ADVANCED VPC Networking Flashcards

1
Q

allowing the monitoring of traffic flow to and from interfaces within a VPC

A

VPC Flow Logs

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

VPC only caputures metadata and not contents

A

True

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

When attached to a VPC, flow logs monitor

A

All ENI in VPC

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

When attached to a Subnet, flow logs monitor

A

All ENI in Subnet

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Can Flow logs be attached to ENIs directly?

A

Yes

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Are Flow Logs realtime?

A

NO

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

VPC Flow Log destinations are S3 or CloudWatch Logs

A

True

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Can Athena be used to query VPC Flow logs in S3?

A

Yes

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Do flow logs monitor packet Contents?

A

No

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Allow outbound (and response) only access to the public AWS services and Public Internet for IPv6-enabled instances or other VPC-based services

A

Egress-Only internet gateways

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Allows private IPs to access public networks without allowing externally initiated connections in

A

NAT

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

Internet Gateway IPv6 allows all IPS in and out

A

True

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

type of VPC endpoint which allow access to S3 and DynamoDB without using public addressing

A

Gateway Endpoints

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

added to route table and points the route table to it

A

Gateway Endpoints

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

Gateway endpoints are Highly available across all AZs in a region

A

True

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

Controls which things can be connected to by the gateway endpoint

A

Endpoint Policies

17
Q

Can Gateway Endpoints access cross-region services?

18
Q

used to allow private IP addressing to access public AWS services apart from S3 and DynamoDb

A

Interface Endpoints

19
Q

Are Interface Endpoints highly available by default?

20
Q

1 Endpoint to 1 Subnet Per used AZ to get High Availability

21
Q

Interface Endpoints only support TCP and IPv4

22
Q

Do interface Endpoints use PrivateLink?

23
Q

Interface Endpoints provides a NEW service endpoint DNS

24
Q

One single DNS name that works with whatever AZ you’re using to access the interface endpoint

A

Endpoint Regional DNS

25
Resolves to one specific interface in one specific availability zone
Endpoint Zonal DNS
26
OVerrides the default DNS for services
PrivateDNS
27
Associates a private R53 hosted zone to the VPC changing the default service DNS to resolve to the interface endpoint ip
Private DNS
28
Uses prefix lists and route tables
Gateway Endpoints
29
Uses DNS and a private IP address
Interface Endpoints
30
networking connection between two VPCs that enables you to route traffic between them using private IPv4 addresses or IPv6 addresses
VPC peering
31
One peering connection links two and only two VPCs
True
32
Does VPC peering work across region/cross account
Yes
33
Does VPC Perring support transitive peering?
No
34
are route tables at both sides of the peering connection needed?
Yes
35
Can VPC peering connections be created where there is overlap in the VPC CIDRS?
No