AWS Certified CloudOps Engineer Associate SOA-C03 Practice Question

An operations engineer needs to verify that the company's AWS Network Firewall deployment continues to inspect every packet that traverses a set of VPCs and that no one has removed or modified rule groups. The engineer must also be able to trace individual connection attempts when troubleshooting. Which approach meets these auditing requirements in a single AWS account?

  • Enable VPC flow logs for all subnets inspected by the firewall and stream them to Amazon S3 Glacier for long-term retention.

  • Configure AWS Firewall Manager policies to automatically audit rule groups and aggregate all firewall logs to S3.

  • Enable both FLOW and ALERT log types on every firewall and send the logs to CloudWatch Logs. Turn on AWS Config with the managed rules that evaluate Network Firewall firewalls, firewall policies, and rule groups.

  • Enable only the FLOW log type on each firewall, send the logs to CloudWatch Logs, and rely on CloudTrail to detect configuration changes.

AWS Certified CloudOps Engineer Associate SOA-C03
Networking and Content Delivery
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot