Skip to content
BytePatterns

CLF-C02 · Domain 3: Cloud Technology and Services · 34% of the exam

Task 3.5: Identify AWS network services.

The parts of a VPC, how security groups and network ACLs differ, what Route 53 does, and the ways to connect a network to AWS.

Study it

Sample questions

Try each one before opening the answer. Every option is explained, with the AWS documentation page that proves it.

Question 1 · choose 2

A team is comparing security groups and network ACLs in its VPC. Which statements describe security groups? (Choose TWO.)

  1. AThey evaluate rules in number order and stop at the first match
  2. BThey can contain rules that explicitly deny traffic
  3. CThey are stateful, so the response to allowed traffic is allowed automatically
  4. DThey are associated with subnets, and each subnet has exactly one
  5. EThey operate at the instance level and apply to the resources associated with them
Show the answer and why
  • AThey evaluate rules in number order and stop at the first match

    Incorrect

    That is how a network ACL works. A security group evaluates all of its rules before deciding whether to allow traffic.

  • BThey can contain rules that explicitly deny traffic

    Incorrect

    Security groups have allow rules only. Explicit deny rules are a network ACL feature.

  • CThey are stateful, so the response to allowed traffic is allowed automatically

    Correct

    Security groups are stateful: return traffic is automatically allowed, whatever the rules in the other direction say.

  • DThey are associated with subnets, and each subnet has exactly one

    Incorrect

    Every subnet is associated with exactly one network ACL. Security groups are associated with resources, and a resource can have several.

  • EThey operate at the instance level and apply to the resources associated with them

    Correct

    A security group controls the traffic allowed to reach and leave the resources it is associated with, such as an EC2 instance.

Security group: instance level, allow rules only, all rules evaluated, stateful. Network ACL: subnet level, allow and deny, numbered order, stateless.

Question 2 · choose 1

A startup has registered the domain name for its new product and wants visitors who type that name to reach its Application Load Balancer. It also wants to check the health of its endpoints. Which service does this?

  1. AAmazon CloudFront
  2. BAmazon Route 53
  3. CAWS Direct Connect
  4. DAmazon API Gateway
Show the answer and why
  • AAmazon CloudFront

    Incorrect

    CloudFront speeds up content delivery through edge locations. It does not translate domain names into addresses.

  • BAmazon Route 53

    Correct

    Route 53 is AWS's DNS service: it registers domain names, routes internet traffic for a domain to resources such as a load balancer, and checks the health of those resources.

  • CAWS Direct Connect

    Incorrect

    Direct Connect links an on-premises network to AWS over a dedicated connection. It has nothing to do with public domain names.

  • DAmazon API Gateway

    Incorrect

    API Gateway creates, publishes and manages APIs. It is not a DNS service.

Names to addresses, plus health checks to route around failures: that is DNS, and DNS on AWS is Route 53.

Question 3 · choose 1

A company moves large volumes of data every day between its data center and its VPC. It wants a dedicated network connection to AWS that does not run over the public internet. Which option should it choose?

  1. AAWS Site-to-Site VPN
  2. BAn internet gateway
  3. CA NAT gateway
  4. DAWS Direct Connect
Show the answer and why
  • AAWS Site-to-Site VPN

    Incorrect

    Site-to-Site VPN creates encrypted IPsec tunnels between your network and your VPC over your existing internet connection — secure, but not a dedicated private link.

  • BAn internet gateway

    Incorrect

    An internet gateway connects a VPC to the internet, which is exactly the path the company wants to avoid.

  • CA NAT gateway

    Incorrect

    A NAT gateway lets instances in private subnets reach outside services while blocking unsolicited inbound connections. It does not connect a data center.

  • DAWS Direct Connect

    Correct

    Direct Connect links your internal network to a Direct Connect location over a standard Ethernet fiber-optic cable, bypassing internet service providers in the network path.

VPN is quick to set up and rides the internet; Direct Connect is a dedicated physical connection. Many companies use both, with VPN as the backup.

Question 4 · choose 1

Database servers in a private subnet of a VPC must download software updates from the internet. They must not be reachable by connections that start on the internet. What should the company add?

  1. AGive the servers public IP addresses and route the subnet to an internet gateway
  2. BA NAT gateway in a public subnet
  3. CAn AWS Direct Connect connection
  4. DA VPC peering connection
Show the answer and why
  • AGive the servers public IP addresses and route the subnet to an internet gateway

    Incorrect

    That turns the subnet into a public one, where the servers can receive connections initiated from the internet.

  • BA NAT gateway in a public subnet

    Correct

    A NAT gateway lets instances in a private subnet connect to services outside the VPC, while external services cannot initiate connections to those instances.

  • CAn AWS Direct Connect connection

    Incorrect

    Direct Connect links an on-premises network to AWS. It does not give private instances outbound internet access.

  • DA VPC peering connection

    Incorrect

    Peering connects two VPCs so they can route traffic privately between them. It does not provide internet access.

Outbound only, from a private subnet: a NAT gateway. Inbound and outbound for public resources: an internet gateway.

Question 5 · choose 1

Which VPC component allows resources in a public subnet, such as a web server with a public IP address, to send traffic to and receive traffic from the internet?

  1. AA security group
  2. BA NAT gateway
  3. CAmazon Route 53
  4. DAn internet gateway
Show the answer and why
  • AA security group

    Incorrect

    A security group is a virtual firewall that allows or blocks traffic to a resource. It does not connect the VPC to the internet.

  • BA NAT gateway

    Incorrect

    A NAT gateway gives instances in private subnets outbound access only; connections from the internet cannot reach them through it.

  • CAmazon Route 53

    Incorrect

    Route 53 translates domain names into IP addresses. It does not carry the traffic between the VPC and the internet.

  • DAn internet gateway

    Correct

    An internet gateway is the VPC component that allows communication between resources in your VPC and the internet, in both directions for resources with public IP addresses.

A subnet is public because its route table sends internet traffic to an internet gateway. Security groups still decide what is allowed in.

Practise domain 3 →Practise all domains →