Advanced VPC Flashcards
What do VPC Flow logs do?
Capture metadata travelling through a VPC
What 3 capture points can be used with flow logs?
VPC -> Subnet -> ENI. Data is captured from capture point down.
What is the main purpose of an Egress Only Internet Gateway?
Deny all inbound traffic to IPv6 addresses in a VPC
VPC Gateway Endpoints provide private access to __ and ________
S3 and DynamoDB
What controls what a VPC Gateway Endpoint can acccess?
An Endpoint policy.
True or False: You can access S3 buckets in a different region than VPC using VPC Gateway Endpoints.
False
What is a VPC Interface Endpoint used for?
Providing private access to AWS Public Services (not S3 DDB)
At what level are VPC Interface endpoints attached?
The subnet level.
__________ is a direct encrypted network link between EXACTLY two VPCs.
VPC peering
True or False: VPC peering is transitive (e.g. A- >B, B->C => A->C)
False