A municipal security operations center needs flow-level visibility of east-west traffic across Transit Gateway attachments to investigate anomalous paths between department VPCs. Which monitoring approach best supports this investigation?
Select an answer to reveal the explanation.
Short Explanation
When east-west traffic goes weird, you need a flight recorder—not a spreadsheet of last month's spend. Transit Gateway and VPC Flow Logs show who talked to whom across attachments. Turning logging off to save pennies makes investigations guesswork.
Full Explanation
Transit Gateway Flow Logs capture information about IP traffic moving through Transit Gateway attachments, which is essential for auditing and troubleshooting east-west paths in hub-and-spoke municipal networks. VPC Flow Logs complement attachment-level visibility inside individual VPCs. Centralizing these logs in a security or logging account supports SOC investigation. Cost reports and informal reviews do not provide packet-flow telemetry, and TGW/VPC flow logging is the AWS-native mechanism for this visibility.