Skip to content
BytePatterns

SAA-C03 · Domain 3: Design High-Performing Architectures · 24% of the exam

Task 3.4: Determine high-performing and/or scalable network architectures.

Network design that keeps up: subnet tiers and IP ranges, edge services for global users, the right load balancer, and private connections between VPCs and to on-premises networks.

Study it

Sample questions

Try each one before opening the answer. Every option is explained, with the AWS documentation page that proves it.

Question 1 · choose 1

A multiplayer game uses a custom UDP protocol. Game servers run behind Network Load Balancers in three AWS Regions. Players worldwide need fast entry onto the AWS network, two fixed IP addresses to allow-list, and failover between Regions that does not depend on DNS. Which solution meets these requirements?

  1. AAWS Global Accelerator with an endpoint group for each Region's load balancer
  2. BAmazon CloudFront with the three Network Load Balancers configured as origins
  3. CAmazon Route 53 latency-based routing that points to the three load balancers
  4. DAn Application Load Balancer in each Region with cross-zone load balancing on
Show the answer and why
  • AAWS Global Accelerator with an endpoint group for each Region's load balancer

    Correct

    Global Accelerator gives two static anycast IP addresses, supports UDP listeners, and reroutes to healthy Regional endpoints without DNS changes.

  • BAmazon CloudFront with the three Network Load Balancers configured as origins

    Incorrect

    CloudFront distributes static and dynamic web content. It does not carry a custom UDP protocol to game servers.

  • CAmazon Route 53 latency-based routing that points to the three load balancers

    Incorrect

    Latency routing answers DNS queries with a Region's load balancer, so players get no fixed pair of addresses, and failover happens through DNS.

  • DAn Application Load Balancer in each Region with cross-zone load balancing on

    Incorrect

    An Application Load Balancer handles HTTP and HTTPS inside one Region; it neither carries UDP nor spans Regions.

Static anycast IPs, UDP and health-based routing across Regions are Global Accelerator features. CloudFront is for web content.

Question 2 · choose 1

A company has 60 VPCs in one Region and two data centers connected by Site-to-Site VPN. Every VPC must reach every other VPC and both data centers, and the network team wants to manage routing in one place as more VPCs are added. Which solution meets these requirements?

  1. ACreate a full mesh of VPC peering connections plus a VPN connection to every VPC
  2. BPublish each VPC's services as AWS PrivateLink endpoint services for the others
  3. CCreate a VPN connection from each data center to every VPC's virtual private gateway
  4. DAttach all 60 VPCs and both of the VPN connections to one shared AWS Transit Gateway
Show the answer and why
  • ACreate a full mesh of VPC peering connections plus a VPN connection to every VPC

    Incorrect

    Peering is not transitive, so 60 VPCs need 1,770 connections, and each VPC can have at most 125 active peering connections.

  • BPublish each VPC's services as AWS PrivateLink endpoint services for the others

    Incorrect

    PrivateLink exposes individual services to consumers. It does not give full network routing between VPCs and data centers.

  • CCreate a VPN connection from each data center to every VPC's virtual private gateway

    Incorrect

    That means 120 VPN connections to maintain, and the VPCs would still have no path to each other.

  • DAttach all 60 VPCs and both of the VPN connections to one shared AWS Transit Gateway

    Correct

    A transit gateway is a hub that connects thousands of VPCs and on-premises networks, with routing controlled centrally in its route tables.

Many-to-many routing that grows over time is a hub-and-spoke problem. A transit gateway is the hub.

Question 3 · choose 2

A SaaS provider must expose a TCP service in its VPC to 200 customer VPCs in other AWS accounts. Many customer VPCs use CIDR ranges that overlap with the provider's and with each other. Customers must reach only this one service, and connections must start from the customer side. Which steps should the provider take? (Choose TWO.)

  1. ACreate a VPC peering connection between the provider VPC and every customer VPC
  2. BPut a Network Load Balancer in front of the service in the provider VPC
  3. CCreate a VPC endpoint service that customers reach through interface endpoints
  4. DAttach every customer VPC to a transit gateway that the provider shares
  5. EPublish the service on an internet-facing Application Load Balancer with AWS WAF
Show the answer and why
  • ACreate a VPC peering connection between the provider VPC and every customer VPC

    Incorrect

    VPC peering cannot connect VPCs with matching or overlapping CIDR blocks, and it opens network paths beyond one service.

  • BPut a Network Load Balancer in front of the service in the provider VPC

    Correct

    A PrivateLink endpoint service is fronted by a Network Load Balancer in the provider's VPC.

  • CCreate a VPC endpoint service that customers reach through interface endpoints

    Correct

    Consumers create interface endpoints to the endpoint service; only consumers can start connections, and overlapping IP ranges are fine.

  • DAttach every customer VPC to a transit gateway that the provider shares

    Incorrect

    A transit gateway routes between whole networks, so customers would reach more than one service, and overlapping ranges cannot be routed apart.

  • EPublish the service on an internet-facing Application Load Balancer with AWS WAF

    Incorrect

    This sends customer traffic over the internet instead of keeping it private, and an ALB does not serve a plain TCP service.

One service, many consumers, overlapping CIDRs and consumer-initiated connections: AWS PrivateLink, with a Network Load Balancer in front of the service.

Question 4 · choose 1

A news website runs on EC2 instances behind an Application Load Balancer in one Region, and readers worldwide see slow page loads. Pages contain many images and scripts that change rarely, plus HTML that is personalized for each signed-in reader. Which solution improves performance for global readers with the LEAST change to the application?

  1. AAn Amazon CloudFront distribution with the load balancer as its origin
  2. BAWS Global Accelerator in front of the load balancer, with the static files still served by the instances
  3. CCopies of the application in three more Regions, with Route 53 latency-based routing to each copy
  4. DLarger instance types for the web tier and a higher maximum size for the Auto Scaling group
Show the answer and why
  • AAn Amazon CloudFront distribution with the load balancer as its origin

    Correct

    CloudFront caches the static files at edge locations near readers and carries the personalized requests to the origin over the AWS network, with no change to the application.

  • BAWS Global Accelerator in front of the load balancer, with the static files still served by the instances

    Incorrect

    Global Accelerator speeds up the path to the load balancer, but it caches nothing: every image and script still travels from the origin for every reader.

  • CCopies of the application in three more Regions, with Route 53 latency-based routing to each copy

    Incorrect

    This would help, but running and synchronizing four deployments is a large change compared with adding a CDN in front of one.

  • DLarger instance types for the web tier and a higher maximum size for the Auto Scaling group

    Incorrect

    More capacity does not shorten the network distance between readers and the Region, which is what makes pages slow.

Static assets for a global audience belong in a CDN cache. CloudFront also accelerates the dynamic part, so one change addresses both.

Question 5 · choose 1

A mobile app calls a REST API on Amazon API Gateway that is backed by Lambda functions in us-east-1. Most users are in Europe, Asia and South America, and they see slow responses caused by long internet paths to the Region. The company wants each request to enter the AWS network at a location near the user, without deploying the API in more Regions and without creating or managing its own CloudFront distribution. Which API endpoint configuration should a solutions architect choose?

  1. AA Regional API endpoint with a Route 53 latency-based routing record
  2. BAn edge-optimized API endpoint, which routes requests through CloudFront
  3. CA private API endpoint reached through interface VPC endpoints
  4. DA Regional API endpoint added to an AWS Global Accelerator endpoint group
Show the answer and why
  • AA Regional API endpoint with a Route 53 latency-based routing record

    Incorrect

    A Regional endpoint is intended for clients in the same Region, and latency-based routing helps only when the application runs in several Regions to choose from.

  • BAn edge-optimized API endpoint, which routes requests through CloudFront

    Correct

    An edge-optimized endpoint routes requests to the nearest CloudFront point of presence, which helps geographically distributed clients, and API Gateway manages that CloudFront setup itself.

  • CA private API endpoint reached through interface VPC endpoints

    Incorrect

    A private API can be reached only from a VPC through an interface VPC endpoint, so mobile users on the internet could not call it at all.

  • DA Regional API endpoint added to an AWS Global Accelerator endpoint group

    Incorrect

    Global Accelerator endpoints are load balancers, EC2 instances and Elastic IP addresses. An API Gateway API cannot be added as an endpoint.

For clients spread around the world, the edge-optimized endpoint type puts the CloudFront edge network in front of the API with no distribution to run and no second Region.

Question 6 · choose 1

A market data provider streams prices to clients over a custom TCP protocol. The service must handle millions of requests per second with very low latency, give clients one static IP address per Availability Zone to allow-list, and pass the clients' source IP addresses through to the servers. Which load balancer should a solutions architect choose?

  1. AAn Application Load Balancer with listener rules for each path of the protocol
  2. BA Gateway Load Balancer in front of the servers
  3. CA Network Load Balancer with a TCP listener
  4. DA Classic Load Balancer with TCP listeners and cross-zone load balancing turned on
Show the answer and why
  • AAn Application Load Balancer with listener rules for each path of the protocol

    Incorrect

    An Application Load Balancer handles HTTP and HTTPS at layer 7. It cannot carry a custom TCP protocol, and it has no static IP address per zone.

  • BA Gateway Load Balancer in front of the servers

    Incorrect

    A Gateway Load Balancer is for deploying and scaling virtual appliances such as firewalls, not for serving clients directly.

  • CA Network Load Balancer with a TCP listener

    Correct

    A Network Load Balancer works at layer 4, handles millions of requests per second at very low latency, has a static IP address per zone, and can preserve client IP addresses.

  • DA Classic Load Balancer with TCP listeners and cross-zone load balancing turned on

    Incorrect

    The Classic Load Balancer is the previous generation. It offers no static IP address per zone, and AWS recommends the current load balancers instead.

Custom TCP, extreme performance, static IPs and client IP preservation are the Network Load Balancer's strengths.

Question 7 · choose 1

A VPC created with the CIDR block 10.0.0.0/22 has almost run out of free IP addresses as an Amazon EKS cluster in it grows. The team needs thousands more private IPv4 addresses in the same VPC without recreating the existing subnets. What should a solutions architect do?

  1. AEnlarge the VPC's existing CIDR block from /22 to /16
  2. BFree the five addresses that AWS reserves in each subnet so that pods can use them
  3. CCreate a second, larger VPC, peer it with this one, and launch the new nodes into the peered VPC
  4. DAssociate a secondary IPv4 CIDR block with the VPC and add new subnets from it
Show the answer and why
  • AEnlarge the VPC's existing CIDR block from /22 to /16

    Incorrect

    The size of an existing VPC CIDR block cannot be increased or decreased.

  • BFree the five addresses that AWS reserves in each subnet so that pods can use them

    Incorrect

    The first four addresses and the last address of every subnet are reserved and cannot be assigned, and five per subnet would not add thousands anyway.

  • CCreate a second, larger VPC, peer it with this one, and launch the new nodes into the peered VPC

    Incorrect

    This adds addresses in another VPC, not in this one, and splits the cluster's network across a peering connection.

  • DAssociate a secondary IPv4 CIDR block with the VPC and add new subnets from it

    Correct

    A VPC can have secondary IPv4 CIDR blocks associated with it, and new subnets can be created from them while the existing subnets stay as they are.

Address space is extended by adding CIDR blocks to the VPC, not by changing the primary block or an existing subnet.

Question 8 · choose 2

A company connects its data center to a VPC over AWS Direct Connect. Servers on premises must resolve names in a Route 53 private hosted zone associated with the VPC, and EC2 instances in the VPC must resolve names in the company's on-premises DNS domain. Which steps meet these requirements with the LEAST operational overhead? (Choose TWO.)

  1. ARecreate the private hosted zone as a public hosted zone so that on-premises servers can query it
  2. BCreate a Route 53 Resolver inbound endpoint and forward on-premises queries for the zone to it
  3. CRun DNS forwarder software on EC2 instances in the VPC for both directions
  4. DPeer the data center network with the VPC so that it can query the VPC's DNS resolver directly
  5. ECreate a Route 53 Resolver outbound endpoint with a forwarding rule for the on-premises domain
Show the answer and why
  • ARecreate the private hosted zone as a public hosted zone so that on-premises servers can query it

    Incorrect

    A public hosted zone publishes the internal names to the whole internet, and it does nothing for lookups from the VPC to on-premises DNS.

  • BCreate a Route 53 Resolver inbound endpoint and forward on-premises queries for the zone to it

    Correct

    An inbound endpoint gives on-premises DNS servers IP addresses in the VPC to forward queries to, so they can resolve the private hosted zone.

  • CRun DNS forwarder software on EC2 instances in the VPC for both directions

    Incorrect

    This works, but the company would patch, scale and keep highly available its own DNS servers, which the managed endpoints avoid.

  • DPeer the data center network with the VPC so that it can query the VPC's DNS resolver directly

    Incorrect

    VPC peering connects two VPCs, not a data center. Queries from on premises reach the Resolver through an inbound endpoint.

  • ECreate a Route 53 Resolver outbound endpoint with a forwarding rule for the on-premises domain

    Correct

    An outbound endpoint and a forwarding rule send queries for the on-premises domain from the VPC to the on-premises DNS servers.

Hybrid DNS has two directions: inbound endpoints for queries coming from on premises, outbound endpoints with rules for queries going there.

Practise domain 3 →Practise all domains →