certslothcertsloth
SAP-C02/Topic 32

AWS / Professional

Hybrid Networks, Shared Inspection and DNS Boundaries

3 min read5 recall promptsReviewed 2026-10-10

Memory hook: Trace both directions through every routing and trust boundary.

Must remember

For a professional scenario, draw the complete client-to-service path and its return. Include VPC subnet routes, Transit Gateway tables, on-premises BGP, security groups/NACLs, inspection appliances and DNS. A working outbound route does not prove return reachability or stateful-session symmetry.

Transit Gateway association selects the route table used for traffic entering from an attachment; propagation advertises that attachment’s routes into selected tables. An attachment associates with one table and can propagate into several. Segment production, nonproduction and shared services by deliberate table design. A propagated prefix does not automatically create the necessary VPC subnet route. Ordinary VPC peering is not transitive, and overlapping address space prevents normal unambiguous routing.

Centralized inspection needs the return path through the stateful appliance handling the forward flow. Transit Gateway appliance mode supports flow/AZ affinity on the inspection attachment; it does not repair every incorrectly configured VPC route. Use resilient per-AZ appliance/endpoints and inspect the failure behavior. Gateway Load Balancer distributes traffic to supported virtual appliances; Network Firewall provides managed firewall capabilities. Choose from required inspection functions, operational ownership and supported routing patterns.

Direct Connect private virtual interfaces connect supported private VPC paths; transit virtual interfaces with a Direct Connect gateway support Transit Gateway connectivity. Public virtual interfaces reach AWS public service prefixes and are not ordinary internet transit. Direct Connect is not inherently an encrypted end-to-end tunnel: use appropriate TLS, VPN or supported MACsec according to the requirement. Two circuits at one location can share a location failure; diversify devices, connections and locations when resilience requires it. A VPN backup must have sufficient capacity and correct BGP preference to be useful.

PrivateLink exposes a supported service through consumer endpoints instead of granting broad routed access, which can help across overlapping consumer/provider networks. It is not a general transitive network. Interface endpoints have DNS and per-AZ cost/availability choices; gateway endpoints serve supported S3/DynamoDB VPC route-table use cases and are not universal on-premises access paths.

For hybrid DNS, inbound Resolver endpoints accept queries from external resolvers; outbound endpoints/rules forward selected queries outward. Associate private hosted zones and shared rules with the intended VPCs. Avoid forwarding a zone back to the resolver that originally forwarded it. A private hosted zone can mask public names in its namespace; missing private records do not necessarily fall back to the public zone.

Choose under exam pressure

Requirement Choice and reason
Many networks require segmented routed connectivity Transit Gateway/appropriate global networking with explicit tables.
Consumers need one service, including overlapping CIDRs PrivateLink where its service pattern fits.
On-premises must resolve a private hosted zone Inbound Resolver path, zone association and permitted DNS traffic.

Traps

  • Association and propagation solve different routing steps.
  • A backup network path is not useful if it cannot carry recovery traffic.
  • Stateful inspection needs forward and return symmetry.

Active recall

1. What does TGW association determine?

The table used to route traffic arriving from that attachment.

2. Why can propagation alone be insufficient?

VPC routes, reverse routes and policy still have to permit the end-to-end path.

3. Why might two Direct Connect links still share a failure?

They may use the same device, carrier path or physical location.

4. Inbound or outbound Resolver for on-premises queries into AWS?

Inbound endpoints, with suitable routing, permissions and zone association.

5. Why use PrivateLink instead of peering?

To expose a supported specific service without broad routed network connectivity.

Sources

CLOSE THE NOTES. EXPLAIN THE CHOICE.

How well could you recall it?

Your next review is based on this answer. Progress stays in this browser.

Search across every published topic.