Networking and Security Flashcards
7 cards from real AWS practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Networking and Security flashcards as text
A Solutions Architect needs to connect two VPCs in different AWS accounts so they can communicate privately. The IP ranges do not overlap. Which solution is most appropriate?
Answer: VPC Peering
VPC Peering creates a direct private network connection between two VPCs (same or different accounts/regions) as long as CIDR ranges do not overlap.
Which AWS service provides a managed, scalable solution for distributed denial-of-service (DDoS) protection at the network and transport layers?
Answer: AWS Shield Standard
AWS Shield Standard is automatically included at no cost for all AWS customers and provides protection against common Layer 3 and Layer 4 DDoS attacks.
A company is setting up a hybrid network and needs consistent, low-latency connectivity between their on-premises data center and AWS. Which service best meets this requirement?
Answer: AWS Direct Connect
AWS Direct Connect provides a dedicated private network connection from on-premises to AWS, offering consistent performance and lower latency than internet-based VPN.
What happens to traffic that does not match any rule in an AWS Network ACL?
Answer: It is denied by the implicit deny-all rule
NACLs include an implicit deny-all rule (rule number *) at the end; any traffic not matching an explicit allow or deny rule is automatically denied.
A developer is using AWS KMS to encrypt data. They want to ensure the encryption key is automatically rotated annually. Which feature should they enable?
Answer: Automatic Key Rotation
AWS KMS Automatic Key Rotation rotates the key material for a customer-managed key annually while keeping the same key ID and alias.
An application running in a VPC needs to access AWS Systems Manager Parameter Store without routing traffic through the internet. What should be configured?
Answer: An Interface VPC Endpoint for Systems Manager
An Interface VPC Endpoint (powered by AWS PrivateLink) for AWS Systems Manager allows private connectivity from within a VPC to Parameter Store without internet exposure.
Which IAM policy evaluation logic is correct when a user has both an explicit Allow and an explicit Deny for the same action?
Answer: Deny takes precedence
In IAM, an explicit Deny always overrides any Allow; if any policy attached to the identity or resource explicitly denies an action, access is denied regardless of other allows.