Certified Solutions Architect VPC Networking and Security Flashcards
7 cards from real AWS practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Certified Solutions Architect VPC Networking and Security flashcards as text
A company needs to connect their on-premises data center to an AWS VPC with consistent, low-latency bandwidth. Which service provides a dedicated private connection?
Answer: AWS Direct Connect
AWS Direct Connect provides a dedicated private network connection from on-premises to AWS, bypassing the public internet for consistent performance.
Which VPC feature allows you to capture and log IP traffic going to and from network interfaces in your VPC for security analysis?
Answer: VPC Flow Logs
VPC Flow Logs capture information about IP traffic to and from network interfaces and can be published to CloudWatch Logs or S3.
A Solutions Architect needs to allow EC2 instances in a private subnet to download software updates from the internet without being directly reachable. What should they use?
Answer: NAT Gateway
A NAT Gateway allows instances in private subnets to initiate outbound internet traffic while preventing inbound connections from the internet.
What is the maximum number of security groups that can be associated with a single EC2 instance's network interface?
Answer: 5
By default, up to 5 security groups can be associated with a single network interface, though this limit can be increased.
A company wants to restrict traffic between subnets within their VPC based on subnet-level rules. Which feature should they implement?
Answer: Network ACLs
Network ACLs (NACLs) are stateless firewalls that control inbound and outbound traffic at the subnet level.
An application needs IPv6 connectivity for EC2 instances in a private subnet to communicate outbound to IPv6 internet resources. Which gateway should be used?
Answer: Egress-Only Internet Gateway
An Egress-Only Internet Gateway allows IPv6 traffic from instances to the internet but prevents the internet from initiating IPv6 connections to those instances.
Which AWS service enables you to centrally manage and connect multiple VPCs and on-premises networks through a single hub?
Answer: AWS Transit Gateway
AWS Transit Gateway acts as a cloud router connecting multiple VPCs and on-premises networks through a single gateway, simplifying network architecture.