Unit 2: Networking and Connectivity in AWS - Subjective Questions

INT364 — Cloud Architecture And Implementation-Ii • Practice Questions with Detailed Answers

20 questions

1

Define an Amazon Virtual Private Cloud (VPC). Explain the major components required to build a functional VPC.

2

Derive a subnetting plan for a VPC with CIDR block 10.0.0.0/24 that must be divided into four equal-sized subnets. State the address range and usable host capacity of each subnet.

3

Distinguish between public, private, and isolated subnets in Amazon VPC.

4

Explain how route tables, Internet Gateways, and NAT Gateways work together to provide connectivity in a multi-tier VPC.

5

Describe the operation and important characteristics of an AWS security group.

6

Explain how Network Access Control Lists (NACLs) secure VPC subnets. Include rule evaluation and return-traffic considerations.

7

Compare security groups and Network ACLs. Explain how they can be used together as defense in depth.

8

Design a secure three-tier VPC network for a highly available web application.

9

What are VPC endpoints? Distinguish between gateway endpoints and interface endpoints.

10

Compare AWS PrivateLink with a gateway VPC endpoint and explain when each should be selected.

11

Describe how private workloads in a VPC can securely connect to managed AWS services. Include DNS, routing, and access-control considerations.

12

Explain VPC peering, its configuration requirements, and its main use cases.

13

Discuss the routing limitations of VPC peering and explain why a large peering mesh can become difficult to manage.

14

Explain AWS Transit Gateway and compare it with VPC peering for multi-VPC network architecture.

15

Describe AWS Site-to-Site VPN, including its components, routing options, and high-availability features.

16

Explain AWS Direct Connect and identify the circumstances in which an organization should use it.

17

Compare AWS Site-to-Site VPN and AWS Direct Connect. Propose a resilient hybrid-connectivity architecture using both.

18

What are VPC Flow Logs? Explain their contents, destinations, uses, and limitations.

19

Describe an AWS network-monitoring and troubleshooting strategy using relevant AWS services and tools.

20

Apply AWS Well-Architected principles to review and improve the networking design of a production workload.