Memory hook: Routing finds a path; filtering permits it; DNS gives a name an answer.
Must remember
- A VPC is a regional network; a subnet belongs to one AZ. Routes direct traffic. A public subnet has an appropriate route to an internet gateway; an instance also needs suitable addressing and security configuration for direct internet communication.
- Security groups are stateful resource-level allow rules. Network ACLs are stateless subnet-level allow/deny rules; return traffic must be allowed explicitly. Neither fixes a missing network route.
- A NAT gateway enables supported outbound connectivity from private subnets without accepting unsolicited inbound connections. NAT has processing/capacity costs. VPC endpoints provide supported private service access; gateway and interface endpoints have different services, mechanics and costs.
- Route 53 provides DNS, domain-registration capabilities and routing/health-check features. A DNS answer can be cached according to TTL; it does not proxy every HTTP request. CloudFront is a content delivery network; Global Accelerator improves supported network routing through AWS edge entry points and static anycast addresses.
- Site-to-Site VPN creates encrypted tunnels over network paths such as the internet. Direct Connect offers dedicated connectivity into AWS and does not inherently mean end-to-end encryption. Redundant connectivity must be designed explicitly.
- VPC peering connects compatible networks directly; Transit Gateway provides hub connectivity. Network designs must consider address overlap and routing. A subnet called private is not proof that data is encrypted.
- Compare latency, transfer volume, cross-AZ/Region movement and endpoint/NAT processing when estimating cost. A remote low-cost service can create unnecessary data-transfer charges.
Choose under exam pressure
| Requirement | Choice and reason |
|---|---|
| Deliver cacheable web assets worldwide | CloudFront. |
| Encrypted connection over the internet | Site-to-Site VPN. |
| Dedicated hybrid connectivity | Direct Connect, with separate encryption and redundancy decisions. |
Traps
- A public IP alone does not supply a working route and permitted traffic.
- A security group has no explicit deny rule.
- A dedicated connection is not automatically encrypted.
Active recall
1. Which control requires explicit return-path rules?
A network ACL, because it is stateless.
2. What does Route 53 resolve?
DNS queries to configured answers; it is not application hosting.
3. Why place an application behind CloudFront?
To cache eligible content near users and use edge delivery features.
4. Does NAT make a private instance accept inbound internet connections?
No. Its usual role is outbound connectivity with corresponding response traffic.
5. Which regional resource is restricted to a single AZ: VPC or subnet?
A subnet. A VPC can include subnets across multiple AZs.