AWS Networking and Content Delivery Flashcards
7 cards from real AWS practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 AWS Networking and Content Delivery flashcards as text
Which AWS service allows you to create a private connection between your VPC and AWS services without traversing the public internet?
Answer: VPC Endpoint
VPC Endpoints allow private connectivity between your VPC and supported AWS services without requiring internet access, a NAT device, or VPN.
What is the maximum number of Elastic IP addresses you can allocate per AWS region by default?
Answer: 5
By default, AWS allows 5 Elastic IP addresses per region per account, though you can request an increase via a support case.
Which CloudFront feature lets you run code at edge locations in response to CloudFront events without provisioning servers?
Answer: Both A and B are correct
Both CloudFront Functions and Lambda@Edge allow running code at the edge; CloudFront Functions are lighter-weight and cheaper, while Lambda@Edge supports more complex logic.
In AWS Route 53, what routing policy would you use to route traffic to the resource with the lowest network latency for your users?
Answer: Latency-based routing
Latency-based routing directs users to the AWS region that provides the lowest latency based on actual network measurements.
What AWS Global Accelerator component serves as the entry point for client traffic and provides static anycast IP addresses?
Answer: Accelerator
The Accelerator in AWS Global Accelerator provides the static anycast IP addresses that serve as the global entry points for client traffic.
Which type of VPC endpoint is used specifically for Amazon S3 and DynamoDB without requiring an ENI?
Answer: Gateway Endpoint
Gateway Endpoints are used for S3 and DynamoDB and are added as a target in your route table rather than creating an ENI in your subnet.
When configuring a Network ACL in a VPC, what is a key behavioral difference compared to Security Groups?
Answer: NACLs are stateless; Security Groups are stateful
Network ACLs are stateless, meaning you must explicitly allow both inbound and outbound traffic, while Security Groups are stateful and automatically allow return traffic.