certslothcertsloth
CLF-C02/Topic 06

AWS / Foundational

VPC, DNS and Content Delivery

2 min read5 recall promptsReviewed 2026-10-10

Memory hook: Routing finds a path; filtering permits it; DNS gives a name an answer.

Must remember

  • A VPC is a regional network; a subnet belongs to one AZ. Routes direct traffic. A public subnet has an appropriate route to an internet gateway; an instance also needs suitable addressing and security configuration for direct internet communication.
  • Security groups are stateful resource-level allow rules. Network ACLs are stateless subnet-level allow/deny rules; return traffic must be allowed explicitly. Neither fixes a missing network route.
  • A NAT gateway enables supported outbound connectivity from private subnets without accepting unsolicited inbound connections. NAT has processing/capacity costs. VPC endpoints provide supported private service access; gateway and interface endpoints have different services, mechanics and costs.
  • Route 53 provides DNS, domain-registration capabilities and routing/health-check features. A DNS answer can be cached according to TTL; it does not proxy every HTTP request. CloudFront is a content delivery network; Global Accelerator improves supported network routing through AWS edge entry points and static anycast addresses.
  • Site-to-Site VPN creates encrypted tunnels over network paths such as the internet. Direct Connect offers dedicated connectivity into AWS and does not inherently mean end-to-end encryption. Redundant connectivity must be designed explicitly.
  • VPC peering connects compatible networks directly; Transit Gateway provides hub connectivity. Network designs must consider address overlap and routing. A subnet called private is not proof that data is encrypted.
  • Compare latency, transfer volume, cross-AZ/Region movement and endpoint/NAT processing when estimating cost. A remote low-cost service can create unnecessary data-transfer charges.

Choose under exam pressure

Requirement Choice and reason
Deliver cacheable web assets worldwide CloudFront.
Encrypted connection over the internet Site-to-Site VPN.
Dedicated hybrid connectivity Direct Connect, with separate encryption and redundancy decisions.

Traps

  • A public IP alone does not supply a working route and permitted traffic.
  • A security group has no explicit deny rule.
  • A dedicated connection is not automatically encrypted.

Active recall

1. Which control requires explicit return-path rules?

A network ACL, because it is stateless.

2. What does Route 53 resolve?

DNS queries to configured answers; it is not application hosting.

3. Why place an application behind CloudFront?

To cache eligible content near users and use edge delivery features.

4. Does NAT make a private instance accept inbound internet connections?

No. Its usual role is outbound connectivity with corresponding response traffic.

5. Which regional resource is restricted to a single AZ: VPC or subnet?

A subnet. A VPC can include subnets across multiple AZs.

Sources

CLOSE THE NOTES. EXPLAIN THE CHOICE.

How well could you recall it?

Your next review is based on this answer. Progress stays in this browser.

Search across every published topic.