What's changed: In-scope coverage: added ops/notification/governance (EventBridge/SNS/SQS/Health Dashboard/Trusted Advisor/Well-Architected/Management Console/Control Tower)
5.2Monitoring Tools and Reachability
Measure state—understand CloudWatch metrics/alarms, Reachability Analyzer, Network Access Analyzer, and Traffic Mirroring. Choose the tool that matches your question.
There are several tools for network monitoring. Choose based on what you want to know—a trend, reachability, or packet contents.
5.2.1Match the tool to the question
- CloudWatch metrics/alarms: monitor metrics over time for NAT/ELB/VPN and alert on thresholds.
- Reachability Analyzer: statically analyzes config (routes/SG/NACL) to determine "can A reach B?".
- Network Access Analyzer: checks for paths that should not be reachable, finding unintended exposure.
- Traffic Mirroring: copies actual packets to IDS/packet capture for deep analysis.
Common on ANS-C01: find why something is unreachable from config = Reachability Analyzer, check for unintended reachable paths = Network Access Analyzer, metric trends/alerts = CloudWatch, and packet analysis = Traffic Mirroring. Note the difference between live testing and static config analysis.
Continue reading — free sign-up
You're reading the free preview. Sign up free to read this section in full, plus every chapter (including 4+) and all questions.

