VPC 4 Flashcards

1
Q

Internet Gateways

Two types of IGWs?

A

IGWs and Egress-Only IGWs

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Internet Gateways

Do IGWs support one-way / two-way IPv6 traffic?

A

Yes, plain IGW handles full IPv4 and IPv6.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Internet Gateways

What’s an Egress-only IGW used for?

A

IPv6 only when you don’t want all internal things to be publicly-available

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Internet Gateways

What does an IGW do with IPv4 addresses?

A

All VPC IPv4 traffic is via RFC1918 addresses; IGW does STATIC NAT for their public IPs.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Internet Gateways

What does an IGW do with IPv6 addresses?

A

Nothing: all IPv6 addresses are publicly-routable. No NATing done.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Flow Logs

High-level, what’s in VPC Flow Logs?

A

Metadata only, no content (need packet sniffer for that)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Flow Logs

Where can you attach a monitor?

A

All ENIs in a single VPC, one subnet in a single VPC, a specific ENI

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Flow Logs

Is Flow Logs real-time?

important

A

No, definite delay before you see them

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Flow Logs

Where does Flow Logs send it’s logs?

A

S3 or CloudWatch Logs

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Flow Logs

What filtering can you set on Flow Logs?

A

Capture all, only accepted, or only rejected

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Flow Logs

5 key parts of a Flow Log record, in order?

A

src ip, dest ip, source port, dest port, protocol

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

Flow Logs

What are important values for protocol?

A

ICMP is 1, TCP is 6, UDP is 7

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

Flow Logs

See entries for inbound accepted to EC2, outbound rejected. What happened?

important

A

NACL. Security Group would have accepted both or rejected both

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

Flow Logs

What 4 things won’t Flow Logs capture?

A

Anything to 169.254.169.254, DHCP, AmazonProvidedDNS, Amazon Windows License

How well did you know this?
1
Not at all
2
3
4
5
Perfectly