Certified Solutions Architect VPC Networking and Security Flashcards
7 cards from real AWS practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Certified Solutions Architect VPC Networking and Security flashcards as text
A team needs to privately access AWS services like S3 from their VPC without internet traffic leaving the AWS network. Which feature enables this?
Answer: VPC Endpoints
VPC Endpoints allow private connectivity to AWS services from within a VPC without requiring an internet gateway, NAT device, or VPN connection.
A Network ACL rule has been configured to DENY traffic on port 443 with rule number 100, and another rule ALLOWs the same traffic with rule number 200. What is the result?
Answer: Traffic is denied because lower rule numbers are evaluated first
NACLs evaluate rules in order from lowest to highest rule number, so rule 100 (DENY) is processed before rule 200 (ALLOW), resulting in the traffic being denied.
What type of VPC endpoint should be used to connect to AWS services that are powered by AWS PrivateLink?
Answer: Interface Endpoint
Interface Endpoints use AWS PrivateLink to create elastic network interfaces with private IPs in your VPC, enabling private connectivity to supported AWS services.
A company uses VPC peering between two VPCs (A↔B and B↔C). Can VPC A communicate with VPC C through VPC B?
Answer: No, VPC peering does not support transitive peering
VPC peering does not support transitive routing — VPC A cannot route traffic to VPC C through VPC B; direct peering between A and C would be required.
Which component must be added to a route table for a public subnet's EC2 instances to reach the internet?
Answer: A route to an Internet Gateway
A public subnet requires a route table entry pointing 0.0.0.0/0 to an Internet Gateway to allow EC2 instances to send and receive internet traffic.
An architect is designing a VPC and needs to ensure that a subnet in us-east-1a is isolated from another subnet in us-east-1b. Which resource enforces this boundary?
Answer: Network ACL
Network ACLs control traffic at the subnet boundary and can be used to filter traffic between subnets in different availability zones within a VPC.
What is a key difference between a Gateway VPC Endpoint and an Interface VPC Endpoint?
Answer: Gateway endpoints only support S3 and DynamoDB and are free; Interface endpoints support most other services and have an hourly cost
Gateway endpoints are free and only support S3 and DynamoDB using route table entries, while Interface endpoints use ENIs and support many other AWS services at an hourly charge.