Advanced VPC Flashcards

1
Q

What do VPC Flow logs do?

A

Capture metadata travelling through a VPC

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What 3 capture points can be used with flow logs?

A

VPC -> Subnet -> ENI. Data is captured from capture point down.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What is the main purpose of an Egress Only Internet Gateway?

A

Deny all inbound traffic to IPv6 addresses in a VPC

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

VPC Gateway Endpoints provide private access to __ and ________

A

S3 and DynamoDB

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What controls what a VPC Gateway Endpoint can acccess?

A

An Endpoint policy.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

True or False: You can access S3 buckets in a different region than VPC using VPC Gateway Endpoints.

A

False

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What is a VPC Interface Endpoint used for?

A

Providing private access to AWS Public Services (not S3 DDB)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

At what level are VPC Interface endpoints attached?

A

The subnet level.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

__________ is a direct encrypted network link between EXACTLY two VPCs.

A

VPC peering

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

True or False: VPC peering is transitive (e.g. A- >B, B->C => A->C)

A

False

How well did you know this?
1
Not at all
2
3
4
5
Perfectly