Skip to content
BytePatterns

SOA-C03 · Domain 5: Networking and Content Delivery · 18% of the exam

Task 5.1: Implement and optimize networking features and connectivity.

Building the network: subnets, route tables, network ACLs, security groups and gateways, private paths with VPC endpoints, PrivateLink and peering, the network protection services, and what each path costs.

Study it

Sample questions

Try each one before opening the answer. Every option is explained, with the AWS documentation page that proves it.

Question 1 · choose 1

A dual-stack VPC has private subnets whose instances already reach the internet over IPv4 through a NAT gateway. The instances now also have IPv6 addresses and must download updates from IPv6 servers on the internet. Nothing on the internet may start an IPv6 connection to them. What should the network team add?

  1. AAn egress-only internet gateway, with a ::/0 route to it in the private subnets' route table
  2. BA gateway VPC endpoint for the update servers, with routes in the private subnets' route table
  3. CAn Elastic IP address associated with each instance in the private subnets
  4. DA peering connection to another VPC that has an internet gateway, with a ::/0 route to the peer
Show the answer and why
  • AAn egress-only internet gateway, with a ::/0 route to it in the private subnets' route table

    Correct

    An egress-only internet gateway allows outbound IPv6 traffic and prevents the internet from initiating IPv6 connections to the instances.

  • BA gateway VPC endpoint for the update servers, with routes in the private subnets' route table

    Incorrect

    Gateway endpoints exist only for Amazon S3 and DynamoDB. They cannot reach arbitrary servers on the internet.

  • CAn Elastic IP address associated with each instance in the private subnets

    Incorrect

    An Elastic IP address is a public IPv4 address. It adds nothing for IPv6 traffic and would expose the instances over IPv4.

  • DA peering connection to another VPC that has an internet gateway, with a ::/0 route to the peer

    Incorrect

    Resources in a peered VPC cannot use the other VPC's internet gateway; peering does not support edge-to-edge routing.

IPv6 addresses are public by default, so outbound-only IPv6 needs its own component: the egress-only internet gateway, the IPv6 counterpart of outbound-only access.

Question 2 · choose 1

The monthly bill shows high data processing charges for a NAT gateway. VPC flow logs show that most of the traffic through it comes from batch instances in private subnets that read and write objects in Amazon S3 buckets in the same Region. The team wants the largest saving with the smallest change and no extra hourly charges. What should the team do?

  1. ATurn on S3 Transfer Acceleration for the buckets that the batch jobs use
  2. BCreate a gateway VPC endpoint for S3 and add it to the private subnets' route tables
  3. CCreate an interface VPC endpoint for S3 in each Availability Zone used by the instances
  4. DConfigure the buckets as Requester Pays buckets
Show the answer and why
  • ATurn on S3 Transfer Acceleration for the buckets that the batch jobs use

    Incorrect

    Transfer Acceleration speeds up long-distance transfers through edge locations and can add data transfer charges; the traffic would still cross the NAT gateway.

  • BCreate a gateway VPC endpoint for S3 and add it to the private subnets' route tables

    Correct

    A gateway endpoint gives S3 access without a NAT device, and there is no additional charge for using it.

  • CCreate an interface VPC endpoint for S3 in each Availability Zone used by the instances

    Incorrect

    An interface endpoint would also bypass the NAT gateway, but interface endpoints are billed, while gateway endpoints are not.

  • DConfigure the buckets as Requester Pays buckets

    Incorrect

    Requester Pays moves request and download costs from the bucket owner to the requester. It does nothing about the NAT gateway's processing charge.

NAT gateways charge for every gigabyte they process. Traffic to S3 or DynamoDB can skip them through gateway endpoints, which cost nothing extra.

Question 3 · choose 1

A software company runs a TCP-based licensing API on Amazon EC2 instances in its own VPC. About 50 customers, each with their own AWS accounts outside the company's organization, must reach the API privately from their VPCs. Several customers use the same CIDR range as the company's VPC, and customers must not gain access to anything else in that VPC. What should the operations team set up?

  1. AA VPC peering connection with each customer VPC and routes to the API subnet
  2. BAn internet-facing Application Load Balancer with a security group that lists customer IP ranges
  3. CA VPC endpoint service on a Network Load Balancer, with each customer allowed
  4. DShared subnets of the API's VPC, given to each customer account through AWS RAM
Show the answer and why
  • AA VPC peering connection with each customer VPC and routes to the API subnet

    Incorrect

    Peering cannot be created between VPCs whose CIDR blocks overlap, and it opens routing between the networks rather than one service.

  • BAn internet-facing Application Load Balancer with a security group that lists customer IP ranges

    Incorrect

    Traffic would cross the public internet instead of staying private, which the requirement rules out.

  • CA VPC endpoint service on a Network Load Balancer, with each customer allowed

    Correct

    With AWS PrivateLink the provider puts a Network Load Balancer in front of the service, allows specific principals, and each customer creates an interface endpoint in its own VPC; overlapping ranges are not a problem.

  • DShared subnets of the API's VPC, given to each customer account through AWS RAM

    Incorrect

    VPC subnets can be shared only with accounts in the same organization, and sharing would place customers inside the company's network.

Exposing one service, not a network, to many outside accounts with overlapping addresses is the case for an endpoint service with AWS PrivateLink.

Question 4 · choose 1

A security audit of a VPC finds that instances could resolve and contact domains that are known to host malware and botnet command-and-control servers. The instances use the VPC's default DNS resolver. The team wants to block DNS queries for such domains for every instance in the VPC, using threat lists that AWS keeps up to date. What should the team configure?

  1. AOutbound network ACL rules that deny the IP addresses the bad domains resolve to
  2. BAn AWS WAF web ACL with an IP reputation rule group on the Application Load Balancer
  3. COutbound security group rules that exclude the known bad domains
  4. DA DNS Firewall rule group that blocks AWS Managed Domain Lists
Show the answer and why
  • AOutbound network ACL rules that deny the IP addresses the bad domains resolve to

    Incorrect

    Network ACLs filter by IP address and cannot block DNS requests to the Route 53 Resolver. AWS points to DNS Firewall for filtering DNS.

  • BAn AWS WAF web ACL with an IP reputation rule group on the Application Load Balancer

    Incorrect

    AWS WAF inspects HTTP(S) requests that reach protected resources such as a load balancer. It does not see the instances' outbound DNS queries.

  • COutbound security group rules that exclude the known bad domains

    Incorrect

    Security groups support allow rules only, not deny rules, and they match IP addresses, not domain names.

  • DA DNS Firewall rule group that blocks AWS Managed Domain Lists

    Correct

    Resolver DNS Firewall filters outbound DNS queries from a VPC, and AWS maintains Managed Domain Lists of domains tied to malware, botnets and other threats.

Blocking by domain name happens at the resolver. DNS Firewall rule groups with AWS Managed Domain Lists do that for the whole VPC.

Practise domain 5 →Practise all domains →