AWS Certified Advanced Networking – Specialty (ANS-C01) flashcards
132 free flashcards. Tap a card to flip it.
AWS Transit Gateway
Flip cardAWS Transit Gateway connects VPCs and on-premises networks through a central hub, simplifying network management and scaling connectivity.
- Acts as a cloud router for centralizing network connections.
- Supports inter-region peering and multi-account connectivity.
- Eliminates the need for numerous point-to-point connections.
Memory trick: Transit Gateway: The central hub that connects all your cloud lands.
VPN over Direct Connect
Flip cardVPN over Direct Connect combines the dedicated bandwidth and consistent network experience of Direct Connect with the IPsec encryption of a Site-to-Site VPN, adding an extra layer of security.
- Uses an AWS Site-to-Site VPN connection
- Traffic travels over a Direct Connect Private VIF
- Provides IPsec encryption for sensitive data
- Enhances security beyond just the private DX connection
Memory trick: DX is the private road, VPN over DX is the armored car on that road.
Client-Side Encryption with KMS
Flip cardEncrypts data before it is sent to AWS, using keys managed by AWS KMS, providing maximum customer control over encryption for data in transit and at rest.
- Data is encrypted on the client-side before upload to AWS.
- Encryption keys are managed within AWS KMS, offering strong security and auditability.
- Provides the highest level of control and assurance for data encryption.
- Ensures data is encrypted both in transit and at rest from the customer's perspective.
Memory trick: Client-Side Keys give ultimate control over data's journey and rest.
AWS Site-to-Site VPN with Transit Gateway
Flip cardProvides secure, encrypted connectivity between on-premises networks and multiple AWS VPCs (potentially across regions) with dynamic routing and high availability.
- Site-to-Site VPN: Encrypted tunnels over public internet.
- Transit Gateway: Central hub for VPCs and on-premises connections.
- Supports BGP for dynamic routing.
- Automatic failover with redundant VPN tunnels.
Memory trick: VPN is the secure 'bridge', Transit Gateway is the 'central station' connecting all trains.
ELB Listener Security Policies
Flip cardELB listener security policies define the SSL/TLS protocols and ciphers that the load balancer uses when negotiating connections with clients, allowing for enforcement of specific TLS versions.
- Configured on ELB listeners (e.g., HTTPS listener).
- Controls accepted TLS protocols (e.g., TLS 1.2, 1.3).
- Controls accepted cipher suites.
Memory trick: ELB's Listener Policy: Your TLS Bouncer at the Door.
AWS Global Accelerator
Flip cardA networking service that improves the availability and performance of your applications with local and global users by directing traffic to optimal healthy endpoints.
- Uses static IP addresses
- Routes traffic to nearest healthy endpoint
- Automatic health checks and failover across regions
Memory trick: Global Accelerator: Your global traffic cop, always finding the fastest healthy route.
AWS Site-to-Site VPN
Flip cardA service that creates an encrypted connection between your on-premises network and your Amazon VPCs, typically over the public internet.
- Each VPN connection has two tunnels for high availability.
- Supports BGP for dynamic routing and automatic failover.
- Cost-effective solution for secure connectivity over the internet.
Memory trick: For 'site-to-site' resilience, use 'Site-to-Site VPN'.
Subnet Sizing (Growth)
Flip cardWhen sizing subnets, calculate current IP needs, add a buffer for expected growth, and account for AWS-reserved IP addresses (5 per subnet).
- Total IPs = 2^(32-CIDR_mask)
- Usable IPs = Total IPs - 5 (AWS reserved)
- Plan for current needs + future growth
- Choose the smallest CIDR block that fits the calculated usable IPs
Memory trick: Instances + Growth + Reserved = Total, then find the smallest CIDR math.
DXGW Inter-Region VPC Traffic Cost
Flip cardInter-region data transfer between VPCs associated with the *same* Direct Connect Gateway leverages the AWS global network at optimized, lower costs.
- Applies to VPCs in different regions
- VPCs must be associated with the same DXGW
- Traffic stays within AWS global network
- Cost-effective for inter-VPC traffic
Memory trick: Same DXGW, different VPCs: AWS backbone is the cheapest superhighway.
AWS Network Firewall
Flip cardA managed firewall service that provides network intrusion prevention and detection, URL filtering, and stateful packet inspection for all traffic traversing a VPC.
- Managed, highly available service.
- Stateful inspection, IPS/IDS, URL filtering.
- Deployed at the subnet level.
- Can be centrally managed with AWS Firewall Manager.
Memory trick: Network Firewall is the watchful 'bouncer' at every VPC's door, centrally managed.
Direct Connect Gateway
Flip cardA globally available resource that allows you to connect your AWS Direct Connect connection to one or more VPCs in any AWS Region (except China) using private virtual interfaces.
- Connects DX to multiple VPCs across regions
- Supports private virtual interfaces (VIFs)
- Enables cross-account connectivity
- Enhances network architecture flexibility
Memory trick: DX for speed, Gateway for spread, VPN for backup.
Direct Connect Gateway with Transit Gateway
Flip cardA combination that allows a single AWS Direct Connect connection to connect to multiple VPCs across different AWS Regions and accounts through Transit Gateways.
- Enables global hybrid connectivity.
- Simplifies routing and network architecture.
- Supports multiple VPCs and AWS accounts.
Memory trick: DX Gateway + TGW = Global Hub for Hybrid Harmony.
AWS Web Application Firewall (WAF)
Flip cardAWS WAF helps protect web applications from common web exploits and bots that may affect availability, compromise security, or consume excessive resources.
- Protects against SQL injection, XSS, etc.
- Integrates with CloudFront, ALB, API Gateway, AppSync.
- Supports custom rules, including rate-based rules for DDoS mitigation.
Memory trick: WAF is the Bouncer for Your Web App's Party.
Network Manager Route Analyzer
Flip cardAn AWS Network Manager feature that simulates and analyzes network paths within a global network, including Transit Gateway, to validate routing and identify misconfigurations.
- Simulates network paths.
- Verifies expected routing.
- Crucial for complex TGW environments.
Memory trick: For TGW routes, the Route Analyzer shows the true path.
TGW Appliance Mode & Firewall Manager
Flip cardA combination of AWS services for centralized network traffic inspection and automated security policy enforcement across an AWS Organization.
- Transit Gateway Appliance Mode enables routing traffic through a security VPC.
- Firewall Manager centralizes security policy deployment across accounts.
- Ensures all internet-bound traffic is inspected consistently.
Memory trick: TGW Appliance Mode and Firewall Manager make Inspection and Enforcement Effortless!
VPC Subnet Sizing
Flip cardThe process of dividing a VPC's CIDR block into smaller subnets, considering the number of IP addresses needed for resources and future growth.
- AWS reserves 5 IP addresses in each subnet.
- Number of usable IPs = 2^(32-CIDR) - 5.
- Allocate slightly more IPs than immediately needed for flexibility.
Memory trick: CIDR math: Bigger number, smaller block, more granular.
DynamoDB Fine-Grained Access (LeadingKeys)
Flip cardLeverages IAM policies with the `dynamodb:LeadingKeys` condition to grant fine-grained access to DynamoDB items based on the item's partition key.
- Enables tenant isolation in multi-tenant applications.
- Access is restricted at the database level, enforcing least privilege.
- Reduces the need for complex authorization logic within the application.
- The condition key matches the partition key (or the first part of a composite key) of DynamoDB items.
Memory trick: LeadingKeys lead to tenant's data, no peeking allowed.
EBS Encryption Enforcement with SCPs
Flip cardAWS Organizations Service Control Policies (SCPs) can be used to prevent the creation of unencrypted EBS volumes or volumes not using a specified KMS CMK, enforcing encryption at rest as a preventive control across an entire organization.
- SCPs are preventive, organization-wide guardrails.
- Denies specific EC2 actions if encryption conditions are not met.
- Ensures compliance with encryption-at-rest policies.
Memory trick: SCP's Iron Rule: Encrypted EBS, or No Creation at All.
Transit Gateway Peering
Flip cardTransit Gateway peering connects two AWS Transit Gateways across different AWS Regions, enabling inter-region connectivity for all VPCs and on-premises networks attached to those Transit Gateways.
- Extends your global network across regions.
- Traffic between peered TGWs remains on the AWS global network.
- Requires route table configuration on both TGWs.
Memory trick: TGW Peering: The superhighway connecting your cloud cities across continents.
AWS Shield Advanced
Flip cardA paid, managed DDoS protection service that provides enhanced protections against larger and more sophisticated DDoS attacks, including 24/7 access to the AWS DDoS Response Team.
- Always-on detection and automatic inline mitigations for L3/L4 DDoS attacks.
- Advanced protection for web applications (L7) when integrated with WAF.
- Protects CloudFront, Route 53, ELB, EC2, Global Accelerator.
- Includes 24/7 access to AWS DDoS Response Team (DRT).
Memory trick: Shield Advanced is the 'elite bodyguard' with a 'special response team' for major attacks.
AWS Direct Connect
Flip cardA cloud service solution that makes it easy to establish a dedicated network connection from your premises to AWS.
- Dedicated, private connection.
- High throughput and consistent low latency.
- Reduces network costs and increases bandwidth.
Memory trick: Direct Connect is the 'Dedicated Lane' to AWS.
NAT Gateway Scaling and Resilience
Flip cardAWS NAT Gateways scale automatically but are zonal resources. For high availability and performance across AZs, multiple NAT Gateways should be used.
- Scales automatically up to 45 Gbps throughput.
- A single NAT Gateway is tied to a specific Availability Zone.
- Deploying one NAT Gateway per AZ and configuring route tables provides redundancy and load distribution.
Memory trick: To scale 'NAT' traffic, 'distribute' it across 'AZs'.
Direct Connect ECMP
Flip cardECMP (Equal-Cost Multi-Path) routing with AWS Direct Connect allows you to use multiple virtual interfaces or connections to an AWS Direct Connect gateway, distributing traffic across them to increase aggregate bandwidth and provide redundancy.
- Requires multiple Direct Connect connections or VIFs to the same Direct Connect Gateway.
- BGP advertises identical prefixes over multiple paths.
- Increases throughput and improves fault tolerance.
Memory trick: Direct Connect: More paths, more speed, more resilience, just like a multi-lane highway.
Continuous Compliance with AWS Config and Lambda
Flip cardAWS Config continuously monitors AWS resource configurations for compliance. When combined with AWS Lambda, it can automatically remediate non-compliant resources, ensuring a desired security posture is maintained.
- AWS Config assesses resource configurations against rules.
- Conformance Packs deploy rules across an organization.
- AWS Lambda can be triggered by Config to automate remediation.
Memory trick: Config & Lambda: The Automated Compliance Patrol.
Amazon GuardDuty
Flip cardA managed threat detection service that continuously monitors for malicious activity and unauthorized behavior to protect your AWS accounts and workloads.
- Analyzes VPC Flow Logs, DNS logs, CloudTrail logs.
- Identifies compromised instances, unusual API calls, port scans.
- Managed, no software to deploy.
- Can be enabled across multiple accounts via AWS Organizations.
Memory trick: GuardDuty is the vigilant 'security guard' always watching your AWS accounts for danger.
S3 Access Control
Flip cardMechanisms used to define who can access Amazon S3 buckets and objects, and what actions they can perform.
- IAM Policies: Identity-based access control.
- S3 Bucket Policies: Resource-based access control.
- S3 Block Public Access: Prevents public access at account/bucket level.
Memory trick: IAM controls 'WHO', Bucket 'WHAT', Block 'NO PUBLIC'.
Direct Connect Packet Loss Monitoring
Flip cardUtilizing the `ConnectionErrorCount` CloudWatch metric for AWS Direct Connect to proactively detect packet loss and other errors indicating connection quality degradation.
- Monitors `ConnectionErrorCount` metric.
- Directly indicates packet loss/errors.
- Crucial for maintaining hybrid network reliability.
Memory trick: Errors in the connection count, that's where packet loss is found.
AWS Network Manager Performance Monitoring
Flip cardA feature within AWS Network Manager that provides visibility into the performance of your global network hosted on AWS, including Transit Gateways.
- Measures latency, jitter, packet loss, and throughput between network attachments.
- Helps identify performance bottlenecks and optimize network design.
- Visualizes network performance data on a global map.
Memory trick: To 'manage' global network 'performance,' use 'Network Manager.'
ALB Listener Security Policies
Flip cardApplication Load Balancers (ALB) can be configured with HTTPS listeners and security policies to enforce TLS versions and ciphers, and HTTP listeners for redirection to HTTPS.
- ALB HTTP listener can redirect to HTTPS.
- ALB HTTPS listener supports predefined and custom security policies.
- Security policies define allowed TLS versions and cipher suites.
- ALB offloads SSL/TLS processing from backend instances.
Memory trick: Listeners redirect to HTTPS, policies secure the TLS handshake.
Enhanced Networking (ENA)
Flip cardA feature for EC2 instances that provides significantly higher packet per second (PPS) performance, lower network jitter, and lower latency through a custom Elastic Network Adapter (ENA).
- Uses ENA to bypass virtualized network stack.
- Offers bare-metal-like network performance.
- Crucial for high-performance computing and latency-sensitive apps.
Memory trick: To make your EC2 fly, ENA is the way to high network performance.
Network Access Control List (NACL)
Flip cardA Network Access Control List (NACL) is a stateless firewall that controls traffic in and out of one or more subnets.
- Operates at the subnet level
- Stateless (separate rules for inbound and outbound)
- Allows or denies specific IP addresses, ports, and protocols
- Rules are evaluated in order, from lowest to highest
Memory trick: ACLs are like traffic cops for subnets, Security Groups are bouncers for instances.
CloudFormation StackSets
Flip cardAn extension of AWS CloudFormation that enables you to provision, update, or delete stacks across multiple AWS accounts and Regions with a single operation.
- Ensures consistent resource deployment across an AWS Organization.
- Manages infrastructure as code (IaC) at scale.
- Supports automatic deployment to new accounts added to an Organization.
Memory trick: For 'consistent' 'stacks' across 'sets' of accounts, use 'StackSets'.
Centralized Inspection VPC with TGW & DX Gateway
Flip cardA network architecture using AWS Transit Gateway to connect multiple VPCs and on-premises networks, routing all traffic through a dedicated inspection VPC for centralized security services like firewall appliances.
- AWS Transit Gateway acts as a central hub for VPC and hybrid connectivity.
- Direct Connect Gateway integrates on-premises networks with TGW across regions.
- A dedicated inspection VPC hosts shared security appliances (e.g., Network Firewall).
- All inter-VPC and hybrid traffic can be forced through the inspection VPC for scrutiny.
Memory trick: Transit Gateway routes all traffic through the inspection VPC.
NAT Gateway
Flip cardA NAT Gateway enables instances in private subnets to connect to the internet or other AWS services, while preventing the internet from initiating connections with those instances.
- Deployed in a public subnet.
- Requires an Elastic IP address.
- Traffic from private subnets is routed through it to the internet.
Memory trick: NAT Gateway: The one-way door to the internet for your private secrets.
S3 Server-Side Encryption with Customer-Provided Keys (SSE-C)
Flip cardSSE-C allows you to encrypt objects using your own encryption keys provided as part of the request. Amazon S3 manages the encryption and decryption process using the key you provide.
- You manage and provide the encryption key.
- S3 performs encryption/decryption server-side.
- Requires specific HTTP headers for upload and download.
Memory trick: Keys in Hand, Policy in Place, S3 Stays Encrypted.
VPC Subnet Sizing (CIDR)
Flip cardVPC subnet sizing involves selecting appropriate CIDR blocks for subnets to allocate sufficient IP addresses for resources while efficiently utilizing the overall VPC CIDR range.
- AWS reserves 5 IP addresses in each subnet (first four and last one).
- A /28 is the smallest subnet (16 IPs, 11 usable).
- A /23 provides 507 usable IP addresses.
- Efficient sizing balances current needs with future growth and IP conservation.
Memory trick: CIDR: The IP address jigsaw puzzle, fitting pieces for all your cloud rooms.
Cluster Placement Group
Flip cardA Cluster Placement Group is a logical grouping of instances within a single Availability Zone that are placed on the same underlying hardware to provide low-latency network performance.
- All instances are on the same rack or cluster within an AZ.
- Offers high network throughput and ultra-low latency.
- Suitable for tightly coupled applications (e.g., HPC, databases).
Memory trick: Placement Groups: Keeping your instances close, like best friends on the same playground.
Route 53 Resolver Inbound Endpoint
Flip cardA feature of Route 53 Resolver that allows DNS queries from on-premises networks to be resolved by the VPC's Route 53 Resolver.
- Enables hybrid DNS resolution (on-premises to AWS).
- Resolves private hosted zones and VPC-specific DNS names.
- Requires IP addresses in your VPC for DNS forwarding.
Memory trick: Inbound is for inquiries 'In' to AWS from on-prem.
Unauthorized Network Change Detection
Flip cardUsing AWS CloudTrail to log all AWS API calls and Amazon EventBridge to create rules that alert on specific network configuration changes made outside of approved processes.
- CloudTrail records all API actions.
- EventBridge filters and reacts to CloudTrail events.
- Essential for auditing and enforcing change management.
Memory trick: CloudTrail sees every step, EventBridge tells you if it's wrong.
AWS IP Address Manager (IPAM)
Flip cardA VPC feature that enables centralized planning, tracking, and monitoring of IP addresses across AWS and hybrid networks, preventing overlaps and automating allocation.
- Centralized IP address management
- Prevents CIDR overlaps
- Automates IP allocation for VPCs and subnets
- Supports hybrid networks
Memory trick: IPAM: Your network's librarian, organizing all the IP addresses neatly.
WAF & CloudFront Geo-restriction
Flip cardAWS WAF provides web application security, while CloudFront Geo-restriction controls content access based on user location.
- AWS WAF protects web applications from common web exploits.
- CloudFront Geo-restriction uses the viewer's IP address to determine location.
- Both services operate at the edge, close to the user, for efficient filtering.
Memory trick: Web Access Filter guards global content with geographic rules.
VPN Tunnel Metrics
Flip cardAmazon CloudWatch provides detailed metrics for AWS Site-to-Site VPN tunnels, indicating their operational status and data transfer.
- Monitors TunnelState (UP/DOWN)
- Reports IPSecTunnelState
- Confirms active encrypted connection when UP
Memory trick: CloudWatch VPN Metrics: The dashboard that lights up when encryption is active.
Direct Connect ConnectionErrorCount
Flip cardA CloudWatch metric that tracks the number of errors detected on an AWS Direct Connect connection, indicating potential physical or logical link issues.
- Monitors connection health.
- Increases with packet loss or physical link problems.
- Found in Amazon CloudWatch under Direct Connect metrics.
Memory trick: Directly Connect to CloudWatch to Catch Connection Errors Fast!
IPsec VPN over Direct Connect
Flip cardCombining AWS Direct Connect with IPsec VPN tunnels to provide both dedicated network connectivity and strong, end-to-end encryption for data in transit.
- Provides Layer 3 encryption.
- Meets high security and compliance standards (e.g., PCI DSS).
- Offers cryptographic isolation of traffic over the Direct Connect link.
Memory trick: Direct Connect plus 'IPsec' makes data 'SECURE'.
Real-time VPC Flow Analysis
Flip cardUsing Kinesis Data Firehose to ingest VPC Flow Logs and then streaming them to Amazon OpenSearch Service for near real-time analysis and visualization of network traffic patterns.
- Kinesis Firehose provides scalable, managed data ingestion.
- OpenSearch Service offers powerful search, analytics, and visualization (Kibana/OpenSearch Dashboards).
- Enables identification of top talkers, security threats, and performance bottlenecks in near real-time.
Memory trick: For 'fast flow' insights, 'firehose' to 'OpenSearch'.
Direct Connect with VPN
Flip cardCombines a dedicated private connection (Direct Connect) with a VPN for encrypted, high-performance connectivity between on-premises networks and AWS VPCs.
- Direct Connect provides private, low-latency, high-bandwidth connectivity.
- VPN adds an encryption layer over the Direct Connect connection.
- Direct Connect Gateway enables connectivity to multiple VPCs and AWS Regions.
Memory trick: Directly Connect Securely, Virtually Private, Globally Linked.
AWS Hybrid Routing Protocols
Flip cardAWS uses BGP (Border Gateway Protocol) for dynamic routing between AWS network services (like Direct Connect, Site-to-Site VPN, Transit Gateway) and on-premises networks.
- BGP enables automatic exchange of routing information.
- Supports high availability and automatic failover.
- Essential for complex hybrid cloud environments with dynamic changes.
Memory trick: To 'route' between 'borders', use 'BGP'.
Centralized Egress with Transit Gateway
Flip cardAn AWS network architecture pattern where all outbound internet traffic from multiple VPCs is routed through a single, dedicated inspection VPC using AWS Transit Gateway.
- Uses AWS Transit Gateway for scalable VPC connectivity.
- A dedicated 'Egress VPC' houses security appliances.
- AWS Network Firewall often deployed in the Egress VPC for inspection.
Memory trick: TRANSIT to the central 'EGRESS' for FIREWALL 'INSPECTION'.
DXGW Route Analyzer
Flip cardA tool within AWS Direct Connect Gateway that provides hop-by-hop path analysis from on-premises networks through the DXGW to AWS VPCs, aiding in troubleshooting hybrid connectivity issues.
- Analyzes paths through Direct Connect Gateway.
- Identifies routing and connectivity issues.
- Provides hop-by-hop BGP route details.
Memory trick: For Direct Connect Gateway paths, the Route Analyzer is your guiding light.
Gateway Load Balancer (GWLB)
Flip cardAn AWS load balancer that makes it easy to deploy, scale, and manage virtual appliances such as firewalls, intrusion detection and prevention systems, and deep packet inspection systems.
- Operates at Layer 3/4 (network layer)
- Transparent 'bump-in-the-wire' for appliances
- Supports GENEVE encapsulation for traffic forwarding
- Integrates with Transit Gateway for centralized inspection
Memory trick: GWLB is the transparent guard, every packet must pass.
VPC Gateway Endpoint
Flip cardA gateway that you can create in your VPC to enable private connection between your VPC and supported AWS services.
- Provides private connectivity to S3 and DynamoDB.
- Traffic stays within the Amazon network.
- Does not require an Internet Gateway or NAT device.
Memory trick: Endpoints are the 'private doors' to AWS services.
DX Gateway with Transit Gateway
Flip cardCombining Direct Connect Gateway with AWS Transit Gateway provides a scalable and simplified architecture for connecting multiple VPCs (across regions) and on-premises networks via a single Direct Connect connection.
- Direct Connect Gateway links DX to multiple VPCs (same or different regions)
- Transit Gateway acts as a central router for VPCs and DX Gateway
- Simplifies routing complexity compared to VPC peering
- Enables global network architecture with private connectivity
Memory trick: DX Gateway gets on-prem to AWS, Transit Gateway connects everything within AWS and to DX.
SSE-KMS with Customer-Managed Keys (CMKs)
Flip cardSSE-KMS uses AWS KMS to manage encryption keys. With a CMK, you have full control over key policy, rotation, and an audit trail of its usage through CloudTrail.
- Data encrypted at rest in S3.
- Keys managed in AWS KMS, controlled by customer.
- Provides audit trail via CloudTrail for key usage.
Memory trick: HIPAA's Key Rule: KMS CMK for Audit and Control.
VPN over Direct Connect Gateway
Flip cardThis architecture combines AWS Direct Connect Gateways for centralized connectivity to multiple VPCs, with AWS Site-to-Site VPN running over the Direct Connect private VIFs to provide secure, encrypted, and highly available communication to on-premises networks.
- Direct Connect Gateway aggregates multiple VPCs to DX connection.
- Site-to-Site VPN provides IPsec encryption over DX private VIFs.
- Ensures secure, encrypted, private connectivity with high availability.
Memory trick: DX Gateway Connects, VPN Encrypts, All Over Private VIFs.
Transit Gateway Multicast
Flip cardAWS Transit Gateway's capability to route multicast traffic between VPCs by creating multicast domains and associating subnets/instances as sources or members.
- Enables multicast across VPCs.
- Requires Transit Gateway multicast domains.
- Supports legacy applications needing multicast.
Memory trick: For VPC multicast, the Transit Gateway is your central director.
Centralized IDPS with AWS Network Firewall and Transit Gateway
Flip cardThis architecture leverages AWS Network Firewall for deep packet inspection and intrusion prevention, and AWS Transit Gateway for centralizing traffic from multiple VPCs, enabling a scalable and robust IDPS solution across an organization.
- AWS Network Firewall offers stateful firewall, IPS, and domain filtering.
- AWS Transit Gateway centralizes routing for multi-VPC environments.
- Provides deep packet inspection and prevention capabilities.
Memory trick: Network Firewall and TGW: The Centralized Security Watchtower.
Subnet Non-overlap
Flip cardWhen allocating CIDR blocks for subnets within a VPC, each subnet's CIDR range must be unique and not overlap with any other subnet's CIDR range.
- CIDR blocks define IP ranges (Start IP - End IP)
- Overlapping CIDRs cause routing conflicts
- Subnets are typically assigned contiguously for efficient IP space management
- Larger CIDR masks (e.g., /24) mean smaller IP ranges
Memory trick: No two roads can share the same address numbers.
CloudWatch Logs Insights
Flip cardA fully integrated, interactive query service for Amazon CloudWatch Logs that enables users to search and analyze log data to troubleshoot operational problems.
- Interactive query capabilities
- Supports various log formats
- Helps identify root causes quickly
Memory trick: CloudWatch Insights: Your logs' detective for quick problem-solving.
Config for Network ACL/SG Audit
Flip cardAWS Config continuously monitors and evaluates Network ACLs and Security Groups against defined rules for compliance with security policies, identifying overly permissive configurations.
- Continuous configuration auditing
- Uses managed or custom rules
- Identifies overly permissive NACL/SG rules
- Scalable across multiple accounts
Memory trick: Config: Your network's rulebook enforcer, always checking for open doors.
AWS Firewall Manager
Flip cardA security management service that allows you to centrally configure and manage firewall rules across your accounts and applications in AWS Organizations.
- Centralized management for WAF, Shield Advanced, Network Firewall.
- Applies policies across multiple accounts and VPCs.
- Automates deployment and ensures compliance.
- Requires AWS Organizations.
Memory trick: Firewall Manager is the 'orchestra conductor' for all security rules in your AWS Organization.