AWS Certified Advanced Networking – Specialty (ANS-C01) flashcards
132 free flashcards. Tap a card to flip it.
Centralized Egress with TGW (IPv6)
Flip cardAn architecture pattern using AWS Transit Gateway to route all outbound internet traffic from multiple VPCs through a single security VPC, supporting both IPv4 and IPv6.
- Enforces security policies uniformly across multiple VPCs.
- Simplifies network management and auditing.
- Leverages Transit Gateway for scalable and centralized routing.
Memory trick: All internet traffic transits through one security gateway, even for IPv6.
Route 53 Latency & Failover Routing
Flip cardA combination of Route 53 routing policies to direct users to the lowest latency healthy endpoint, with automatic failover to another healthy endpoint if the primary fails.
- Latency routing minimizes user response times.
- Failover routing ensures high availability.
- Requires health checks for failover to function.
- Useful for global, multi-region deployments.
Memory trick: Latency's fast, failover's a must, for global users, we put our trust!
TGW for Multi-VPC Segmentation
Flip cardUtilizing AWS Transit Gateway with distinct route tables per VPC attachment to achieve scalable and manageable network segmentation across multiple VPCs and AWS accounts.
- TGW acts as a central routing hub.
- Supports connections across thousands of VPCs.
- Separate TGW route tables enable granular segmentation.
- Simplifies network architecture for multi-account environments.
Memory trick: TGW's route tables, a segment for each, connecting VPCs, within easy reach!
Route 53 Latency and Failover Routing
Flip cardA combination of Route 53 routing policies to optimize user experience by directing traffic to the lowest-latency healthy endpoint, with an automatic fallback to another healthy endpoint if the primary fails.
- Latency routing minimizes network travel time for users.
- Failover routing ensures high availability by redirecting traffic from unhealthy endpoints.
- Can be combined to create resilient, performance-optimized global applications.
- Requires Route 53 health checks to determine endpoint health.
Memory trick: Route 53: Latency for Speed, Failover for Safety.
Centralized Egress with TGW
Flip cardUsing AWS Transit Gateway to route all outbound internet traffic from multiple VPCs through a single, dedicated Security VPC for inspection and filtering.
- TGW acts as a central hub.
- Simplifies network management for many VPCs.
- Enables consistent security policy enforcement.
- Security VPC hosts firewalls/IDS/IPS.
Memory trick: One way out, through the gate, security checked, no debate!
AWS PrivateLink (VPC Endpoint Service)
Flip cardA technology that enables private connectivity between VPCs and AWS services, other AWS accounts, and on-premises applications, without exposing data to the public internet.
- Provider creates a VPC Endpoint Service.
- Consumers create Interface VPC Endpoints to access the service.
- No public IP addresses, NAT gateways, or internet gateways required.
- Ideal for SaaS offerings and private service consumption.
Memory trick: PrivateLink is the private 'link' for your SaaS customers.
Route 53 Failover Routing
Flip cardA Route 53 routing policy that routes traffic to a resource if it's healthy, or to a different resource if the first is unhealthy.
- Requires Route 53 health checks to monitor endpoint health.
- Supports active-passive (primary/secondary) failover.
- Provides automatic DNS updates for disaster recovery.
Memory trick: Route 53 detects failure and switches traffic over, like a reliable DNS traffic cop.
Route 53 Private Hosted Zone & ALB
Flip cardCombining a Route 53 Private Hosted Zone for internal DNS resolution within a VPC with an Application Load Balancer for HTTP/HTTPS traffic distribution, health checks, and session management.
- Private Hosted Zone for internal DNS names.
- ALB for Layer 7 (HTTP/HTTPS) load balancing.
- ALB supports advanced routing and health checks.
- ALB can manage session stickiness.
Memory trick: Private DNS for internals, ALB for the web, high availability, no need to dread!
AWS Global Accelerator for Gaming
Flip cardLeveraging AWS Global Accelerator to provide static entry points and intelligent traffic routing over the AWS global network, optimizing for real-time network conditions and rapid failover for latency-sensitive applications like online games.
- Uses static Anycast IP addresses.
- Routes over the AWS global network backbone.
- Optimizes based on real-time network conditions.
- Faster failover than DNS-based methods.
Memory trick: Global Accelerator's the game's best friend, low latency, till the very end!
VPC Endpoints
Flip cardA feature that enables private connectivity from your VPC to supported AWS services and VPC endpoint services powered by AWS PrivateLink, without requiring an internet gateway, NAT device, VPN connection, or AWS Direct Connect connection.
- Keeps traffic within the Amazon network.
- Supports two types: Interface Endpoints (powered by PrivateLink) and Gateway Endpoints.
- Gateway Endpoints support S3 and DynamoDB.
- Enhances security by eliminating public internet exposure.
Memory trick: Endpoints keep your data 'inside the fence' of AWS.
Direct Connect with VPC Endpoints
Flip cardAn architecture that uses AWS Direct Connect for a private connection from on-premises to AWS, combined with VPC Endpoints (Gateway for S3, Interface for DynamoDB/others) to privately access AWS services without traversing the public internet.
- Direct Connect establishes a private link from on-premises to AWS.
- Direct Connect Gateway enables connectivity to VPCs across regions.
- Gateway VPC Endpoints provide private access to S3 and DynamoDB.
- Interface VPC Endpoints provide private access to other services (like DynamoDB API) via ENIs.
Memory trick: Directly Connect your private home to the Cloud's private services.
Centralized Egress with TGW (IPv4/IPv6)
Flip cardAn architecture where all internet-bound traffic from multiple spoke VPCs is routed through a central Egress VPC via AWS Transit Gateway. This allows for unified inspection and security enforcement using shared security appliances for both IPv4 and IPv6 traffic.
- Uses AWS Transit Gateway as a central hub.
- All internet-bound traffic from spoke VPCs routes to a dedicated Egress VPC.
- Security appliances (firewalls, IDS/IPS) are deployed in the Egress VPC.
- Simplifies network architecture and security policy enforcement.
Memory trick: Transit Gateway is the 'Traffic Cop' for all IPv4/IPv6 egress.