โ† All AWS Flashcard Decks

Certified Solutions Architect VPC Networking and Security Flashcards

7 cards from real AWS practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Certified Solutions Architect VPC Networking and Security flashcards as text
  1. A company has a VPC with CIDR 10.0.0.0/16. They need a subnet with at least 250 usable host addresses. Which subnet mask should they choose?

    Answer: /24

    A /24 subnet provides 256 addresses minus 5 reserved by AWS (network, router, DNS, future, broadcast), leaving 251 usable host addresses.

  2. An EC2 instance in a private subnet needs to access an S3 bucket. The architect wants to avoid internet traffic and minimize cost. What is the best solution?

    Answer: Create a Gateway VPC Endpoint for S3

    A Gateway VPC Endpoint for S3 provides free private connectivity to S3 without internet traffic, NAT charges, or data transfer fees.

  3. Which VPC DNS feature must be enabled to allow EC2 instances to resolve public DNS hostnames to private IP addresses within the VPC?

    Answer: DNS Resolution and DNS Hostnames must both be enabled

    Both DNS Resolution (enableDnsSupport) and DNS Hostnames (enableDnsHostnames) must be enabled for EC2 instances to receive public DNS hostnames resolvable to private IPs.

  4. A security architect needs to implement network-level threat detection across an entire AWS account by analyzing VPC Flow Logs, DNS logs, and CloudTrail. Which service should be used?

    Answer: Amazon GuardDuty

    Amazon GuardDuty continuously monitors VPC Flow Logs, DNS logs, and CloudTrail events using machine learning to detect threats and anomalous activity.

  5. A company wants to enforce that all traffic between their VPC and a partner VPC is encrypted at the network layer. Which solution achieves this?

    Answer: Deploy AWS Site-to-Site VPN over Direct Connect or Transit Gateway

    AWS Site-to-Site VPN uses IPsec to encrypt traffic at the network layer, which can be deployed over Direct Connect or Transit Gateway for encrypted inter-VPC communication.

  6. An architect needs to configure a security group to allow outbound traffic from an EC2 instance to any destination. What is the default outbound rule in a new security group?

    Answer: All outbound traffic is allowed to 0.0.0.0/0 by default

    By default, new security groups include an outbound rule that allows all traffic to all destinations (0.0.0.0/0), which can be removed and restricted as needed.

  7. A company has multiple VPCs across different AWS regions and needs to establish private connectivity between them. Which solution should be used?

    Answer: Both A and C are valid

    Both inter-region VPC Peering and AWS Transit Gateway inter-region peering support cross-region private VPC connectivity, each with different trade-offs in management and scalability.