (E). C, D, and E together form the data path from network capture to a countable metric.

Why the Other Options Are Wrong

A creates an EventBridge rule reacting to EC2 Instance State-change Notification events and B adds a CloudWatch Logs log group as that rule's target. Instance state-change events capture instance lifecycle transitions such as running, shutting down, and terminated, not network connections, so neither can produce a count of RDP sessions; luisfsm_111 explicitly noted that no EventBridge is needed. nqg54118 suggested a subscription filter targeting Kinesis Data Streams, Lambda, or Firehose, which would stream the log events to another service for processing, but the requirement is a metric count for the log data already in CloudWatch, which a metric filter produces without any additional consumer. C, D, and E are the correct combination.

Community Comment Notes

Community voted C,D,E (90). Srikantha and Ky_24 explained that VPC Flow Logs capture traffic including RDP on TCP port 3389 and are the way to detect session activity from a network perspective. luisfsm_111 pointed out that no EventBridge rule is needed at all, which eliminates A and B. One comment referenced an unrelated ECR pull through cache scenario, which does not apply here.

Official Reference

Related Analysis

Practice All DOP-C02 Questions

Access 85 questions with complete answers and detailed explanations.

View Full DOP-C02 Practice Test →

← Back to DOP-C02 Study Guide