VPC Flashcards

1
Q

VPC Components

There are 11 elements in the answer

A
  • Internet Gateway (IGW)
  • Virtual Private Gateway
  • Routing tables
  • Network Access Control Lists (NACLs)
  • Security Groups (SG)
  • Public Subnets
  • Private Subnets
  • Nat Gateway
  • Customer Gateway
  • VPC Endpoints
  • VPC Peering
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

How many VPCs per region can you create?

A

5

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

How many subnets per VPC can you have?

A

200

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

In VPC, What elements can you use for free?

There are 6 elements in the answer

A
  • Route tables
  • NACLs
  • Internet Gateway
  • Security groups
  • Subnets
  • VPC Peering
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

In VPC, What elements can you use paying some money?

There are 4 elements in the answer

A
  • NAT gateway
  • VPC Endpoints
  • VPN Gateway
  • Customer Gateway
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What can you set when creating a VPC?

There are 4 fields

A
  • Name tag
  • IPv4 CIDR Block (10.0.0.0/16)
  • IPv6 CIDR Block (The adress of the VPC)
  • Tenacy (Default or dedicated hardware)
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What does it come with a default VPC?

A
  • A subnet in each AZ
  • Internet Gateway
  • Security group
  • NACLS
  • DHCP
  • Route Table
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What is the purpose of the default VPC in each region?

A

You can start deploying your instances immediately

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What does VPC Peering allow you to do?

A

Securely connect multiple VPCs together over a direct route

No Transitive Peering (peering must take place directly between VPCs)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

This VPC feature lets you connect one VPC with another, over a direct network route using private IP addresses

A

VPC Peering

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

This VPC component is used to determine where network traffic is directed

dəˈtɜrmən

A

Route Tables

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

In VPC, What do you have to associate with your route table?

Route Tables are used to determine where network traffic is directed

A

Subnets

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

In VPC, How many subnets can have a route table?

A

As much as you want

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

In VPC, How many route tables can be associated with a subnet?

A

One route table at a time

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

This VPC component allows your VPC to access the internet

A

Internet Gateway (IGW)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

What does an Internet Gateway do?
It does two things

It provides a …
It performs …

A
  • It provide a target in your route tables for internet traffic
  • It performs network address translation (NAT)
17
Q

In VPC, Should a bastion host be located in a Public, or Private subnet?

A

Public

18
Q

Which AWS service removes the need for bastion hosts?

A
  • System Manager
  • Amazon EC2 Systems Manager.

Systems Manager allows you to remotely execute commands on managed hosts without using a bastion host (you might know this feature as EC2 Run Command). A host-based agent polls Systems Manager to determine whether a command awaits execution.

19
Q

In VPC, This type of host is a security hardened image used for secure SSH or RDP access to a private subnet

A

Bastion Host / Jump Box

20
Q

What is a Bastion or Jumpbox?

A

Bastions are EC2 instances which are security harden.

They are designed to help you gain access to your EC2 Instances via SSH or RCP That are in a private subnet.

21
Q

AWS solution for establishing dedicated network connections from on-premises locations to AWS.

A

AWS Direct Connect

On-Premise > 1GB to 10GB

Helps reduce network costs and increase bandwidth throughput. (great for high traffic networks)
Fast -> Amazon S3

22
Q

What are the 2 types of VPC Endpoints?

A

Gateway Endpoints

Interface Endpoints

23
Q

What do VPC endpoints allow you to do?

A

Keep all traffic between your VPC and other AWS services inside of the AWS network

24
Q

True or False, a VPC endpoint eliminates the need for an internet gateway, NAT device, VPN, or DirectConnect Connection

A

True

If you have an instance inside a VPC and you want to connect to a S3, you could do that through the internet gateway but it would be more convenient if you access to it using a Router > VPC Endpoint > S3 without the need for an internet gateway

25
Q

In VPC, Interface Endpoints are…

A

Elastic Network Interfaces (ENI) with a private IP address.
They serve as an entry point for traffic going to a supported service.

If an instance fails you can disconnect that ENI from your failed instance and attach it to the new instance

ENI is like a network card

26
Q

In VPC, Which AWS service powers interface endpoints?

A

Interface Endpoints are powered by AWS PrivateLink

ˈpraɪvɪt lɪŋk

27
Q

In VPC, What is a Gateway Endpoint?

A

It is for supported AWS services only. You specify a gateway endpoint as a route table target for traffic destined to the following AWS services:
S3 and DynamoDB

28
Q

In VPC, How much do VPC Gateway Endpoints cost?

A

Free

29
Q

In VPC, What are the only supported 2 services VPC Gateway Endpoints?

A

S3

DynamoDB

30
Q

VPC Private gateway and your on premise network

A

You can connect your VPC with your On-Premise network and you can access your resources because you’d be within your VPC

31
Q

What is VPC?

A

It’s a service that enables you to launch AWS resources into a virtual network that you’ve defined