ADVANCED VPC Networking Flashcards
allowing the monitoring of traffic flow to and from interfaces within a VPC
VPC Flow Logs
VPC only caputures metadata and not contents
True
When attached to a VPC, flow logs monitor
All ENI in VPC
When attached to a Subnet, flow logs monitor
All ENI in Subnet
Can Flow logs be attached to ENIs directly?
Yes
Are Flow Logs realtime?
NO
VPC Flow Log destinations are S3 or CloudWatch Logs
True
Can Athena be used to query VPC Flow logs in S3?
Yes
Do flow logs monitor packet Contents?
No
Allow outbound (and response) only access to the public AWS services and Public Internet for IPv6-enabled instances or other VPC-based services
Egress-Only internet gateways
Allows private IPs to access public networks without allowing externally initiated connections in
NAT
Internet Gateway IPv6 allows all IPS in and out
True
type of VPC endpoint which allow access to S3 and DynamoDB without using public addressing
Gateway Endpoints
added to route table and points the route table to it
Gateway Endpoints
Gateway endpoints are Highly available across all AZs in a region
True