AWS Cloud Foundations0- Module 5: Networking and Content Delivery

studied byStudied by 0 people
0.0(0)
Get a hint
Hint

Two or more machines that are connected together in order to communicate

1 / 62

flashcard set

Earn XP

Description and Tags

AWS Academy: Cloud Foundations

63 Terms

1

Two or more machines that are connected together in order to communicate

Computer Network

New cards
2

T/F A network can be logically partitioned into subnets

True

New cards
3

A unique number assigned to a machine in order to be identified uniquely

IP Address

New cards
4

32-bit address

IPv4 Address

New cards
5

128- bit address

IPv6 address

New cards
6

A way to express a group of IP address that are consecutive to each other

Classless Inter-Domain Routing (CIDR)

New cards
7

In the OSI model, this layer’s function is Means for an application to access a computer network. Ex. HTTP(S), FTP, DHCP, LDAP

Layer 7 - Application

New cards
8

This layer’s function is to Ensure application layer can read the data and Encryption. Ex. ASCI, ICA

Layer 6 - Presentation

New cards
9

This layer in the OSI model enables order exchange of data

Layer 5 - Session

New cards
10

This layer in the OSI Model provides protocols to support host-to-host communication. Ex. TCP, UDP

Layer 4- Transport

New cards
11

This layer of the OSI Model is in charge of routing and packet forwarding (hubs and switches)

Layer 2 - Data Link

New cards
12

This layer of the OSI Model handles transmission and reception of raw bitstreams over a physical medium

Layer 1 - Physical

New cards
13

Enables you to provision a logically isolated sections of the AWS cloud where you can launch AWS resources in a virtual network that you define

Amazon VPC

New cards
14

Amazon VPC give you control over your virtual networking resources, including:

Selection of IP address range, Creation of subnets, and Configuration of route tables and network gateways

New cards
15

a range of IP addresses in a VPC

Subnet

New cards
16

The resource used to move data to and from a VPS to the public internet

Internet gateway

New cards
17

The rules that dictate how traffic is going to flow into and out of our subnets

Route

New cards
18

directs traffic destined for elsewhere in the VPC, so that anything that is moving within the VPC can communicate with each other. This traffic never leaves the VPC.

Local Route

New cards
19

An optional layer of security for your VPC that acts as a firewall for controlling traffic in and out of subnets.

Network ACLs (Network Access Control List )

New cards
20

An ______ gateway serves two purposes: Provides a target in your VPC route tables for internet traffic and to perform network instances that were assigned public IPv4 addresses.

Internet gateway

New cards
21

How do you have a subnet public?

You attach an internet gateway to your VPC and add a route entry to the route table associated with the subnet

New cards
22

A Network Address Translation

NAT gateway

New cards
23

What enables instances in a private subnet to connect to the internet or other AWS services but prevents the public internet from initiating a connection with those instances?

NAT gateway

New cards
24

When creating a _____ gateway, you must specify the public subnet in which this gateway should live and an elastic IP address to associate with this gateway. after creation, you must update the route table that is associated with one or more of your private subnets to point internet-bound traffic to the gateway.

NAT gateway

New cards
25

Enables customers to share subnets with others AWS accounts in the same organization in AWS Organizations

VPC Sharing

New cards
26

Separation of Duties, Ownership, security groups, efficiencies, no hard limits, and optimized costs are all benefits of ______.

VPC Sharing

New cards
27

A networking connection between two VPCs that enables you to route traffic between them privately. Instances in either VPC can communicate with each other as if they are within them privately.

VPC Peering

New cards
28

T/F: When setting up a peer connection, AWS creates rules in your route table to allow the VPCs to communicate with each other through the peering resource.

False: You create the rules

New cards
29

T/F: VPC peering has come restrictions, including: IP address range cannot overlap, Transitive peering is not supported, and you can only have one peering resource between the same two VPCs.

True

New cards
30

Suppose that you have three VPCs: A, B, and C. VPC A is connected to VPC B, and VPC A is connected to VPC C. However, VPC B is not connected to VPC C implicitly. To connect VPC B to VPC C, you must explicitly establish that connectivity. what is this an example of?

Transitive peering not being supported

New cards
31

1.

Create a new virtual gateway device (called a

virtual private network (VPN) gateway

) and

attach it to your VPC.

2.

Define the configuration of the VPN device or the

customer gateway

. The customer gateway

is not a device but an AWS resource that provides information to AWS about your VPN device.

3.

Create a custom route table to point corporate data center

-

bound traffic to the VPN gateway.

You also must update security group rules. (You will learn about security groups in the next

section.)

4.

Establish an

AWS Site

-

to

-

Site VPN (Site

-

to

-

Site VPN) connection

to link the two systems

together.

5.

Configure routing to pass traffic through the connection.

New cards
32
New cards
33
New cards
34

1.Create a new virtual gateway device (called a virtual private network (VPN) gateway) and attach it to your VPC.

2. Define the configuration of the VPN device or the customer gateway. The customer gateway is not a device but an AWS resource that provides information to AWS about your VPN device.

3.Create a custom route table to point corporate data center-bound traffic to the VPN gateway. You also must update security group rules.

4.Establish an AWS Site-to-Site VPN (Site-to-Site VPN) connection to link the two systems together.

5.Configure routing to pass traffic through the connection.

What are these steps for?

Connecting your VPC to your remote network

New cards
35

Enables you to establish a dedicated, private network connection between your network and one of the DX locations.

AWS Direct Connect

New cards
36

This private connection can reduce your network costs, increase bandwidth throughput, and provide a more consistent network experience than internet-based connections

AWS Direct Connect

New cards
37

A virtual devices that enables you to privately connect your VPC to supported AWS services and VPS endpoint services that are powered by AWS PrivateLink.

VPC endpoint

New cards
38

This gateway simplifies network architecture and enables efficient traffic routing between different environments. Uses the hub and spoke topology.

AWS Transit Gateway

New cards
39
<p>Label Diagram</p>

Label Diagram

knowt flashcard image
New cards
40

Acts as a virtual firewall for your instance, and it controls inbound and outbound traffic.

Security Groups

New cards
41

_____ act at instance level, not the subnet level. Therefore, each instance in a subnet in your VPC can be assigned to a different set of _____.

Security groups

New cards
42

T/F: Default Security groups deny all inbound traffic and allow all outbound traffic.

True

New cards
43

_____ are stateful, which means that state information is kept even after a request is processed.

Security groups

New cards
44

To add another layer of security to your VPC, you can set up ______ with rules that are similar to your security groups.

Network ACLs

New cards
45

T/F: Each subnet in your VPS doesn’t need to be associated with a network ACL

False: Each subnet in your VPS must be associated with a network ACL. If you don’t explicitly associate a subnet with a network ACL, the subnet is automatically associated with the default network ACL

New cards
46

T/F: Network ACLs are stateless, which means that no information about a request is maintained after a request is processed

New cards
47

Se in single-server environments

Simple routing

New cards
48

Assign weights to resource record sets to specify the frequency

Weight routing

New cards
49

Helps improve your global applications

Latency routing

New cards
50

Routes traffic based on location of users

Geolocation routing

New cards
51

Routes traffic based on location of your resources

Geoproximity routing

New cards
52

il over to a backup site if your primary site becomes unreachable.

Failover routing

New cards
53

Responds to DNS queries with up to eight healthy record selected at random

Multivalue answer routing

New cards
54

Designed to give developers and businesses a reliable and cost-effective way to route users to internet applications by translating domain names ( like www.example.com) into the numeric IP addresses (like 192.0.2.1) that computers use to connect to each other.

Amazon Route 53

New cards
55

T/F: The DNS resolver checks with your domain in Route 53, gets the IP address, and returns it to the user.

True

New cards
56

T/F: Multi-Region deployment improves your application’s performance for a local audience

False : Multi-Region deployment improves your application’s performance for a global audience

New cards
57

A fast CDN (content delivery network) service that securely deliveries data, videos, applications, and application programming interfaces (APIs) to customers globally with low latency and high transfer speeds

Amazon CloudFront

New cards
58

____ is different from traditional content delivery solutions because it enables you to quickly obtain the benefits of high-performance content delivery without negotiated contracts, high prices, or minimum fees

Amazon CloudFront

New cards
59

This services benefits include: Fast and global, security at the edge, highly programmable, deeply integrated with AWS, and cost effective

Amazon CloudFront benefits

New cards
60

Charged for the volume of data transferred out from Amazon CloudFront edge location to the internet or to your origin

Data transfer out

New cards
61

T/F: You are charged for the number of HTTP(S) requests

True

New cards
62

T/F: No additional charge for the first 1,000 paths that are requested for invalidation each month. Thereafter, $0.005 per path that is required for invalidation

True

New cards
63

T/F: $200 per month for each custom SSL certificate that is associated with one or more CloudFront distributions that use the Dedicated IP version of custom SSL certificate support

False: $600 per month

New cards

Explore top notes

note Note
studied byStudied by 5 people
... ago
5.0(1)
note Note
studied byStudied by 16 people
... ago
4.0(1)
note Note
studied byStudied by 10 people
... ago
5.0(1)
note Note
studied byStudied by 9 people
... ago
5.0(1)
note Note
studied byStudied by 69 people
... ago
5.0(3)
note Note
studied byStudied by 18 people
... ago
4.5(2)

Explore top flashcards

flashcards Flashcard (80)
studied byStudied by 13 people
... ago
4.0(1)
flashcards Flashcard (73)
studied byStudied by 15 people
... ago
4.5(2)
flashcards Flashcard (65)
studied byStudied by 2 people
... ago
5.0(1)
flashcards Flashcard (32)
studied byStudied by 1 person
... ago
5.0(1)
flashcards Flashcard (28)
studied byStudied by 242 people
... ago
5.0(5)
flashcards Flashcard (79)
studied byStudied by 12 people
... ago
5.0(1)
flashcards Flashcard (80)
studied byStudied by 2 people
... ago
5.0(1)
flashcards Flashcard (81)
studied byStudied by 228 people
... ago
5.0(4)
robot