โ† All AWS Flashcard Decks

Networking and Security Flashcards

7 cards from real AWS practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Networking and Security flashcards as text
  1. A Solutions Architect needs to connect two VPCs in different AWS accounts so they can communicate privately. The IP ranges do not overlap. Which solution is most appropriate?

    Answer: VPC Peering

    VPC Peering creates a direct private network connection between two VPCs (same or different accounts/regions) as long as CIDR ranges do not overlap.

  2. Which AWS service provides a managed, scalable solution for distributed denial-of-service (DDoS) protection at the network and transport layers?

    Answer: AWS Shield Standard

    AWS Shield Standard is automatically included at no cost for all AWS customers and provides protection against common Layer 3 and Layer 4 DDoS attacks.

  3. A company is setting up a hybrid network and needs consistent, low-latency connectivity between their on-premises data center and AWS. Which service best meets this requirement?

    Answer: AWS Direct Connect

    AWS Direct Connect provides a dedicated private network connection from on-premises to AWS, offering consistent performance and lower latency than internet-based VPN.

  4. What happens to traffic that does not match any rule in an AWS Network ACL?

    Answer: It is denied by the implicit deny-all rule

    NACLs include an implicit deny-all rule (rule number *) at the end; any traffic not matching an explicit allow or deny rule is automatically denied.

  5. A developer is using AWS KMS to encrypt data. They want to ensure the encryption key is automatically rotated annually. Which feature should they enable?

    Answer: Automatic Key Rotation

    AWS KMS Automatic Key Rotation rotates the key material for a customer-managed key annually while keeping the same key ID and alias.

  6. An application running in a VPC needs to access AWS Systems Manager Parameter Store without routing traffic through the internet. What should be configured?

    Answer: An Interface VPC Endpoint for Systems Manager

    An Interface VPC Endpoint (powered by AWS PrivateLink) for AWS Systems Manager allows private connectivity from within a VPC to Parameter Store without internet exposure.

  7. Which IAM policy evaluation logic is correct when a user has both an explicit Allow and an explicit Deny for the same action?

    Answer: Deny takes precedence

    In IAM, an explicit Deny always overrides any Allow; if any policy attached to the identity or resource explicitly denies an action, access is denied regardless of other allows.