โ† All CLF-C02 Flashcard Decks

Networking Flashcards

7 cards from real CLF-C02 practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Networking flashcards as text
  1. Which Route 53 feature would a company use to route a percentage of traffic to a new application version for A/B testing?

    Answer: Weighted routing

    Weighted routing allows you to assign proportional weights to different resource record sets, enabling gradual traffic shifts like sending 10% to a new version during testing.

  2. A company wants to privately access Amazon S3 from their VPC without sending traffic over the internet. Which type of VPC Endpoint should they use?

    Answer: Gateway Endpoint

    Gateway Endpoints are available for Amazon S3 and DynamoDB, allowing private access from a VPC by adding an entry to the route table that directs traffic to the endpoint.

  3. What is the primary benefit of deploying resources across multiple Availability Zones within a VPC?

    Answer: It improves fault tolerance by protecting against single AZ failures

    Deploying across multiple Availability Zones ensures that if one AZ experiences an outage, resources in other AZs continue to serve traffic, improving application availability.

  4. Which AWS service provides DDoS protection and is automatically included at no extra charge for all AWS customers?

    Answer: AWS Shield Standard

    AWS Shield Standard is automatically enabled for all AWS customers at no additional cost and provides protection against common, most frequently occurring DDoS attacks.

  5. A company's EC2 instances in a private subnet need to access AWS services like S3 and DynamoDB. Which solution keeps this traffic within the AWS network?

    Answer: Use VPC Endpoints for S3 and DynamoDB

    VPC Endpoints (Gateway Endpoints for S3 and DynamoDB, Interface Endpoints for other services) allow private connectivity to AWS services without traversing the public internet.

  6. What is the difference between an AWS Site-to-Site VPN and AWS Direct Connect?

    Answer: Site-to-Site VPN creates an encrypted tunnel over the internet; Direct Connect provides a dedicated private connection

    Site-to-Site VPN creates an IPsec-encrypted tunnel over the public internet for quick setup, while Direct Connect provides a dedicated physical connection bypassing the internet for consistent performance.

  7. Which Amazon Route 53 health check feature automatically redirects traffic away from unhealthy endpoints?

    Answer: Failover routing with health checks

    Failover routing combined with Route 53 health checks automatically routes traffic to a standby resource when the primary resource becomes unhealthy.