Network Specialist All Flashcards
What is required to send VPC Flow Logs to CloudWatch?
IAM Role
3 Types of Placement Groups?
• Cluster – clusters instances into a low-latency group in a single Availability Zone
• Partition – spreads instances across logical partitions, ensuring that instances in one partition do not share underlying hardware with instances in other partitions
Spread – spreads instances across underlying hardware
Is CloudWatch supported for NAT GW?
No
Interface VPC Endpoint
- One interface per Avail Zone
- No endpoint policy support
- Access from direct connect but not from VPN GW
- Use endpoint specifc DNS name or route 53 private hosted
GW VPC Endpoint
- Supports multiple avail zones
- Uses routing table ID instead of DNS
- Pollicy is supported
What IP addresses can reach the public VIF of a customer router connected to direct connect?
All Amazon owned addresses.
Max Number of peering sessions per VPC
125
Number of Transit GW connections per DC GW
3
Can you access a Interface GW from DC?
No, only interface endpoints
Can you enable private hostname for DMS endpoint?
Yes. Then it can be accessed with https://kms..amazonaws.com
Does ALB support on premise targets?
Yes
What does VPC endpoint policy require?
- The principal that can perform actions
- The actions that can be performed
- The resources on which actions can be performed
What VPC endpoint operations does CloudTrial logs not support?
Principles in other accounts or operations from other accounts.
With ALB is cross-zone load-balancing enabled by default?
Yes
With NLB is cross-zone load-balancing enabled by default?
No