NETWORK AND HYBRID Flashcards

1
Q

What does DHCP Mean?

A

Dynamic Host Configuration Protocol

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What does DHCP Provide?

A

Auto Config for Network Resources

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Can DHCP Option Sets be edited once created?

A

No they are Immutable

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

How many VPCs can DHCP Option Sets be associated with?

A

0 or more VPC

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Whats the max number of Option Sets that can be attached to a vpc?

A

1

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Associating a new option set is immediate but changes take a DHCP Renew which takes time. True or False?

A

True

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Default Gateway is always subnet + what?

A

Subnet or VPC Router +1

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

AWS Supply Public and Private what?

A

DNS Names

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

To use custom domains, you need to use what in tandem?

A

Custom DNS Servers

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

VPC Routers equals what?

A

Virtual Router within a VPC

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

VPC Router is HA across what?

A

All Az’s in that Region

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

VPC Routers route traffic between where?

A

subnets from external networks into vpc

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

VPC Routers is controlled using what?

A

Route Table

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

Every subnet has a what

A

VPC Router Interface

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

VPC Router Interface uses what?

A

Subnet +1 Address

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

Route Tables Control what?

A

Routing Decisions

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
17
Q

VPC Routers direct on premises traffic at what?

A

Gateway

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
18
Q

VPC Routers direct on premises traffic at what?

A

Gateway

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
19
Q

VPC Routers direct traffic at public what?

A

Public Network Gateways

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
20
Q

Every VPC is created with a what?

A

Main Route Table

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
21
Q

Route Table is default for every what?

A

Subnet in VPC

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
22
Q

Subnets are associated with what?

A

One RT Main or Custom

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
23
Q

RT’s are associated with how many subnets?

A

0 or more

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
24
Q

Subnet has to have what?

A

One RT Main or Custom

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
25
Q

RT Controls what happens to what?? as it leaves subnets it is associated with?

A

Data

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
26
Q

Local Route tables are always there. They are uneditable and match VPC IPv4 an IPv6 CIDR Ranges. True or False?

A

True

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
27
Q

Higher Prefix Values are more specific and take what?

A

Higher Priority

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
28
Q

Default Route is what happens if nothing else what?

A

Matches

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
29
Q

Every Connection has 2 parts. which are these?

A

Request and Response

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
30
Q

Stateless is what?

A

2 Rules inverse of each other

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
31
Q

Requests always go to well know what?

A

Port

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
32
Q

Both Request and Response can be what?

A

In and Out

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
33
Q

Response will always be what of Request?

A

Inverse

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
34
Q

Any rules created for response needs full range of what?

A

Ephemeral Ports

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
35
Q

Stateful means?

A

Lower admin overhead

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
36
Q

Every subnet has an associated what?

A

ACL

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
37
Q

NACL Filter traffic crossing the subnet boundary where?

A

Inbound or Outbound

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
38
Q

Connection within a subnet arent impacted by what?

A

NACL’s

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
39
Q

NACL are what?

A

Stateless

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
40
Q

NACL Offer both what?

A

Explicit Deny and Allow

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
41
Q

Rules are processed in what?

A

Order

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
42
Q

Once rules are processed in order. What rule number is first?

A

Lowest rule number first

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
43
Q

Once rule match occurs, what happens?

A

Processing Stops

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
44
Q

If no rules match what happens?

A

Implicit Deny

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
45
Q

Since NACL are stateless every request and response need a rule. What rule do they need?

A

1 Inbound and 1 Outbound

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
46
Q

VPC are created with what by default? e.g rules etc…

A

NACL

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
47
Q

Stateful detects response traffic what?

A

Automatically

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
48
Q

Stateful has no explicit deny only what?

A

Allow and Implicit Deny

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
49
Q

Stateful cant block what?

A

Specific Bad Actors

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
50
Q

Stateful are attached to what?

A

ENI

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
51
Q

Stateful allow rule cannot not be what?

A

Overwritten / no Explicit Deny

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
52
Q

In Stateful how are IP changed handled?

A

Automatically

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
53
Q

BGP AS System advertises the shortest path to a destination its aware of to all the other BGP routers its paired with.

True or False?

A

True

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
54
Q

What does AWS Global Accelerator do?

A

Moves AWS network closer to customer

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
55
Q

Customers enter the edge using what?

A

anycast IPs

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
56
Q

AWS Global Accelerator transits over AWS Back to where?

A

1+ locations

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
57
Q

AWS Global Accelerator can be use for NON what?

A

HTTP

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
58
Q

AWS Global Accelerator works over what?

A

TCP/UDP

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
59
Q

If you have any questions about caching what do you use instead of global accelerator?

A

Cloudfront

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
60
Q

If you have any questions about UDP/TCP Global Performance Optimization you use what?

A

AWS Global Accelerator

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
61
Q

VPN run over what?

A

Public Internet

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
62
Q

VPN is what if you design and implement it correctly?

A

Highly Available

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
63
Q

VPN are quick to provision. How long does it take?

A

less than a hour

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
64
Q

This VPN has no loading balancing and multi connection failover

A

Static VPN

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
65
Q

Has Multiple VPN connections Provide HA and traffic distribution

A

Dynamic VPN

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
66
Q

In Dynamic VPN if route propagation is enabled means routes are added to RT… what?

A

Automatically

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
67
Q

What is the VPN speed limitation?

A

1.25 GBPS

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
68
Q

VPN Latency is what?

A

Inconsistent

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
69
Q

VPN is used over the ?

A

Public Internet

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
70
Q

VPN Speed of setup is

A

Hours

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
71
Q

VPNs are how to connect one or more what?

A

Business Premises to AWS

72
Q

AWS Transit Gateway supports?

A

Transitive Routing

73
Q

AWS Transit Gateway is used to create?

A

Global Networks

74
Q

Use AWS Transit Gateway to share between accounts using

A

AWS Resource Access Manager

75
Q

AWS Transit Gateway is used to peer with different regions either?

A

Same or cross account

76
Q

AWS Transit Gateway offers less what?

A

Complexity

77
Q

A Transit Gateway has what by default?

A

Route Table (RT)

78
Q

All attachments in the TGW use the what for routing purposes?

A

Default RT

79
Q

All attachments in TGW propagate and add routes to what?

A

RT

80
Q

What doesnt have route propagation?

A

Peering Attachments

81
Q

What uses unique ASNs for future route propagation?

A

TGW

82
Q

Public over Private IP resolution is not supported over what?

A

Peers

83
Q

How many peering attachments per TWG?

A

50

84
Q

what is required in TGW?

A

Static Routes

85
Q

All attachments in TGW are associated with the same what?

A

Route Table

86
Q

All attachments propagate to the same what?

A

Route Table

87
Q

Attachments in TGW can only be associated with how many RTs?

A

1

88
Q

In TGW Route Tables can be associated with many what?

A

attachments

89
Q

Route Tables can be associated with what other gateways?

A

Internet Gateway and Virtual Private Gateway

90
Q

What are handled seperatly in a RT?

A

IPv4 and IPv6

91
Q

What is number 1 on priority of routes?

A

Longest Prefix

92
Q

Whats number 2 on priority for routes?

A

Static Routes

93
Q

whats number 3 on priority for routes?

A

Propagated Routes

94
Q

Peering between overlapping CIDR isnt supported where?

A

VPC Routing

95
Q

What is used to direct a IGW to take actions on inbound traffic such as forwarding it to a security appliance?

A

Gateway Route Table

96
Q

Without Gateway RT the IGW would forward any return traffic directly using what?

A

10.16.0.0/16 local route

97
Q

What is IPSEC?

A

A group of protocols

98
Q

What sets up secure tunnels across insecure networks between two peers (local and remote)

A

IPSEC

99
Q

IPSEC provides what?

A

Authentication and Encryption

100
Q

The data inside tunnels are what?

A

Encrypted on secure connection

101
Q

Asymmetric Encryption is what?

A

Slow but easy to exchange keys

102
Q

Symmetric is what?

A

fast but hard to exchange public keys

103
Q

What VPN has rule set match traffic?

A

Policy Based VPN

104
Q

What VPN has target matching using prefix?

A

Route Based VPN

105
Q

Site 2 Site has 2 Resilent what?

A

Public Space Endpoints

106
Q

This has 2 IPSEC Tunnels that transit over the public internet

A

Site to Site VPN

107
Q

Site to Site Acceleration can be enabled when creating a what?

A

TGW VPN Attachment

108
Q

Site to Site Acceleration is not compatiable with VPNs using what?

A

Virtual Private Gateway

109
Q

If deploying Site to Site VPN where possible use what?

A

TGW

110
Q

When using Site to Site VPN while using Transit Gateway make sure to enable what?

A

Site 2 Site Accelerator

111
Q

This is a managed implementation of OpenVPN

A

Client VPN

112
Q

With Client VPN what is not the default?

A

Split Tunnel

113
Q

With Client VPN this must be enabled or else all data goes via tunnel?

A

Split Tunnel

114
Q

What are the speeds of DX Connection Physical Port?

A

1,10,100 g

115
Q

What type of connection do you need for DX Port?

A

Single Mode fibre

116
Q

If connecting at 1Gbps what tranceiver do you use?

A

1000 BASE-LX 1310nm

117
Q

If connection at 10 gbps what transceiver do you use?

A

10 GBASE-LR (1310nm)

118
Q

If connection at 100 gbps what transceiver do you use?

A

100 BASE-LR4

119
Q

What needs to be disabled on DX Port?

A

Auto Negotiation

120
Q

What do you need to manually set in DX Port?

A

Port Speed and Full Duplex

121
Q

What does your router need to support in the DX Location?

A

BGP and BGP MDS Authentication

122
Q

What uses a physical connection to a AWS Region?

A

AWS Direct Connect (DX)

123
Q

How many gig for DX?

A

1 10 100 Gigs

124
Q

The DX Connection is between what 3 things?

A

Business Premises, DX Location, and AWS Region

125
Q

What does AWS Provide at DX Location?

A

Port allocation

126
Q

What provides low and consistent latency + high speeds?

A

Direct Connect

127
Q

Direct Connect is used to access what?

A

AWS Private Service in a VPC and AWS Public Service

128
Q

DX cant access what?

A

Public Internet

129
Q

Does AWS own the DX Location?

A

No they rent the space

130
Q

How do you connect to AWS via port at DX Location?

A

Cross Connect

131
Q

What does MACsec Provide?

A

Hop by Hop Encryption

132
Q

What does Hop by Hop encrypt?

A

2 switches or routers

133
Q

What 4 High Level features does MACSec Provide?

A

Confidentiality , Data Integrity, Data Origin Authenticity, Replay Protection

134
Q

Since MACsec isnt end 2 end what does it not replace?

A

IPSec over DX

135
Q

MACSec allows for what type of high speed?

A

Terabit Networks

136
Q

Where does a DX Connection Begin?

A

DX location

137
Q

What does DX Location contain?

A

AWS and Customer Equipment

138
Q

Does AWS own DX Location?

A

No

139
Q

Who connects things together at DX Location?

A

Data Center

140
Q

How does the Data Center Staff get authorization to connect cables?

A

Letter of Authorization

141
Q

Wha\t is needed for DC Staff to connect cables together with other entities?

A

Authorization from all parties

142
Q

What are DX Connection?

A

Physical Connection

143
Q

What is a VIF?

A

BGP Peering Session

144
Q

What does VIF Mean?

A

Virtual Interface

145
Q

Private Vif attach to how many VPC?

A

1

146
Q

Private VIF attaches to one VPC via what?

A

VIrtual Private Gateway (VGW)

147
Q

Private VIF and VGW can be used in same what only?

A

Region DX terminates on

148
Q

To setup Private VIF you need one of each what?

A

P VIF, VGW, and VPC

149
Q

Private VIF has no what?

A

Encryption

150
Q

With Private VIF AWS will advertise what two things?

A

VPC CIDR and BGP Peer IPs

151
Q

With Private VIF you can advertise?

A

default or specific corp prefixes (max 100)

152
Q

Use Private VIF to access what?

A

Private AWS Services

153
Q

VGW has AWS ASN or you can configure one…. True or False?

A

True

154
Q

BGGGP can be either?

A

IPv4 or IPv6

155
Q

You configure Your ____ on the VIF?

A

ASN

156
Q

You configure your VIF on either a ?

A

Private ASN or Public owned one

157
Q

Private ASN or Public owned use what Range?

A

64512-65535

158
Q

What do you use Public VIFs for?

A

Public Zone Services

159
Q

What doesnt Public VIF have access to?

A

Private VPC Services

160
Q

Public VIFS can access all public zone region across what?

A

AWS Global Network

161
Q

AWS advertise all what in public VIF?

A

AWS Public IP Ranges

162
Q

You can advertise any public IPs you own over what?

A

BGP

163
Q

Your prefixes dont leave what?

A

AWS example Public VIF

164
Q

What does Public VIF add?

A

low and consistent latency

165
Q

Direct Contact GW is a ?

A

Global Network device

166
Q

DCG doesnt allow what?

A

Other VPCs to communicatte

167
Q

How many VGW per DX Gateway?

A

10

168
Q

1 DX can have how many private VIFs?

A

50

169
Q

1 Private VIF =?

A

1 DX Gateway

170
Q

1 DX can have up to how many VPCs?

A

500

171
Q

How many Transit VIFs can you have per DX Connection?

A

One

172
Q

Each transit VIF supports up to how many TGWs?

A

3

173
Q

A DX gateway can be associated with VPCS and Private VIFS or TGW and Transit VIF but not what?

A

Not Both

174
Q

TGW can be attached to up to how many Direct Connect Gateways (DXGW)?

A

20

175
Q

DX Gateway doesnt support ( _____ ) what? ) between interfaces attached to the DX Gateway?

A

Routing

176
Q

A TGW allows ______ across DX Gateway attachments allowing connectivity between DX enabled offices?

A

Routing

177
Q

TGWs will route DX Gateway attachments even across TWG peers to where?

A

TO/From