Topics 58
Amazon API Gateway Amazon Athena Amazon CloudFront & Content Delivery Amazon DynamoDB Amazon ECS (Elastic Container Service) Amazon EFS (Elastic File System) Amazon EKS (Elastic Kubernetes Service) Amazon ElastiCache (Redis & Memcached) Amazon EventBridge Amazon Kinesis & Data Streaming Amazon QuickSight & Business Intelligence Amazon Redshift & Data Warehousing Amazon Route 53 & DNS Management Amazon SageMaker & Machine Learning on AWS Amazon SNS (Simple Notification Service) Amazon SQS (Simple Queue Service) Auto Scaling Groups AWS AI Services (Rekognition, Polly, Lex & Comprehend) AWS Backup & Disaster Recovery AWS Batch AWS Certificate Manager (ACM) AWS Certification Paths & Career Roadmap AWS CLI & SDKs AWS CloudTrail & Auditing AWS CodePipeline, CodeBuild & CodeDeploy (CI/CD) AWS Config AWS Cost Management & Billing AWS Database Migration Service & Application Migration AWS Direct Connect & Hybrid Connectivity AWS Elastic Beanstalk AWS Fargate AWS Free Tier & Account Setup AWS Global Infrastructure (Regions, AZs & Edge Locations) AWS Glue & ETL AWS KMS & Data Encryption AWS Organizations & Multi Account Strategy AWS Outposts & Hybrid Cloud AWS Secrets Manager & Parameter Store AWS Security Hub & GuardDuty AWS Serverless Application Model (SAM) AWS Step Functions AWS Storage Gateway AWS Systems Manager AWS Trusted Advisor AWS WAF & Shield Core Services Overview EC2 & Compute Elastic Container Registry (ECR) Elastic Load Balancing (ALB, NLB & CLB) IaC (CloudFormation) IAM Lambda & Serverless Monitoring (CloudWatch) RDS & Databases S3 & Storage Tagging Strategies & Resource Management VPC & Networking Well-Architected Framework

VPC & Networking

7 questions found

What is Amazon VPC and why is it the foundation for networking within AWS?

Beginner
Amazon VPC, or Virtual Private Cloud, lets you provision a logically isolated section of the AWS cloud where you can launch resources within a network you define, including your own IP address range, subnets, route tables, and gateways, giving you complete control over your virtual networking environment, which is why nearly every other AWS compute and database service is deployed within the context of a VPC.
aws ec2 create-vpc --cidr-block 10.0.0.0/16
Real-world example A company creates a dedicated VPC for its production environment with a carefully planned IP address range, ensuring complete network isolation from its separate development environment's own distinctly configured VPC.

Common follow-ups: What is the default VPC that comes with every AWS account?;How many VPCs can you create within a single AWS account by default?

EC2 & Compute;AWS Direct Connect & Hybrid Connectivity

What is the difference between a public subnet and a private subnet within a VPC?

Beginner
A public subnet has a route table entry directing traffic to an internet gateway, allowing resources within it to communicate directly with the internet, while a private subnet lacks this direct route, meaning resources within it cannot be reached from or initiate outbound connections directly to the internet, unless traffic is routed through something like a NAT Gateway, making private subnets the appropriate choice for resources like databases that should never be directly exposed to the public internet.
aws ec2 create-route --route-table-id rtb-12345 --destination-cidr-block 0.0.0.0/0 --gateway-id igw-12345
Real-world example A company places its web servers in a public subnet so customers can reach them directly over the internet, while placing its database servers in a private subnet, ensuring the database can never be directly accessed from outside the VPC.

Common follow-ups: How does a resource in a private subnet access the internet for software updates if needed?;What is the relationship between a subnet and an Availability Zone?

EC2 & Compute;RDS & Databases

How do security groups and network ACLs differ in how they control traffic to and from resources within a VPC?

Intermediate
Security groups act as a stateful firewall at the instance level, meaning if you allow inbound traffic, the corresponding outbound response traffic is automatically allowed as well, while network ACLs act as a stateless firewall at the subnet level, meaning you must explicitly define rules for both inbound and outbound traffic separately, and while security groups only support allow rules, network ACLs support both explicit allow and explicit deny rules, giving you an additional layer of control at the subnet boundary.
aws ec2 authorize-security-group-ingress --group-id sg-12345 --protocol tcp --port 443 --cidr 0.0.0.0/0
Real-world example A company uses security groups as the primary line of defense controlling exactly which ports each individual EC2 instance accepts traffic on, while also configuring a network ACL at the subnet level to explicitly block traffic from a specific known malicious IP range as an additional defense in depth measure.

Common follow-ups: Why would you need both security groups and network ACLs if security groups alone can control access?;How do you troubleshoot connectivity issues that might be caused by either layer?

AWS Security Hub & GuardDuty;EC2 & Compute

How does a NAT Gateway allow resources in a private subnet to access the internet for outbound connections while remaining unreachable from inbound internet traffic?

Intermediate
A NAT Gateway is placed in a public subnet and allows instances in a private subnet to initiate outbound connections to the internet, such as downloading software updates, by translating their private IP addresses to the NAT Gateway's own public IP address, while preventing any unsolicited inbound connections from the internet from ever reaching those private instances directly, giving you outbound internet access without compromising the security benefit of keeping those resources otherwise fully isolated from direct inbound access.
aws ec2 create-nat-gateway --subnet-id subnet-12345 --allocation-id eipalloc-12345
Real-world example A company's private subnet hosted application servers use a NAT Gateway to download necessary security patches from the internet, while remaining completely unreachable from any inbound connection originating outside the VPC.

Common follow-ups: What is the difference between a NAT Gateway and a NAT Instance?;How does NAT Gateway pricing work, and what data transfer costs should be expected?

EC2 & Compute;AWS Cost Management & Billing

How does VPC Peering enable private network communication between two separate VPCs, and what are its limitations?

Intermediate
VPC Peering creates a direct, private network connection between two VPCs, allowing resources in either VPC to communicate with each other using private IP addresses as if they were part of the same network, but it does not support transitive routing, meaning if VPC A is peered with VPC B, and VPC B is peered with VPC C, resources in VPC A cannot automatically communicate with VPC C through that chain, which is a common limitation that leads larger organizations toward using a Transit Gateway instead for more complex, multi VPC networking needs.
aws ec2 create-vpc-peering-connection --vpc-id vpc-11111 --peer-vpc-id vpc-22222
Real-world example A company connects its application VPC with a separate shared services VPC containing a central logging system using VPC Peering, but later needs to adopt a Transit Gateway once they have more than a handful of VPCs needing interconnected communication, since peering alone would require an impractical number of individual connections.

Common follow-ups: What is the maximum number of VPC peering connections a single VPC can have?;At what point does an organization typically outgrow VPC Peering in favor of Transit Gateway?

AWS Direct Connect & Hybrid Connectivity;AWS Organizations & Multi Account Strategy

How do VPC endpoints, including gateway and interface endpoints, allow private connectivity to AWS services without traversing the public internet?

Advanced
A VPC endpoint lets resources within your VPC connect privately to supported AWS services, such as S3 or DynamoDB using a gateway endpoint, or many other services using an interface endpoint backed by a private IP address within your VPC, meaning traffic to these services never needs to leave the AWS network or traverse the public internet through an internet gateway or NAT Gateway, both improving security and often reducing data transfer costs.
aws ec2 create-vpc-endpoint --vpc-id vpc-12345 --service-name com.amazonaws.us-east-1.s3 --route-table-ids rtb-12345
Real-world example A company running sensitive workloads in a private subnet with no internet access at all still allows those workloads to securely access S3 and Secrets Manager by configuring VPC endpoints for both services, entirely avoiding any need for internet connectivity.

Common follow-ups: What is the difference between a gateway endpoint and an interface endpoint?;Do VPC endpoints incur an hourly cost in addition to standard data transfer charges?

S3 & Storage;AWS Secrets Manager & Parameter Store

How should an organization design a scalable, secure VPC architecture that supports multiple accounts, hybrid connectivity, and future growth?

Advanced
A scalable VPC architecture typically uses a hub and spoke model built around a Transit Gateway that centrally connects multiple VPCs across different accounts along with an on premises network through Direct Connect, carefully plans non overlapping IP address ranges across all VPCs to avoid future conflicts, separates workloads into distinct VPCs or subnets based on their security and compliance requirements, and centralizes shared services like DNS resolution and network monitoring, all designed with enough IP address space and architectural flexibility to accommodate significant future growth without requiring a disruptive redesign later.
aws ec2 create-transit-gateway-vpc-attachment --transit-gateway-id tgw-12345 --vpc-id vpc-12345 --subnet-ids subnet-12345
Real-world example A rapidly growing company designs its VPC architecture around a central Transit Gateway from the very beginning, carefully allocating non overlapping IP address ranges across dozens of planned future VPCs, avoiding the painful re architecture that many organizations face when their initial simple networking design cannot accommodate later growth.

Common follow-ups: How do you plan IP address allocation across dozens of VPCs to avoid future conflicts?;What role does centralized DNS resolution play in a hub and spoke VPC architecture?

AWS Direct Connect & Hybrid Connectivity;AWS Organizations & Multi Account Strategy