A SOC is redesigning east-west visibility after moving half its workloads to a cloud VPC. Analysts can see north-south traffic at the perimeter firewall but cannot see traffic between application tiers inside the VPC. Which change most directly restores the missing visibility?
Select an answer to reveal the explanation.
Short Explanation
Think about where the traffic actually goes. If two app tiers talk to each other inside the VPC, that conversation never crosses your perimeter — so no amount of turning up perimeter logging will show it to you. You need a sensor where the traffic lives, and in a cloud VPC that's flow logs on the subnets themselves.
Full Explanation
East-west traffic between tiers in the same VPC is switched inside the virtual network and never transits the perimeter enforcement point, so the perimeter firewall has no record of it at any verbosity. VPC flow logging is the native telemetry source for that path: it records source and destination address, port, protocol, packet and byte counts, and accept/reject disposition per flow, which is enough to establish who talked to whom and to baseline normal inter-tier behavior. Forwarding those records to the SIEM puts them beside existing perimeter and endpoint data so correlation rules can span both planes. Raising perimeter log verbosity fails because verbosity changes the detail of events the device already sees, not the set of flows it observes. Adding a second perimeter firewall in HA improves availability at the same chokepoint and still observes only north-south traffic, so the blind spot is unchanged. Shortening DHCP leases makes correlation harder, not easier, because a given address maps to more hosts over time. Operational check: pick a known inter-tier connection, confirm it appears in the flow log within the aggregation interval, and verify the SIEM parses the disposition field before relying on it for detection.