Answer – A,B and C
To create a flow log, you specify the resource for which you want to create the flow log, the type of traffic to capture (accepted traffic, rejected traffic, or all traffic), the name of a log group in CloudWatch Logs to which the flow log will be published, and the ARN of an IAM role that has sufficient permission to publish the flow log to the CloudWatch Logs log group.
Option D is INCORRECT because the kibana dashboard is a visualization tool and is used only to view the log data
For more information on VPC Flow logs , please refer to the below URL:
http://docs.aws.amazon.com/AmazonVPC/latest/UserGuide/flow-logs.html