AWS SYS OPS VPC Flashcards
PASS ON FIRST TRY EXAM
AMAZON VPC IS THE ______ LAYER OF EC2
NETWORKING
VPC SPANS ALL _____ IN A REGION.
AZs
PARTS OF A VPC:
- IP SPECIFICATIONS
- SUBNETS
- SECURITY GROUPS
- ROUTE TABLES
- NACLs
______ AND ____ ARE USED TO PROTECT AWS RESOURCES IN EACH SUBNET
SECURITYGROUPS(INSTANCE LEVE)
NACLs(SUBNET LEVEL)
EXPAND VPC BY ADDING
SECONDARY IP RANGES
ON-PREM CONNECTS TO ____ WHICH CONNECTS TO VPC
MANAGED VPN CONNECTION
VPN CONNECTION CONSISTS OF :
VIRTUAL PRIVATE GATEWAY: VPN concentrator on Amazon side of VPN connection, attached to VPC
CUSTOMER GATEWY: Physical device or software on your side of the VPN connected
AWS PRIVATELINK
Privately connect your VPC to supported AWS services, services hosted by other AWS accounts( VPC ENDPOINTS) and supported AWS Marketplace partner services.
Does traffic with AWS PRIVATELINK leave the AWS NETWORK?
NEGATIVE, GHOSTRIDER
3 SUBNET TYPES
Public (IGW)
Private (no IGW)
VPN-only Subnet (has a virtual private gateway instead)
/28 has how many IP address
16 (this is an interview question)
/16 has how many IP address
65, 536
which IP addresses in each subnet CIDR block are NOT AVAIABLE FOR YOU AND CAN NOT BE ASSIGNED TO AN INSTANCE
First 4 and the LAST IP addy can not be used.
CIDR BLOCK IS READY FOR USE WHEN IT IS IN ____
ASSOCIATED STATE
EACH SUBNET MUST BE ASSOCIATED WITH A
ROUTE TABLE, WHICH SPECIFIED THE ALLOWED ROUTES FOR OUTBOUND TRAFFIC LEAVING THE SUBNET