ADVANCED VPC Networking Flashcards

1
Q

allowing the monitoring of traffic flow to and from interfaces within a VPC

A

VPC Flow Logs

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

VPC only caputures metadata and not contents

A

True

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

When attached to a VPC, flow logs monitor

A

All ENI in VPC

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

When attached to a Subnet, flow logs monitor

A

All ENI in Subnet

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Can Flow logs be attached to ENIs directly?

A

Yes

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Are Flow Logs realtime?

A

NO

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

VPC Flow Log destinations are S3 or CloudWatch Logs

A

True

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Can Athena be used to query VPC Flow logs in S3?

A

Yes

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Do flow logs monitor packet Contents?

A

No

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Allow outbound (and response) only access to the public AWS services and Public Internet for IPv6-enabled instances or other VPC-based services

A

Egress-Only internet gateways

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Allows private IPs to access public networks without allowing externally initiated connections in

A

NAT

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

Internet Gateway IPv6 allows all IPS in and out

A

True

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

type of VPC endpoint which allow access to S3 and DynamoDB without using public addressing

A

Gateway Endpoints

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

added to route table and points the route table to it

A

Gateway Endpoints

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

Gateway endpoints are Highly available across all AZs in a region

A

True

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

Controls which things can be connected to by the gateway endpoint

A

Endpoint Policies

17
Q

Can Gateway Endpoints access cross-region services?

A

No

18
Q

used to allow private IP addressing to access public AWS services apart from S3 and DynamoDb

A

Interface Endpoints

19
Q

Are Interface Endpoints highly available by default?

A

No

20
Q

1 Endpoint to 1 Subnet Per used AZ to get High Availability

A

True

21
Q

Interface Endpoints only support TCP and IPv4

A

True

22
Q

Do interface Endpoints use PrivateLink?

A

Yes

23
Q

Interface Endpoints provides a NEW service endpoint DNS

A

True

24
Q

One single DNS name that works with whatever AZ you’re using to access the interface endpoint

A

Endpoint Regional DNS

25
Q

Resolves to one specific interface in one specific availability zone

A

Endpoint Zonal DNS

26
Q

OVerrides the default DNS for services

A

PrivateDNS

27
Q

Associates a private R53 hosted zone to the VPC changing the default service DNS to resolve to the interface endpoint ip

A

Private DNS

28
Q

Uses prefix lists and route tables

A

Gateway Endpoints

29
Q

Uses DNS and a private IP address

A

Interface Endpoints

30
Q

networking connection between two VPCs that enables you to route traffic between them using private IPv4 addresses or IPv6 addresses

A

VPC peering

31
Q

One peering connection links two and only two VPCs

A

True

32
Q

Does VPC peering work across region/cross account

A

Yes

33
Q

Does VPC Perring support transitive peering?

A

No

34
Q

are route tables at both sides of the peering connection needed?

A

Yes

35
Q

Can VPC peering connections be created where there is overlap in the VPC CIDRS?

A

No