Regions and AZs Controlling VPC Traffic Integrating On-Premises Components CIDR and Subnets Potpourri
100
Two
How many AZs should you use generally (without a compelling reason to do otherwise)?
100
Security Groups
This virtual firewall service remembers state, so once it allows an inbound request, the corresponding outbound request is OKed automatically.
100
On-Premises (Components)
What is the name used by AWS to refer to hardware at the customer location?
100
16 = 2^4
172.32.0.0/28 contains how many IP addresses? (including the 5 reserved ones)
100
One
How many VPC peering connections are allowed between any pair of VPCs?
200
Two
How many AZs exist at minimum inside of a Region?
200
Route Table
This serves as a map to how to enter and leave the network.
200
VPN
This type of connection is more secure but not faster than accessing AWS through the internet. You can use an AWS Gateway or setup your own EC2 instance in a public subnet to use this.
200
/16 to /28
What is the range of possible CIDR post-fixes (ends) from largest to smallest?
200
Root
The name of the base of the Organizations tree.
300
Data sovereignty and compliance
When choosing a Region, this factor is primary and concerns where your data can even be stored (physically).
300
Network Access Control List (NACL)
This virtual firewall service controls security on the subnet level (rather than per-instance).
300
AWS Direct Connect
This is the fastest, most secure way to connect on-premises components to AWS that is also the most expensive.
300
Multi-VPC
This is the name of an architecture with a single account and multiple VPCs managed by one account.
300
Service Control Policy
These can be attached to either OUs or users (or the root) in Organizations to limit or allow access to stuff.
400
Cost Effectiveness
This is the fourth and least important consideration when deciding what Region to host your application in.
400
VPC flow logs
This is the name of the collection of accepted and rejected traffic on a VPC.
400
All US Regions and GovCloud
AWS Direct Connect provides direct access to the region it is a part of as well as which regions?
400
Multi-account
This is the name of the architecture where there are multiple VPCs but each VPC is managed by a different user account.
400
A handshake
What is the name of the exchange of information between parties in AWS Organizations?
500
Proximity to User
Amazon found that a 100 ms delay led to a 1% drop in sales. This factor of choosing a Region is why.
500
chaining diagram
The name of the diagram used in the slides to show how Security Groups can interlock to create layered security.
500
Amazon Virtual Gateway (VGW)
What is the name of the Amazon service that accepts multiple VPN connections?
500
”jump” box
A NAT/proxy/bastion host for restricted outbound-only public internet access from a private VPC that is barely mentioned in the slides.
500
transitivity
The slide reader was very insistent that peering does not have what mathematical property that might make you think that having VPC A peered to VPC B and B peered to C would automatically mean VPCs A and C are peers now.






AWS Designing Your Environment Questions

Press F11 for full screen mode



Limited time offer: Membership 25% off


Clone | Edit | Download / Play Offline