AWS Certified CloudOps Engineer Associate SOA-C03 Practice Question
A company runs an internal HTTP API on several EC2 instances in a private subnet. Clients in multiple branch offices reach the API through an AWS Site-to-Site VPN that terminates on a virtual private gateway (VGW). Users report that some requests now take more than 3 seconds, but the problem is intermittent and hard to reproduce. As the CloudOps engineer, you must create a near-real-time dashboard that helps network engineers pinpoint whether the latency originates on-premises or inside AWS. Which solution meets the requirement with the LEAST operational overhead?
Turn on detailed monitoring for the VPN connection and add the TunnelDataIn and TunnelDataOut metrics to a CloudWatch dashboard.
Install the Amazon CloudWatch agent on each EC2 instance, enable the netstat plug-in, and create a dashboard from the collected metrics.
Enable VPC Flow Logs with a custom format that includes the start and end fields, stream the logs to CloudWatch Logs, create a Logs Insights query that calculates average and p99 latency (end - start) by source IP, and add the query results to a CloudWatch dashboard.
Deploy AWS Internet Monitor, attach the VPN connection as a monitored resource, and display the internet performance panel on a CloudWatch dashboard.
The VGW automatically publishes CloudWatch metrics such as TunnelDataIn and TunnelDataOut, but latency-specific metrics are not available. CloudWatch Internet Monitor only supports internet-facing resources, not private VPN connections. The CloudWatch agent on each EC2 instance would add operational overhead and would not easily isolate latency across the VPN. VPC Flow Logs in CloudWatch Logs contain start and end timestamps for each captured flow. These can be used by CloudWatch Logs Insights to calculate the duration, which represents the connection-level latency. A Logs Insights query can then calculate and aggregate this latency by source IP and be visualized on a CloudWatch dashboard, providing the required visibility with minimal management effort.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What are VPC Flow Logs, and how do they help in network troubleshooting?
Open an interactive chat with Bash
What is CloudWatch Logs Insights, and what role does it play in analyzing VPC Flow Logs?
Open an interactive chat with Bash
How does streaming VPC Flow Logs to CloudWatch reduce operational overhead?
Open an interactive chat with Bash
AWS Certified CloudOps Engineer Associate SOA-C03
Networking and Content Delivery
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .