# AWS242 Supplied Network Evidence

All values are fictional/redacted. Do not run corrective changes.

## Investigation A: accepted SYN, unhealthy service

Expected tuple: app ENI to API ENI, TCP 443, same Region.

Flow-log configuration:

- Source ENI and destination ENI are covered with `ALL`.
- Custom fields include interface, flow direction, interface-level tuple, action, flags, times, and status. Packet-level address fields were not configured and must be marked unavailable.
- Delivery status is `SUCCESS`; records have `log-status=OK`.

Records:

```text
12:00:04 eni-app egress 10.0.1.10 10.0.2.20 51514 443 6 3 180 2 ACCEPT OK
12:00:04 eni-api ingress 10.0.1.10 10.0.2.20 51514 443 6 3 180 2 ACCEPT OK
12:00:05 eni-api egress 10.0.2.20 10.0.1.10 443 51514 6 1 60 4 ACCEPT OK
12:00:05 eni-app ingress 10.0.2.20 10.0.1.10 443 51514 6 1 60 4 ACCEPT OK
```

Reachability Analyzer at 12:07 says reachable through both subnet route tables, NACLs, and SGs.

OS evidence at 12:03:

```text
ss -lntp: no process listening on :443
systemd: api.service failed after invalid certificate path
```

Tasks:

1. Interpret SYN and RST without claiming payload visibility.
2. Explain why Flow Logs and RA agree but the application fails.
3. Identify correction, rollback, and application acceptance evidence.
4. Define an alarm that catches process failure before connection complaints.

## Investigation B: governance finding without observed traffic

Requirement: production database ENIs must not have a potential path from an internet gateway on TCP 5432.

NAA scope:

- Match source resource type InternetGateway.
- Match destination resources tagged `Environment=prod,Role=database`.
- Match TCP destination port 5432.
- Exclude only one approved scanner ENI, although an internet gateway can never be that approved source.

Analysis in account A, `ap-south-1`, reports one finding:

```text
igw -> public route table -> subnet NACL -> database ENI SG
SG source 0.0.0.0/0 TCP 5432
database ENI has public IPv4
```

Flow Logs for the preceding hour contain `NODATA`. No client attempt is known.

Reachability Analyzer, using the internet gateway as source and database ENI as destination on TCP 5432, reports reachable.

Tasks:

1. Explain potential path versus observed use.
2. Decide whether `NODATA` reduces the policy violation.
3. Evaluate whether the exclusion is logically useful and govern it.
4. State the smallest correction and prove both modeled isolation and app continuity.
5. Explain what the account/Region-specific NAA result does not cover.

## Evidence-conflict drill

For each statement, accept, reject, or qualify it:

1. “The flow was accepted, so the API returned 200.”
2. “RA is reachable, so packets crossed during the incident.”
3. “NAA found a path, so an attacker used it.”
4. “There are no records, so no packets existed.”
5. “No NAA findings means the organization is isolated.”
6. “A synthetic monitor fixes hybrid failover.”
