passdrill

VPC & Networking

38 cards · AWS SAA-C03 · answer each one, then read the explanation. Your score tallies below.

0 / 38 answered · 0 correct

AWS SAA-C03 · VPC & Networking · Card 001/038 easy

A VPC contains a subnet whose route table has no route to an internet gateway. EC2 instances in this subnet have public IP addresses assigned. Can these instances reach the internet directly?

  1. Yes, because they have public IP addresses
  2. Yes, but only if a NAT gateway also exists somewhere in the VPC
  3. No, subnets can never have instances with public IP addresses
  4. No, a route to an internet gateway in the subnet's route table is required regardless of whether instances have public IPs
AWS SAA-C03 · VPC & Networking · Card 002/038 easy

A web server sits in a subnet protected by both a security group and the default network ACL. An inbound rule on the security group allows TCP 443 from 0.0.0.0/0. No outbound rule was added to the security group. What happens to the server's response traffic on port 443?

  1. The response is blocked because there is no matching outbound security group rule
  2. The response is automatically allowed because security groups are stateful and track connections
  3. The response is allowed only because the default NACL allows all traffic
  4. The response requires an explicit outbound rule permitting ephemeral ports back to the client
AWS SAA-C03 · VPC & Networking · Card 003/038 easy

An architect places a NAT gateway inside a private subnet and updates that subnet's route table to send 0.0.0.0/0 traffic to the NAT gateway, hoping to give the private instances outbound internet access. The setup does not work. What is wrong?

  1. NAT gateways must be deployed in a public subnet that itself routes to an internet gateway
  2. NAT gateways can only be used with IPv6 traffic
  3. The route table update should point to the internet gateway instead
  4. NAT gateways require a security group allowing all outbound traffic
AWS SAA-C03 · VPC & Networking · Card 004/038 easy

An instance in a public subnet is stopped and later started again. Before stopping it, the engineer wants its public-facing address to remain identical after the restart. Which approach guarantees this?

  1. Rely on the automatically assigned public IP, since AWS never changes it
  2. Add a static route in the route table for the instance's current public IP
  3. Enable "Auto-assign Public IP" on the subnet
  4. Associate an Elastic IP address with the instance before stopping it
AWS SAA-C03 · VPC & Networking · Card 005/038 medium

VPC A is peered with VPC B, and VPC B is separately peered with VPC C. An engineer expects instances in VPC A to now be able to reach instances in VPC C through VPC B. The connection fails. Why?

  1. The CIDR blocks of A and C must be identical for this to work
  2. VPC peering connections are not transitive; A must be peered directly with C
  3. Peering connections expire after 24 hours unless renewed
  4. VPC B must enable a NAT gateway to forward traffic between A and C
AWS SAA-C03 · VPC & Networking · Card 006/038 medium

A company wants private connectivity from a VPC to Amazon S3 without traversing the internet or a NAT gateway, and wants to avoid any hourly charge for the endpoint itself. Which VPC endpoint type meets this requirement, and how is it implemented?

  1. Interface endpoint, implemented as an Elastic Network Interface with a private IP in the subnet
  2. Interface endpoint, which is required for all AWS services including S3
  3. Gateway endpoint, implemented as a target added to the route table, with no hourly charge
  4. Gateway endpoint, which requires attaching an Elastic IP for private routing
AWS SAA-C03 · VPC & Networking · Card 007/038 medium

A custom network ACL has rule #100 denying all traffic from 203.0.113.0/24, and rule #200 allowing all inbound traffic from 0.0.0.0/0. A request arrives from an address inside 203.0.113.0/24. What happens?

  1. The traffic is allowed because rule #200 covers a broader range and takes priority
  2. Both rules apply and their effects are combined, resulting in a partial allow
  3. The traffic is denied because NACL rules are evaluated in ascending numeric order and the first match applies
  4. The traffic is allowed because more specific CIDR ranges are always evaluated last
AWS SAA-C03 · VPC & Networking · Card 008/038 medium

Two subnets exist in the same VPC. Subnet X's route table sends 0.0.0.0/0 to an internet gateway. Subnet Y's route table sends 0.0.0.0/0 to a NAT gateway that itself lives in subnet X. How should these two subnets be classified?

  1. X and Y are both public subnets because both eventually reach the internet
  2. X is a private subnet and Y is a public subnet
  3. Classification depends only on whether instances in the subnet have public IPs
  4. X is a public subnet and Y is a private subnet
AWS SAA-C03 · VPC & Networking · Card 009/038 hard

A company has 12 VPCs that all need to communicate with each other and with an on-premises data center over a single VPN connection. Using only VPC peering, the required full mesh would need 66 separate peering connections and 66 corresponding sets of route table entries. Which alternative most directly solves both the connection-count and the transitive-routing problems?

  1. Attach all 12 VPCs and the VPN connection to a single Transit Gateway
  2. Create one central "hub" VPC and peer all 11 others to it
  3. Use VPC peering but summarize routes to reduce the entry count
  4. Replace all VPCs with a single VPC containing 12 subnets
AWS SAA-C03 · VPC & Networking · Card 010/038 hard

An application currently calls the Amazon Kinesis API using its standard public regional endpoint hostname. The team creates an interface VPC endpoint for Kinesis with private DNS enabled, expecting to avoid code changes while removing the need for internet or NAT gateway access. Does this work, and why?

  1. No, interface endpoints only support services accessed by IP address, never by hostname
  2. Yes, because enabling private DNS makes the standard public hostname resolve to the endpoint's private IP addresses inside the VPC
  3. Yes, but only if the VPC's internet gateway is also removed first
  4. No, the application must be rewritten to use the VPC-endpoint-specific DNS name
AWS SAA-C03 · VPC & Networking · Card 011/038 easy

A VPC was created with a primary IPv4 CIDR block of 10.0.0.0/16. An engineer wants to shrink that primary block to 10.0.0.0/20 to free up address space for a different VPC. Which statement correctly describes what AWS allows here?

  1. The primary CIDR block can be resized to /20 directly, and AWS automatically shrinks any oversized subnets to fit
  2. The resize is allowed only after every subnet in the VPC is deleted first
  3. The primary CIDR block can be resized, but only by AWS Support and only once per calendar year
  4. An existing CIDR block, including a VPC's primary CIDR block, can never be resized larger or smaller after it is associated; only additional secondary CIDR blocks can be associated or disassociated
AWS SAA-C03 · VPC & Networking · Card 012/038 easy

An architect associates a new secondary IPv4 CIDR block, 10.2.0.0/16, with an existing VPC whose primary CIDR is 10.0.0.0/16, intending to build a new subnet inside the secondary range. What does AWS do automatically as part of this association?

  1. AWS automatically adds a route with destination 10.2.0.0/16 and target 'local' to the VPC's route tables
  2. AWS automatically provisions a NAT gateway to translate traffic between the two CIDR ranges
  3. AWS merges 10.0.0.0/16 and 10.2.0.0/16 into a single contiguous 10.0.0.0/15 block
  4. Nothing changes until the engineer manually adds a route for 10.2.0.0/16 to every route table
AWS SAA-C03 · VPC & Networking · Card 013/038 easy

A developer creates a brand-new AWS account and, without configuring any VPC resources, launches an EC2 instance into the account's default VPC. The instance turns out to be reachable from the internet immediately. Which combination of default VPC characteristics explains this?

  1. The default VPC has no subnets at all, so every instance is launched directly onto the public internet
  2. The default VPC includes a pre-configured NAT gateway in every subnet
  3. The default VPC already includes a public subnet in every Availability Zone, an attached internet gateway, DNS resolution enabled, and default subnets that auto-assign public IPv4 addresses to launched instances
  4. Default VPCs disable security groups entirely, so no inbound traffic is ever blocked
AWS SAA-C03 · VPC & Networking · Card 014/038 easy

A VPC has enableDnsSupport set to true and enableDnsHostnames set to false. An EC2 instance in this VPC is launched with a public IPv4 address. What is the practical effect of this specific combination?

  1. The instance cannot resolve any DNS names at all, because enableDnsHostnames is false
  2. The instance can still resolve DNS names (including public internet hostnames) using the Amazon-provided DNS resolver, but it is not assigned a public DNS hostname of its own, and the resolver cannot resolve Amazon-provided private DNS hostnames
  3. The instance is assigned a public DNS hostname, but all resolver queries fail
  4. AWS rejects this combination and forces both attributes to the same value
AWS SAA-C03 · VPC & Networking · Card 015/038 easy

An engineer creates a VPC Flow Log for a subnet and wants it to record only traffic that was rejected by a security group or network ACL, then have that data queryable with Amazon Athena. Which combination of settings and destination supports this?

  1. Flow logs can only capture ALL traffic, never REJECT-only, so a separate security tool is required
  2. Set the traffic filter to REJECT, but flow logs can only be queried through the EC2 console, not Athena
  3. Set the traffic filter to REJECT and publish the flow log to Amazon S3
  4. Set the traffic filter to ACCEPT and publish the flow log to Amazon CloudWatch Logs
AWS SAA-C03 · VPC & Networking · Card 016/038 easy

A team currently runs an EC2 instance configured as a NAT instance so that private subnet traffic can reach the internet, and they also use that same instance as an SSH bastion host with a custom port-forwarding rule. They are considering migrating to a NAT gateway. Which statement about this migration is accurate?

  1. The NAT gateway will support the same bastion and port-forwarding functionality, since NAT gateways are simply a managed version of NAT instances with identical features
  2. NAT gateways support port forwarding but not bastion functionality
  3. NAT gateways support bastion functionality but not port forwarding
  4. A NAT gateway cannot be used as a bastion host and does not support custom port-forwarding configuration; those two functions would need to be moved to a separate instance
AWS SAA-C03 · VPC & Networking · Card 017/038 easy

A company wants to associate an IPv6 CIDR block with its VPC and specifically wants Amazon to allocate the block from Amazon's own IPv6 address pool rather than bringing their own range. Which statement correctly describes what happens?

  1. The company chooses any /56 IPv6 range they like, and AWS reserves it for their exclusive use
  2. AWS assigns a fixed-size IPv6 CIDR block (a /56) from its own pool, and the company cannot choose the specific range of addresses themselves
  3. AWS requires the company to first own a public IPv4 range before it will allocate any IPv6 block
  4. IPv6 CIDR blocks can only be added to a VPC at creation time and can never be added to an existing VPC later
AWS SAA-C03 · VPC & Networking · Card 018/038 medium

Security group `sg-db` in VPC B has an inbound rule that allows TCP 5432 from security group `sg-app` in VPC A. VPC A and VPC B are connected only by an active VPC peering connection (there is no transit gateway involved). Which statement is correct about this rule?

  1. The rule works: instances in sg-app can reach port 5432 on instances in sg-db using sg-app instances' private IP addresses, and none of sg-app's own rules are imported into sg-db as a result
  2. The rule is invalid, because a security group rule can only reference another security group when both are in the same VPC
  3. The rule works only if every instance in sg-app also has its public IP address individually added to sg-db
  4. Creating this rule automatically also permits sg-db instances to initiate connections to sg-app on any port
AWS SAA-C03 · VPC & Networking · Card 019/038 medium

A subnet's route table contains three entries: 10.0.0.0/8 targeting a virtual private gateway, 10.0.1.0/24 targeting a NAT gateway, and 10.0.1.128/25 targeting 'local'. A packet is destined for 10.0.1.150. Which route does AWS use to forward this packet?

  1. The 10.0.0.0/8 route, because routes are evaluated in the order they were created and this one was created first
  2. All three routes are used simultaneously, splitting the traffic across each target
  3. The 10.0.1.0/24 route, because NAT gateway targets always take precedence over other target types
  4. The 10.0.1.128/25 route, because AWS selects the most specific (longest prefix) matching route regardless of creation order
AWS SAA-C03 · VPC & Networking · Card 020/038 medium

A VPC has private subnets in three Availability Zones, all currently routing their internet-bound traffic to a single NAT gateway that lives in one Availability Zone's public subnet. What does AWS recommend to make this design more resilient, and what is the tradeoff of not doing so?

  1. Deploy a separate NAT gateway in each Availability Zone's public subnet and route each private subnet to the NAT gateway in its own AZ; otherwise, an outage of the single NAT gateway's AZ takes down internet access for every private subnet, and cross-AZ traffic to reach it incurs inter-AZ data transfer charges
  2. Nothing needs to change; a single NAT gateway is already redundant across all Availability Zones in the Region
  3. Replace the NAT gateway with a NAT instance, since NAT instances are inherently more available across Availability Zones
  4. Attach a second Elastic IP address to the existing NAT gateway so it can serve two Availability Zones redundantly
AWS SAA-C03 · VPC & Networking · Card 021/038 medium

A VPC has both an IPv4 and an IPv6 CIDR block. The team wants instances to be able to initiate outbound IPv6 connections to the internet, while preventing any host on the internet from initiating an inbound IPv6 connection to those instances. Which component should they add, and what is a key property of it?

  1. A NAT gateway, since NAT gateways handle both IPv4 and IPv6 outbound-only traffic identically
  2. An egress-only internet gateway, which handles IPv6 traffic only, is stateful (it forwards requests out and returns the responses), and cannot have a security group attached to it directly
  3. An internet gateway with a restrictive network ACL, since internet gateways are outbound-only by default for IPv6
  4. An egress-only internet gateway, which is stateless and requires a matching inbound rule for every outbound connection's response traffic
AWS SAA-C03 · VPC & Networking · Card 022/038 medium

A company creates an interface VPC endpoint for a supported AWS service and attaches a custom endpoint policy that restricts access to a specific IAM role. A developer using that role also has an identity-based IAM policy that denies the same action. What is the net effect, and how do these policy layers relate?

  1. The endpoint policy always overrides identity-based and resource-based policies, so the action is allowed regardless of the IAM deny
  2. Endpoint policies only apply to gateway endpoints, so this interface endpoint ignores the attached policy entirely
  3. The endpoint policy does not override or replace identity-based or resource-based policies; it is an additional resource-based control layer, so an explicit IAM deny still blocks the action even though the endpoint policy would otherwise permit it
  4. Since no endpoint policy was ever explicitly required, AWS denies all access to the endpoint by default until one is attached
AWS SAA-C03 · VPC & Networking · Card 023/038 hard

Transit Gateway TGW-1 (with VPC A attached) is peered with Transit Gateway TGW-2 (with VPC B attached) via a transit gateway peering attachment, which has been accepted. A week later, instances in VPC A still cannot reach instances in VPC B. What is the most likely cause, given how transit gateway peering attachments handle routing?

  1. Transit gateway peering attachments support automatic route propagation just like VPC attachments, so the routes should already exist — the peering attachment itself must be misconfigured
  2. VPC A and VPC B must have identical CIDR blocks before any traffic can pass over a transit gateway peering attachment
  3. Transit gateway peering attachments only support routing IPv6 traffic, so IPv4 traffic between the VPCs will never work over this attachment
  4. Transit gateway peering attachments do not support route propagation; a static route pointing to the peering attachment must be manually added to (and associated with) the transit gateway route tables on both TGW-1 and TGW-2
AWS SAA-C03 · VPC & Networking · Card 024/038 hard

A company wants to expose an internal application, running behind a Network Load Balancer in its own VPC, to several customer VPCs in other AWS accounts — without those customers being able to reach any other resource in the company's VPC, and without requiring VPC peering or CIDR coordination between the accounts. Which AWS PrivateLink feature fits this requirement, and what is a defining property of it?

  1. A VPC peering connection combined with a highly restrictive route table, since peering is the only way to connect resources across AWS accounts privately
  2. A Transit Gateway attachment shared with the customer accounts via AWS Resource Access Manager, since Transit Gateway is required for any cross-account AWS PrivateLink connectivity
  3. A VPC endpoint service (an AWS PrivateLink-powered service) fronted by the Network Load Balancer; consumer accounts connect via an interface VPC endpoint, and access is limited to only the exposed service, not general network reachability into the provider's VPC, with no CIDR overlap concerns between the two sides
  4. A gateway VPC endpoint, since gateway endpoints are the mechanism used to expose custom applications to other AWS accounts
AWS SAA-C03 · VPC & Networking · Card 025/038 easy

A company already has an internet gateway named igw-prod attached to VPC-A. An engineer tries to attach a second internet gateway, igw-backup, to the same VPC-A for redundancy. What happens?

  1. The attempt fails, because a VPC can only have one internet gateway attached to it at any given time; redundancy for internet access is instead achieved through the internet gateway's own highly available, horizontally scaled design, not by attaching a second one
  2. The attempt succeeds, and traffic is automatically load-balanced across both internet gateways based on route table weights
  3. The attempt succeeds, but only one of the two internet gateways can be referenced in route tables at a time, requiring manual failover
  4. The attempt succeeds only if igw-backup is created in a different Availability Zone from igw-prod
AWS SAA-C03 · VPC & Networking · Card 026/038 easy

A team's AWS account already has five Elastic IP addresses allocated in the us-east-1 Region, the AWS default quota for that Region. They attempt to allocate a sixth Elastic IP address for a new NAT gateway in the same Region without taking any other action first. What happens?

  1. It succeeds automatically, because Elastic IP address quotas apply per Availability Zone, not per Region, and this new address is being allocated for a different purpose (a NAT gateway) than the existing five
  2. It fails, because five Elastic IP addresses per Region is the default quota for an AWS account, and the account must request a quota increase through the Service Quotas console before allocating more
  3. It succeeds automatically, because Elastic IP address quotas apply only to addresses associated with running EC2 instances, and NAT gateway Elastic IP addresses are exempt from the quota
  4. It fails permanently, because five Elastic IP addresses per Region is a hard limit that cannot be raised even with a quota increase request
AWS SAA-C03 · VPC & Networking · Card 027/038 easy

A subnet is created with CIDR block 10.0.1.0/27, which provides 32 IP addresses in total. How many of those addresses are actually available to be assigned to resources such as EC2 instances?

  1. 32 (every address in the block is usable, since AWS subnets don't reserve any addresses the way traditional on-premises networks do)
  2. 30 (AWS reserves only the first address for the network and the last address for broadcast, exactly like a traditional network/broadcast address pair)
  3. 27 (AWS reserves the first four addresses in the block plus the last address, for the network address, the VPC router, DNS, future use, and network broadcast)
  4. 24 (AWS reserves the first eight addresses in every subnet for its own internal management traffic)
AWS SAA-C03 · VPC & Networking · Card 028/038 medium

An engineer wants to quickly fail over a network-intensive appliance from one EC2 instance to a standby instance by detaching the appliance's elastic network interface (ENI) from the failed instance and attaching it to the standby instance, preserving the same private IP address. Under what condition does this work?

  1. It works regardless of Availability Zone, as long as both instances are in the same VPC
  2. It works regardless of VPC, as long as both instances are in the same Availability Zone and AWS account
  3. It works only if the network interface is the primary network interface of the failed instance, since secondary network interfaces cannot be detached and reattached
  4. It works only if both instances are in the same Availability Zone as the network interface itself, since a network interface can only be attached to instances located in the Availability Zone in which it was created
AWS SAA-C03 · VPC & Networking · Card 029/038 medium

A private subnet's outbound traffic through a single NAT gateway is failing intermittently for connections to one specific busy third-party API endpoint, while traffic to other destinations is unaffected. Monitoring shows the NAT gateway's IP address is hitting its concurrent-connection ceiling for that one destination. What AWS-recommended fix directly raises this specific ceiling for the existing NAT gateway, without changing which subnet or route table the traffic uses?

  1. Associate additional secondary Elastic IP addresses with the same NAT gateway; each IP address on a NAT gateway supports its own separate pool of concurrent connections to a given unique destination (a specific destination IP, port, and protocol combination), so more addresses raise the effective ceiling
  2. Increase the NAT gateway's instance type, since NAT gateways run on a selectable EC2 instance type and larger instance types support proportionally more concurrent connections per destination
  3. Enable VPC Flow Logs on the NAT gateway's network interface, which automatically raises its per-destination connection ceiling once AWS detects sustained legitimate traffic
  4. Change the route table's default route from the NAT gateway to an internet gateway, since internet gateways have no per-destination connection ceiling
AWS SAA-C03 · VPC & Networking · Card 030/038 hard

A company has two VPCs peered across two different AWS Regions via an active VPC peering connection. An engineer tries to add an inbound security group rule in the first VPC that references the security group ID of an instance in the second VPC — the same pattern they already use successfully for VPCs peered within a single Region. What happens?

  1. It works identically to the same-Region case, because VPC peering fully supports security group referencing regardless of whether the peered VPCs are in the same or different Regions
  2. It fails to reference the peer security group; AWS does not support referencing a security group across a VPC peering connection when the peered VPCs are in different Regions, so the engineer must reference the peer VPC's CIDR block instead
  3. It works, but only for outbound rules; inbound rules can never reference a security group across any VPC peering connection, same-Region or cross-Region
  4. It fails because VPC peering itself does not support connections between VPCs in different Regions at all
AWS SAA-C03 · VPC & Networking · Card 031/038 medium

Two VPCs, A and B, are connected by an active VPC peering connection, and both VPCs already have DNS hostnames and DNS resolution enabled. An instance in VPC A resolves the public DNS hostname of an instance in VPC B (for example, ec2-x-x-x-x....amazonaws.com) and gets back that instance's public IPv4 address, even though both instances could reach each other privately over the peering connection. What must be configured so that resolving that same public DNS hostname instead returns the private IPv4 address, keeping the traffic off the public internet path?

  1. Nothing further is possible; a public DNS hostname always resolves to a public IP address, regardless of any VPC peering configuration
  2. Create a Route 53 private hosted zone associated with both VPCs and manually add records duplicating every instance's public hostname
  3. Enable the 'DNS resolution' option for the VPC peering connection — with the owner of the requester VPC enabling it for the requester side and the owner of the accepter VPC enabling it for the accepter side — which makes the public DNS hostname resolve to the instance's private IPv4 address for requests that traverse that peering connection
  4. Disable the enableDnsHostnames attribute on both VPCs; turning off DNS hostname support is what causes public hostnames to resolve to private addresses over a peering connection
AWS SAA-C03 · VPC & Networking · Card 032/038 easy

A team wants to set up a gateway VPC endpoint so that instances in a private subnet can reach a service without traversing an internet gateway or a NAT device, and without any hourly charge for the endpoint itself. For which AWS services can they actually create a gateway endpoint?

  1. Any AWS service that offers a VPC interface endpoint, since gateway endpoints and interface endpoints are two names for the same underlying feature
  2. Amazon S3 only; DynamoDB requires an interface endpoint because it does not support AWS PrivateLink
  3. Any regional AWS service reachable over HTTPS, since gateway endpoints work generically by routing traffic destined for any AWS-owned IP range
  4. Only Amazon S3 and Amazon DynamoDB; gateway endpoints are a distinct mechanism from AWS PrivateLink interface endpoints and are limited to these two services
AWS SAA-C03 · VPC & Networking · Card 033/038 easy

After creating a gateway VPC endpoint for Amazon S3, instances in a subnet still cannot use it to reach S3 privately, even though the endpoint itself shows as available. What is the most likely missing step?

  1. The subnet's route table was never associated with (selected for) the gateway endpoint, so it never received the automatically-added route that points the S3 prefix list at the endpoint
  2. The subnet's security group was never updated to allow inbound traffic from the gateway endpoint's private IP address
  3. The gateway endpoint was never given an Elastic IP address to act as its entry point
  4. The VPC's enableDnsHostnames attribute was never enabled, which is required for any gateway endpoint to receive traffic
AWS SAA-C03 · VPC & Networking · Card 034/038 hard

A Transit Gateway has three VPC attachments: A, B, and C. Attachment A is associated with TGW route table RT1. Route propagation from attachment B is enabled into both RT1 and a separate TGW route table RT2, while attachment C is associated with RT2. Based on how Transit Gateway route tables work, which statement is correct?

  1. Attachment A can also be associated with RT2 at the same time, since a single attachment can be associated with multiple TGW route tables simultaneously
  2. Attachment A can send traffic based only on the routes in RT1, the one route table it's associated with, while attachment B's routes can be propagated into multiple TGW route tables (here, both RT1 and RT2) so they can be learned by other attachments
  3. Route propagation and association are two names for the same action; enabling propagation from attachment B into RT1 is what associates attachment B with RT1
  4. Attachment C cannot receive attachment B's routes unless attachment C is itself also enabled for propagation into RT2
AWS SAA-C03 · VPC & Networking · Card 035/038 medium

A company sets up a new AWS Direct Connect dedicated connection between its data center and an AWS Region to get consistent, high-bandwidth connectivity for a workload with strict data-in-transit encryption requirements. Without adding anything else, is the traffic on this Direct Connect connection encrypted?

  1. Yes, all traffic sent over any Direct Connect connection is automatically encrypted at the physical layer by AWS with no configuration required
  2. Yes, but only if the connection uses a private virtual interface rather than a public virtual interface
  3. No, Direct Connect does not encrypt traffic in transit by default; the company needs to add a Site-to-Site VPN over the Direct Connect connection, or use a MACsec-capable connection, to get encryption
  4. No, and there is no supported way to encrypt traffic that traverses a Direct Connect connection; encryption must happen entirely at the application layer instead
AWS SAA-C03 · VPC & Networking · Card 036/038 medium

A company has a single AWS Direct Connect connection from its data center to a Direct Connect location, and separate VPCs in two different AWS Regions that it wants that same connection to reach, each VPC keeping its own virtual private gateway. What AWS resource is designed to let one Direct Connect connection reach VPCs across multiple Regions like this?

  1. A second Direct Connect connection provisioned in the second Region, since a single Direct Connect connection can only ever reach VPCs in the Region it physically terminates in
  2. A Transit Gateway peering attachment between the two Regions' Transit Gateways, with no involvement from Direct Connect needed once the peering is active
  3. A VPC peering connection between the two Regions' VPCs, layered on top of the existing Direct Connect connection
  4. A Direct Connect gateway, a globally available resource that can be associated with virtual private gateways (or Transit Gateways) in multiple Regions, letting one Direct Connect connection reach VPCs across those Regions
AWS SAA-C03 · VPC & Networking · Card 037/038 easy

A company runs an application behind Application Load Balancers in two AWS Regions and wants clients to fail over to the healthy Region within seconds of an outage, without depending on DNS TTL expiry or client-side DNS caching to pick up a change. Which AWS service is purpose-built for this, and how does it avoid the DNS-caching delay?

  1. AWS Global Accelerator, because it gives the application a small set of static anycast IP addresses that clients connect to directly; Global Accelerator then routes each connection to a healthy endpoint over the AWS global network, so failover doesn't depend on clients re-resolving DNS at all
  2. Amazon Route 53 with a simple routing policy, because Route 53 always propagates DNS record changes to every resolver worldwide within one second regardless of the record's configured TTL
  3. AWS Global Accelerator, because it works by rewriting the DNS response's TTL to zero, forcing every client and resolver to bypass caching entirely
  4. Amazon CloudFront, because CloudFront edge locations independently re-run health checks against the origin and silently update the client's own cached DNS records without any client action needed
AWS SAA-C03 · VPC & Networking · Card 038/038 medium

A team creates a new interface VPC endpoint for an AWS service and does not attach any custom endpoint policy to it. Immediately after creation, what access does the endpoint grant by default?

  1. No access at all; every interface VPC endpoint starts with an implicit deny-all policy and requires a custom policy to be attached before any traffic is allowed through it
  2. Full access; the default endpoint policy allows all principals to perform all actions on the service through the endpoint, equivalent to how the service behaves without a VPC endpoint at all, subject to any other IAM or resource policies that would otherwise apply
  3. Access limited to the AWS account that owns the VPC, but no other accounts, even if those other accounts' principals would otherwise be authorized by IAM
  4. Access limited strictly to read-only API actions until a custom policy explicitly grants write actions