Chapter
Answers to Assessment Test
Chapter 1 Introduction to Advanced Networking
AWS Global Infrastructure
Amazon Virtual Private Cloud
Services Outside Your VPC
Amazon Elastic Compute Cloud
Amazon Virtual Private Cloud
Chapter 2 Amazon Virtual Private Cloud (Amazon VPC) and Networking Fundamentals
Introduction to Amazon Virtual Private Cloud (Amazon VPC)
Network Access Control Lists (ACLs)
Network Address Translation (NAT) Instances and NAT Gateways
Egress-Only Internet Gateways (EIGWs)
Virtual Private Gateways (VGWs), Customer Gateways, and Virtual Private Networks (VPNs)
Elastic Network Interfaces
Dynamic Host Configuration Protocol (DHCP) Option Sets
Amazon Domain Name Service (DNS) Server
Chapter 3 Advanced Amazon Virtual Private Cloud (Amazon VPC)
VPC Endpoints and Security
Amazon DynamoDB Endpoints
Accessing Gateway Endpoints Over Remote Networks
Securing Gateway VPC Endpoints
AWS PrivateLink for Customer and Partner Services
Comparing AWS PrivateLink and VPC Peering
AWS PrivateLink Service Provider Considerations
AWS PrivateLink Service Consumer Considerations
Accessing a Shared Services VPC
Routing Across Peered VPCs
Resizing VPC Considerations
Reclaiming Elastic IP Addresses
Cross-Account Network Interfaces
Comparison with VPC Peering and VPC Endpoints
Chapter 4 Virtual Private Networks
Introduction to Virtual Private Networks
Virtual Private Gateway as a VPN Termination Endpoint
Availability and Redundancy
Amazon Elastic Compute Cloud (Amazon EC2) Instance as a VPN Termination Endpoint
Availability and Redundancy
VPN Termination Endpoint for On-Premises Networks (Customer Gateways)
Chapter 5 AWS Direct Connect
What Is AWS Direct Connect?
802.1Q Virtual Local Area Networks (VLANs)
Bidirectional Forwarding Detection
AWS Direct Connect Locations
Download Your Letter of Authorization
Cross-Connect to the AWS Port
AWS Direct Connect Partners
Public Virtual Interfaces
Private Virtual Interfaces
Hosted Virtual Interfaces
Dual Connection: Single Location
Single Connections: Dual Locations
Dual Connections: Dual Locations
Virtual Interface Configuration
Public Virtual Interface Configuration
Private Virtual Interface Configuration
Bidirectional Forwarding Detection
Virtual Private Network with AWS Direct Connect
Backup Virtual Private Network (VPN)
Virtual Private Network Over AWS Direct Connect
Integration with the Transit Virtual Private Cloud Solution
Border Gateway Protocol Path Selection
Private Virtual Interface Data Transfer
Public Virtual Interface Data Transfer
Chapter 6 Domain Name System and Load Balancing
Introduction to Domain Name System and Load Balancing
Domain Name System Concepts
Domain Names, Subdomains, and Hosts
Fully Qualified Domain Names
Steps Involved in DNS Resolution
Domain Level Name Servers
Start of Authority Record
Certificate Authority Authorization
Amazon EC2 DNS vs. Amazon Route 53
Amazon EC2 DNS and VPC Peering
Custom Amazon EC2 DNS Resolver
Domain Name System Service
Latency-Based Routing Policy
Geolocation Routing Policy
Multivalue Answer Routing
Traffic Flow to Route DNS Traffic
Geoproximity Routing (Traffic Flow Only)
Application Load Balancer
Internet-Facing Load Balancers
Elastic Load Balancing Concepts
Elastic Load Balancer Configuration
Cross-Zone Load Balancing
Connection Draining (Deregistration Delay)
Chapter 7 Amazon CloudFront
Introduction to Amazon CloudFront
Content Delivery Network Overview
The AWS CDN: Amazon CloudFront
How Amazon CloudFront Delivers Content
Configuring Amazon CloudFront
Amazon CloudFront Edge Locations
Amazon CloudFront Regional Edge Caches
Dynamic Content and Advanced Features
Dynamic Content, Multiple Origins, and Cache Behaviors
A Note on Performance: Dynamic Content and HTTP/2
Amazon CloudFront and AWS Certificate Manager (ACM)
Invalidating Objects (Web Distributions Only)
Amazon CloudFront and AWS Lambda@Edge
Amazon CloudFront Field-Level Encryption
Chapter 8 Network Security
Edge Locations and Regions
Security Groups and Network Access Control Lists (ACLs)
Amazon Elastic Compute Cloud (Amazon EC2)
Secure Shell (SSH) Login Attempts
Chapter 9 Network Performance
Network Performance Basics
Maximum Transmission Unit
Amazon Elastic Compute Cloud (Amazon EC2) Instance Networking Features
Amazon Elastic Block Store (Amazon EBS)-Optimized Instances
Network Address Translation (NAT) Gateways
Enabling Enhanced Networking
Additional Tuning and Driver Support
Load Balancer Performance
Virtual Private Network (VPN) Performance
AWS Direct Connect Performance
Quality of Service (QoS) in a VPC
High Performance Computing
Data Processing, Ingestion, and Backup
On-Premises Data Transfer
Amazon CloudWatch Metrics
Introduction to Network Automation
Verifying Changes with Change Sets
Configuring Non-AWS Resources
Pipeline Stages, Actions, and Artifacts
Monitoring Network Health Metrics
Creating Alarms for Unusual Events
Converting Logs to Metrics
Chapter 11 Service Requirements
Introduction to Service Requirements
The Elastic Network Interface
AWS Cloud Services and Their Network Requirements
Amazon WorkSpaces Requirements
Amazon AppStream 2.0 Requirements
AWS Lambda (Within a VPC)
Amazon EC2 Container Service (Amazon ECS)
Amazon Relational Database Service (Amazon RDS)
AWS Database Migration Service (AWS DMS)
Amazon Redshift Requirements
AWS Elastic Beanstalk Requirements
Chapter 12 Hybrid Architectures
Introduction to Hybrid Architectures
Application Architectures
Three-Tier Web Application
Applications Requiring Consistent Network Performance
Remote Desktop Application: Amazon Workspaces
Application Storage Access
Amazon Simple Storage Service (Amazon S3)
Amazon Elastic File System (Amazon EFS)
Hybrid Cloud Storage: AWS Storage Gateway
Application Internet Access
Access VPC Endpoints and Customer-Hosted Endpoints over AWS Direct Connect
Encryption on AWS Direct Connect
Use of Transitive Routing in Hybrid IT
Transit VPC Architecture Considerations
Chapter 13 Network Troubleshooting
Introduction to Network Troubleshooting
Methodology for Troubleshooting
Network Troubleshooting Tools
AWS Identity and Access Management (IAM) Policy Simulator
Troubleshooting Common Scenarios
Internet Key Exchange (IKE) Phase 1 and Phase 2 Troubleshooting
Network Access Control Lists
Virtual Private Cloud (VPC) Peering Connections
Connectivity to AWS Cloud Services
Amazon CloudFront Connectivity
Elastic Load Balancing Functionality
Service and Port-Hour Fees
Virtual Private Network (VPN) Connections
Data Transfer: Region to Region
Data Transfer: Same Region via Public IP
Data Transfer: Inter-Availability Zone
Data Transfer: VPC Peering
Data Transfer: Intra-Availability Zone
Virtual Private Network (VPN) Endpoints (Virtual Private Gateways [VGWs])
AWS Direct Connect Public Virtual Interfaces (VIFs)
Chapter 15 Risk and Compliance
It All Begins with Threat Modeling
Audit Reports and Other Papers
Ownership Model and the Role of Network Management
Controlling Access to AWS
Amazon CloudFront Distributions
AWS API Calls and Internet API Endpoints
Encryption in Transit Inside AWS Environments
Encryption in Load Balancers and Amazon CloudFront PoPs
Network Activity Monitoring
Malicious Activity Detection
AWS Shield and Anti-DDoS Measures
Amazon VPC Flow Logs Analysis
Amazon CloudWatch Alerting and AWS Lambda
AWS Marketplace and Other Third-Party Offerings
Security Information and Event Management (SIEM)
Intrusion Detection System (IDS)/Intrusion Prevention System (IPS)/AWS Web Application Firewall (AWS WAF)
Penetration Testing and Vulnerability Assessment
Penetration Test Authorization Scope and Exceptions
Applying for and Receiving Penetration Test Authorization
Chapter 16 Scenarios and Reference Architectures
Introduction to Scenarios and Reference Architectures
Hybrid Networking Scenario
Multi-Location Resiliency
Appendix Answers to Review Questions
Chapter 1: Introduction to Advanced Networking
Chapter 2: Amazon Virtual Private Cloud (Amazon VPC) and Networking Fundamentals
Chapter 3: Advanced Amazon Virtual Private Cloud (Amazon VPC)
Chapter 4: Virtual Private Networks
Chapter 5: AWS Direct Connect
Chapter 6: Domain Name System and Load Balancing
Chapter 7: Amazon CloudFront
Chapter 8: Network Security
Chapter 9: Network Performance
Chapter 11: Service Requirements
Chapter 12: Hybrid Architectures
Chapter 13: Network Troubleshooting
Chapter 15: Risk and Compliance
Chapter 16: Scenarios and Reference Architectures