AWS SYS OPS VPC Flashcards
PASS ON FIRST TRY EXAM
AMAZON VPC IS THE ______ LAYER OF EC2
NETWORKING
VPC SPANS ALL _____ IN A REGION.
AZs
PARTS OF A VPC:
- IP SPECIFICATIONS
- SUBNETS
- SECURITY GROUPS
- ROUTE TABLES
- NACLs
______ AND ____ ARE USED TO PROTECT AWS RESOURCES IN EACH SUBNET
SECURITYGROUPS(INSTANCE LEVE)
NACLs(SUBNET LEVEL)
EXPAND VPC BY ADDING
SECONDARY IP RANGES
ON-PREM CONNECTS TO ____ WHICH CONNECTS TO VPC
MANAGED VPN CONNECTION
VPN CONNECTION CONSISTS OF :
VIRTUAL PRIVATE GATEWAY: VPN concentrator on Amazon side of VPN connection, attached to VPC
CUSTOMER GATEWY: Physical device or software on your side of the VPN connected
AWS PRIVATELINK
Privately connect your VPC to supported AWS services, services hosted by other AWS accounts( VPC ENDPOINTS) and supported AWS Marketplace partner services.
Does traffic with AWS PRIVATELINK leave the AWS NETWORK?
NEGATIVE, GHOSTRIDER
3 SUBNET TYPES
Public (IGW)
Private (no IGW)
VPN-only Subnet (has a virtual private gateway instead)
/28 has how many IP address
16 (this is an interview question)
/16 has how many IP address
65, 536
which IP addresses in each subnet CIDR block are NOT AVAIABLE FOR YOU AND CAN NOT BE ASSIGNED TO AN INSTANCE
First 4 and the LAST IP addy can not be used.
CIDR BLOCK IS READY FOR USE WHEN IT IS IN ____
ASSOCIATED STATE
EACH SUBNET MUST BE ASSOCIATED WITH A
ROUTE TABLE, WHICH SPECIFIED THE ALLOWED ROUTES FOR OUTBOUND TRAFFIC LEAVING THE SUBNET
YOU CAN ASSOCIATED UP TO ____ SECURITY GROUPS TO AN _____
5 SECURITY GROUPS TO AN INSTANCE IN YOUR VPC
WHEN YOU CREATE A SECURITY GROUP, IT HAS _________ AND
NO INBOUND RULES AND INCLUDES AN OUTBOUND RULE THAT ALLOWS ALL OUTBOUND TRAFFIC BY DEFAULT
NACLs can connect to multiple subnets , however_____
a subnect can be associated with one NACL
ROUTE TABLES:
A CERTAIN SET OF RULES, CALLED ROUTES, THAT DETERMINE WHERE NETWORK TRAFFIC IS DIRECTED
SET VPC enableDnsHostnames and enableDnsSupport to true so that
your instances recieve a public DNS hostname and Amazon-provided DNS server can resolve Amazon-provided private DNS hostnames
if you use custom DNS domain names defined in a privated hosted zone in Route 53, then the
enableDnsHostnames and enableDnsSupport attributes must be set to true
You are limited to _____ Elastic IP Addresses
5
an Elastic IP Address is a
static public IPv4 addy
AWS imposes a small hourly charge for EIPs that
are not being used
VPC ENDPOINTS:
PRIVATELY CONNECT YOUR VPC TO SUPPORTED AWS SERVICES
TWO TYPES OF ENDPOINTS
INTERFACE /GATEWAY
INTERFACE ENDPOINTS
- ENI WITH A PRIVATE IP, USED AS AN ENTRY POINT FOR TRAFFIC DESTINED TO A SUPPORTED SERVICE
- DO NOT SUPPORT THE USE OF ENDPOINT POLICIES
- SUPPORTS IPV4 TCP TRAFFIC ONLY
GATEWAY ENDPOINTS
- TARGET FOR A SPECIFIED ROUTE IN YOUR ROUTE TABLE, USED FOR TRAFFIC DESTINED TO A SUPPORTED AWS SERVICE
- YOU CAN CREATE MULTIPLE ENDPOINTS IN A SINGLE VPC.
- SUPPORTED WITHIN THE SAME REGION
- YOU CAN MODIFY ENDPOINT POLICY
- IPV4 TRAFFIC ONLY
- ABILITY FOR MULTIPLE SCHEMA CHANGES
- DATABASE SHOULD BE DURABLE
- CHANGES TO THE DATABASE SHOULD NOT RESULT IN DOWNTIME
AURORA