Amazon Virtual Private Cloud (VPC) Flashcards

1
Q

VPC provides complete control over the _______ __________ environment

A

VPC provides complete control over the virtual networking environment

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

VPCs are _____ wide service

A

VPCs are region wide service

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

A default VPC is created in each _____ with a ____ in each AZ

A

A default VPC is created in each region with a subnet in each AZ

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

By default, you can create up to ____ VPCs per region

A

By default, you can create up to Five VPCs per region

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Public subnets are subnets that have which setting set to “Yes”

A

Public subnets are subnets that have which setting set to “Yes”

  • “Auto-assign public IPv4 address” set to “Yes”
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Public subnet route table has an ________ _______ attached

A

Public subnet route table has an Internet Gateway attached

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

When you create a VPC, you must specify a ____ of ____ addresses for the VPC in the form of a ____ block

A

When you create a VPC, you must specify a range of Ipv4 addresses for the VPC in the form of a CIDR block

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

A VPC spans all the ____ _____ in the region

A

A VPC spans all the ____ _____ in the region

Availability Zones

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

You have ___ _______ over who has access to the AWS resources inside your VPC

A

You have ___ _______ over who has access to the AWS resources inside your VPC

full control

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Routers interconnect subnet and direct traffic between (4)

A

Internet gateways

NAT gateways

Virtual private gateways

Subnets

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

VPC Endpoints allows private connectivity between services ______ in ___

A

VPC Endpoints allows private connectivity between services hosted in AWS

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

Egress-only Internet Gateway is a stateful gateway that provides egress-only access for ____ traffic from the ___ to the internet

A

Egress-only Internet Gateway is a stateful gateway that provides egress-only access for IPv6 traffic from the VPC to the internet

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

Peering Connection enables you to route traffic via private IP addresses between two ______ _____

A

Peering Connection enables you to route traffic via private IP addresses between two peered VPCs

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

NAT Gateway features: (3)

_______ available

Provides resources in _______ subnet access to the ______ internet

______ Network Address Translation (NAT) service

A

Highly available

Provides resources in private subnet access to the public internet

Managed Network Address Translation (NAT) service

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

Your side of the VPN connection is called the ________ Gateway

A

Your side of the VPN connection is called the Customer Gateway

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

CIDR block size can be between ____ and _____

A

CIDR block size can be between /16 and /28

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
17
Q

You cannot ____ or _____ the size of an existing CIDR blcok

A

You cannot increase or decrease the size of an existing CIDR block ;

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
18
Q

The first ____ and ____ IP addresses in a subnet CIDR block are ___ _________ for use

A

The first four and last IP addresses in a subnet CIDR block are not available for use

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
19
Q

AWS recommends you use CIDR blocks from the ___ _____ ranges

A

AWS recommends you use CIDR blocks from the RFC 1918 ranges

20
Q

In order to work properly, VPC Peering requires non-overlapping CIDR blocks across all ____ in all _____ and _______ you want to connect

A

In order to work properly, VPC Peering requires non-overlapping CIDR blocks across all VPCs in all regions and accounts you want to connect

21
Q

Flow Logs capture information about traffic to and from _______ interfaces in a ___

A

Flow Logs capture information about traffic to and from network interfaces in a VPC

22
Q

The ________ Gateway is the Amazon ___ side of a connection to the public Internet.

A

The Internet Gateway is the Amazon VPC side of a connection to the public Internet.

23
Q

Flow log data is stored using __________ Logs or ___

A

Flow log data is stored using CloudWatch Logs or S3

24
Q

Flow logs can be created at the following levels: (3)

A

Network interface

Subnet

VPC

25
Q

Hardware VPN Connection is a hardware-based connection between your Amazon VPC and your ____ center, ____ network, or __-_______ facility

A

Hardware VPN Connection is a hardware-based connection between your Amazon VPC and your data center, home network, or co-location facility

26
Q

Security Groups operate at the _______ level while Network ACL operate at the ______

A

Security Groups operate at the instance level while Network ACL operate at the subnet

27
Q

Which is stateful and stateless between SGs and ACLs?

A

ACL: Stateless

SG: Stateful

28
Q

SG’s support _____ rules only and evaluates ___ rules regardless of _____

A

SG’s support deny rules only and evaluates all rules regardless of order

29
Q

ACL’s support _____ and _____ rules and processes rules in _____

A

ACL’s support allow and deny rules and processes rules in order

30
Q

Network ACL rules ___________ _____ to all instances in the associated subnets.

A

Network ACL rules ___________ _____ to all instances in the associated subnets.

automatically apply

31
Q

VPN CloudHub provides a way to link _____ ______ for a backup or primary WAN access to AWS resources and ____ _____

A

VPN CloudHub provides a way to link remote offices for a backup or primary WAN access to AWS resources and each other

32
Q

VPN CloudHub connects locations in a ___ and _____ manner using AWS Virtual Private Gateway

A

VPN CloudHub connects locations in a ___ and _____ manner using AWS Virtual Private Gateway

Hub and Spoke

33
Q

If you have resources in multiple AZ and they share a NAT Gateway. What will happen if the AZ where the NAT Gateway is goes down?

A

All connected resources will lose internet access

34
Q

What makes an application or process stateful vs. stateless depends on whether or not it _____ data ____ _____

A

What makes an application or process stateful vs. stateless depends on whether or not it stores data over time.

35
Q

SG’s are stateful, meaning if you send a request from your instance, the response traffic for that request is _______ to flow in regardless of _______ ____

A

SG’s are stateful, meaning if you send a request from your instance, the response traffic for that request is allowed to flow in regardless of inbound rules.

36
Q

By default, custom Network ACL’s deny all inbound and outbound traffic until you ___ _____

A

By default, custom Network ACL’s deny all inbound and outbound traffic until you add rules.

37
Q

Each subnet in VPC must be associated with a network ACL. If you don’t explicitly associate a subnet with a network ACL, then that subnet is ____________ associated with the ______ network ACL.

A

Each subnet in VPC must be associated with a network ACL. If you don’t explicitly associate a subnet with a network ACL, then that subnet is automatically associated with the default network ACL.

38
Q

You can associate a network ACL with how many subnets?

A

multiple subnets.

39
Q

When you associate a network ACL with a subnet, what happens to the previous ACL association?

A

the previous association is removed.

40
Q

A Network ACL being stateless means responses to inbound traffic are subject to the rules for outbound traffic and vice versa

A

A Network ACL being stateless means responses to inbound traffic are subject to the _____ for _______ traffic and ____ ____

41
Q

VPC endpoints allow you to connect AWS services without leaving the Amazon ________ _______

A

VPC endpoints allow you to connect AWS services without leaving the Amazon internal network

42
Q

With AWS, you can choose between two VPC endpoint types- ________ endpoint or ________ endpoint - to securely access your __ ______ using a private network

A

With AWS, you can choose between two VPC endpoint types- gateway endpoint or interface endpoint - to securely access your S3 buckets using a private network

43
Q

You can peer VPC with VPCs in the ____ account and with ____ AWS accounts

A

You can peer VPC with VPCs in the same account and with other AWS accounts

44
Q

If you need to connect tens, hundreds, or thousands of customer VPCs, what service should you use instead of VPC peering

A

AWS PrivateLink

45
Q

When using VPC endpoints, Gateway Endpoint only supports __ and ________

A

When using VPC endpoints, Gateway Endpoint only supports S3 and DynamoDB

46
Q

The ________ ________ Gateway is the Amazon VPC side of a ____ connection.

A

The Virtual Private Gateway is the Amazon VPC side of a VPN connection.