Free knowledge base

AWS Certified Advanced Networking – Specialty (ANS-C01) — key terms, tricks & tips

Everything from the course in one searchable place: 215 entries. Use it to review before a practice test or look up a word you forgot.

215 results

Key term

Exam Guide

Official AWS document outlining exam domains, objectives, and topics.

Getting Started: Exam Overview & Strategy

Key term

Domain Weighting

Percentage of exam questions from a specific content area.

Getting Started: Exam Overview & Strategy

Key term

Multiple-Choice

Question type with one correct answer from several options.

Getting Started: Exam Overview & Strategy

Key term

Multiple-Response

Question type requiring selection of two or more correct answers.

Getting Started: Exam Overview & Strategy

Key term

Passing Score

Minimum score required to pass the certification exam (750).

Getting Started: Exam Overview & Strategy

Key term

Recertification

Process of renewing an AWS certification, typically every three years.

Getting Started: Exam Overview & Strategy

Key term

AWS Skill Builder

Official AWS platform for online training and learning paths.

Getting Started: Exam Overview & Strategy

Key term

Pearson VUE/PSI

Authorized testing centers for AWS certification exams.

Getting Started: Exam Overview & Strategy

Memory trick

Understanding the ANS-C01 Exam Format and Objectives

D-I-M-S-H: Design, Implementation, Management, Security, Hybrid. That's the order of the domains by weighting, from highest to lowest!

Getting Started: Exam Overview & Strategy

Exam tip

Understanding the ANS-C01 Exam Format and Objectives

The ANS-C01 exam has 65 questions and a time limit of 170 minutes. The passing score is 750. Remember these precise numbers.

Getting Started: Exam Overview & Strategy

Common mistake

Understanding the ANS-C01 Exam Format and Objectives

Underestimating the difficulty of the expert-level exam and not dedicating enough study time.

Getting Started: Exam Overview & Strategy

Common mistake

Understanding the ANS-C01 Exam Format and Objectives

Ignoring the official Exam Guide and focusing on generic networking topics instead of AWS-specific objectives.

Getting Started: Exam Overview & Strategy

Common mistake

Understanding the ANS-C01 Exam Format and Objectives

Not practicing with timed full-length exams, leading to poor time management during the actual test.

Getting Started: Exam Overview & Strategy

Key term

Active Learning

Engaging directly with material to process and retrieve information.

Getting Started: Exam Overview & Strategy

Key term

Passive Learning

Absorbing information without direct engagement, e.g., rereading.

Getting Started: Exam Overview & Strategy

Key term

AWS Whitepapers

Official AWS documents explaining architectural best practices and services.

Getting Started: Exam Overview & Strategy

Key term

Hands-on Experience

Practical application of knowledge by configuring and using AWS services.

Getting Started: Exam Overview & Strategy

Key term

Study Plan

A structured schedule for learning, reviewing, and practicing exam topics.

Getting Started: Exam Overview & Strategy

Memory trick

Effective Study Techniques & Resource Utilization

To remember the study cycle: A L P R T R (Assess, Learn, Practice, Review, Test, Refine) – 'Always Learn Practical Review, Then Repeat!'

Getting Started: Exam Overview & Strategy

Exam tip

Effective Study Techniques & Resource Utilization

The ANS-C01 exam frequently tests your ability to choose the most appropriate AWS networking service for a given scenario. Keywords like 'high bandwidth, low latency' often point to Direct Connect, while 'secure site-to-site connectivity' might indicate VPN. Memorize the primary use cases and limitations of core services like VPC, VPN, Direct Connect, Transit Gateway, and Route 53.

Getting Started: Exam Overview & Strategy

Common mistake

Effective Study Techniques & Resource Utilization

Relying solely on video courses without reading official documentation or doing hands-on labs.

Getting Started: Exam Overview & Strategy

Common mistake

Effective Study Techniques & Resource Utilization

Underestimating the importance of practice exams for identifying weak areas and time management.

Getting Started: Exam Overview & Strategy

Common mistake

Effective Study Techniques & Resource Utilization

Trying to memorize facts without understanding the underlying concepts and their practical application.

Getting Started: Exam Overview & Strategy

Key term

VPC Peering

Direct network connection between two VPCs.

Advanced Network Architectures & Connectivity

Key term

AWS Transit Gateway

Central routing hub for VPCs and on-premises networks.

Advanced Network Architectures & Connectivity

Key term

AWS PrivateLink

Private connectivity to services across VPCs/accounts.

Advanced Network Architectures & Connectivity

Key term

AWS Direct Connect

Dedicated private network connection to AWS.

Advanced Network Architectures & Connectivity

Key term

AWS Site-to-Site VPN

Encrypted tunnels over the internet to AWS.

Advanced Network Architectures & Connectivity

Key term

Direct Connect Gateway

Connects DX connections to multiple VPCs/TGWs.

Advanced Network Architectures & Connectivity

Key term

Hybrid Cloud

Integration of on-premises and cloud environments.

Advanced Network Architectures & Connectivity

Key term

Inter-Region Peering

Connecting Transit Gateways across different AWS regions.

Advanced Network Architectures & Connectivity

Memory trick

Designing Complex Multi-VPC and Hybrid Connectivity

Think of a 'T' for Transit Gateway: it's a Traffic hub, Transitive, and can connect to Thousands of networks.

Advanced Network Architectures & Connectivity

Exam tip

Designing Complex Multi-VPC and Hybrid Connectivity

The exam frequently tests the use cases and limitations of VPC Peering versus Transit Gateway. Remember that VPC Peering is non-transitive and point-to-point, while Transit Gateway is transitive and acts as a central hub. Also, know the benefits of Direct Connect (dedicated, consistent performance) vs. Site-to-Site VPN (cost-effective, internet-based).

Advanced Network Architectures & Connectivity

Common mistake

Designing Complex Multi-VPC and Hybrid Connectivity

Using VPC Peering for complex, many-to-many connectivity, leading to a 'spaghetti' network.

Advanced Network Architectures & Connectivity

Common mistake

Designing Complex Multi-VPC and Hybrid Connectivity

Not planning for non-overlapping CIDR blocks across all connected VPCs and on-premises networks, causing IP conflicts.

Advanced Network Architectures & Connectivity

Common mistake

Designing Complex Multi-VPC and Hybrid Connectivity

Failing to implement redundancy for Direct Connect or Site-to-Site VPN connections, creating single points of failure.

Advanced Network Architectures & Connectivity

Key term

BGP

Border Gateway Protocol; dynamic routing protocol for exchanging routes between autonomous systems.

Advanced Network Architectures & Connectivity

Key term

Transit Gateway

AWS service that connects VPCs and on-premises networks as a central hub.

Advanced Network Architectures & Connectivity

Key term

IPAM

IP Address Manager; AWS service for planning and managing IP addresses.

Advanced Network Architectures & Connectivity

Key term

CIDR

Classless Inter-Domain Routing; method for allocating IP addresses and routing IP packets.

Advanced Network Architectures & Connectivity

Key term

Static Route

Manually configured route entry in a routing table.

Advanced Network Architectures & Connectivity

Key term

Dynamic Route

Routes automatically learned and updated by routing protocols like BGP.

Advanced Network Architectures & Connectivity

Key term

Longest Prefix Match

Routing decision rule prioritizing the most specific route.

Advanced Network Architectures & Connectivity

Memory trick

Advanced Routing & IP Addressing

To remember BGP's role, think 'BGP Brings Global Paths' – it connects different networks over long distances.

Advanced Network Architectures & Connectivity

Exam tip

Advanced Routing & IP Addressing

On the exam, you must understand the role of BGP in Direct Connect and VPN connections for dynamic routing. Pay close attention to how Transit Gateway simplifies routing in multi-VPC and hybrid scenarios, and how IPAM helps manage large IP address spaces. Keywords: BGP, Transit Gateway, IPAM, Direct Connect routing.

Advanced Network Architectures & Connectivity

Common mistake

Advanced Routing & IP Addressing

Forgetting to configure route propagation from Direct Connect Gateway or VPN to Transit Gateway route tables.

Advanced Network Architectures & Connectivity

Common mistake

Advanced Routing & IP Addressing

Using overlapping IP CIDR blocks between VPCs or between AWS and on-premises networks, leading to routing conflicts.

Advanced Network Architectures & Connectivity

Common mistake

Advanced Routing & IP Addressing

Underestimating the complexity of managing static routes in large, dynamic environments.

Advanced Network Architectures & Connectivity

Key term

High Availability (HA)

Ensuring continuous operation within a single Region, minimizing downtime.

Advanced Network Architectures & Connectivity

Key term

Disaster Recovery (DR)

Restoring operations after large-scale disruptions, often multi-Region.

Advanced Network Architectures & Connectivity

Key term

Recovery Time Objective (RTO)

Maximum acceptable time to restore service after an outage.

Advanced Network Architectures & Connectivity

Key term

Recovery Point Objective (RPO)

Maximum acceptable data loss, measured in time, after an outage.

Advanced Network Architectures & Connectivity

Key term

Warm Standby

Scaled-down DR environment in another Region, quickly scaled up.

Advanced Network Architectures & Connectivity

Key term

Pilot Light

Minimal DR environment, only core services running, faster recovery than backup.

Advanced Network Architectures & Connectivity

Key term

Global Accelerator

Routes traffic to nearest healthy endpoint, improving availability and performance.

Advanced Network Architectures & Connectivity

Key term

DNS Failover

Route 53 feature to redirect traffic from unhealthy to healthy endpoints.

Advanced Network Architectures & Connectivity

Memory trick

High Availability & Disaster Recovery for Networks

Remember 'RTO is Time, RPO is Point (of data)'. Time to get back up, point in time of last good data.

Advanced Network Architectures & Connectivity

Exam tip

High Availability & Disaster Recovery for Networks

The exam frequently tests your understanding of RTO and RPO, and how different DR strategies (backup & restore, pilot light, warm standby, multi-site active/active) map to specific RTO/RPO requirements. Know the services used for each.

Advanced Network Architectures & Connectivity

Common mistake

High Availability & Disaster Recovery for Networks

Confusing HA (within Region) with DR (cross-Region).

Advanced Network Architectures & Connectivity

Common mistake

High Availability & Disaster Recovery for Networks

Not understanding the cost implications of lower RTO/RPO targets.

Advanced Network Architectures & Connectivity

Common mistake

High Availability & Disaster Recovery for Networks

Failing to test DR plans regularly; a plan not tested is not a plan.

Advanced Network Architectures & Connectivity

Key term

Route 53

AWS's highly available and scalable cloud DNS web service.

Advanced Network Architectures & Connectivity

Key term

Route 53 Resolver

Enables DNS resolution between VPCs and on-premises networks.

Advanced Network Architectures & Connectivity

Key term

VPC (Virtual Private Cloud)

A logically isolated virtual network in the AWS cloud.

Advanced Network Architectures & Connectivity

Key term

Subnet

A range of IP addresses in your VPC, isolated for specific resources.

Advanced Network Architectures & Connectivity

Key term

Security Group

A virtual firewall that controls traffic for one or more instances.

Advanced Network Architectures & Connectivity

Key term

NACL (Network ACL)

A stateless firewall that controls traffic for one or more subnets.

Advanced Network Architectures & Connectivity

Key term

Conditional Forwarding

Directs DNS queries for specific domains to designated DNS servers.

Advanced Network Architectures & Connectivity

Key term

Private Hosted Zone

A Route 53 hosted zone for DNS resolution within your VPCs.

Advanced Network Architectures & Connectivity

Memory trick

DNS Strategies and Network Segmentation Best Practices

Think 'VPC-S-N' for Segmentation: VPCs for big isolation, Subnets for smaller zones, NACLs for subnet rules, Security Groups for instance rules.

Advanced Network Architectures & Connectivity

Exam tip

DNS Strategies and Network Segmentation Best Practices

The exam frequently tests your understanding of Route 53 Resolver's role in hybrid DNS. Memorize the function of inbound and outbound endpoints, and how conditional forwarding rules are used to bridge on-premises and AWS DNS.

Advanced Network Architectures & Connectivity

Common mistake

DNS Strategies and Network Segmentation Best Practices

Forgetting to configure both inbound and outbound endpoints for full hybrid DNS resolution with Route 53 Resolver.

Advanced Network Architectures & Connectivity

Common mistake

DNS Strategies and Network Segmentation Best Practices

Confusing the stateful nature of Security Groups with the stateless nature of NACLs, leading to incorrect firewall rules.

Advanced Network Architectures & Connectivity

Common mistake

DNS Strategies and Network Segmentation Best Practices

Placing all application tiers in a single subnet, which compromises the benefits of network segmentation and security.

Advanced Network Architectures & Connectivity

Key term

VPC

Logically isolated network in AWS cloud.

Implementing Core AWS Networking Services

Key term

CIDR Block

Notation for defining IP address ranges.

Implementing Core AWS Networking Services

Key term

Route Table

Rules for directing network traffic.

Implementing Core AWS Networking Services

Key term

Internet Gateway

Enables internet connectivity for VPC.

Implementing Core AWS Networking Services

Key term

NAT Gateway

Allows private subnets outbound internet.

Implementing Core AWS Networking Services

Key term

Public Subnet

Subnet with route to Internet Gateway.

Implementing Core AWS Networking Services

Key term

Private Subnet

Subnet without direct internet access.

Implementing Core AWS Networking Services

Memory trick

VPC, Subnet, and Routing Configuration Deep Dive

VPC, Subnet, Route: 'Very Practical Systems Need Robust Operations Under Traffic Rules Everywhere.'

Implementing Core AWS Networking Services

Exam tip

VPC, Subnet, and Routing Configuration Deep Dive

The exam often tests the distinction between public and private subnets, and how Internet Gateways and NAT Gateways facilitate different types of internet access. Remember: IGW for inbound/outbound public access, NAT Gateway for outbound-only from private.

Implementing Core AWS Networking Services

Common mistake

VPC, Subnet, and Routing Configuration Deep Dive

Not planning CIDR blocks carefully, leading to IP exhaustion or overlap with on-premises networks.

Implementing Core AWS Networking Services

Common mistake

VPC, Subnet, and Routing Configuration Deep Dive

Incorrectly configuring route tables, resulting in instances being unable to reach the internet or other internal resources.

Implementing Core AWS Networking Services

Common mistake

VPC, Subnet, and Routing Configuration Deep Dive

Placing sensitive resources like databases in public subnets, exposing them to unnecessary risk.

Implementing Core AWS Networking Services

Key term

Site-to-Site VPN

IPsec tunnel over the public internet connecting on-premises to AWS VPCs.

Implementing Core AWS Networking Services

Key term

Client VPN

Managed OpenVPN service for remote users to securely access AWS resources.

Implementing Core AWS Networking Services

Key term

Direct Connect

Dedicated, private network connection from on-premises to AWS.

Implementing Core AWS Networking Services

Key term

Customer Gateway (CGW)

Logical representation of your on-premises VPN device in AWS.

Implementing Core AWS Networking Services

Key term

Virtual Private Gateway (VGW)

VPN concentrator on the Amazon side of a Site-to-Site VPN connection.

Implementing Core AWS Networking Services

Key term

Virtual Interface (VIF)

Logical interface over a Direct Connect connection for specific services.

Implementing Core AWS Networking Services

Memory trick

VPN, Direct Connect, and Transit Gateway

VPN is 'Virtual Public Network' (over internet), Direct Connect is 'Dedicated Private Network'. Transit Gateway is the 'Traffic Gatekeeper' for all your networks.

Implementing Core AWS Networking Services

Exam tip

VPN, Direct Connect, and Transit Gateway

The exam often tests the differences and appropriate use cases for Site-to-Site VPN vs. Direct Connect. Look for keywords like 'cost-effective,' 'over public internet,' or 'small branch' for VPN, and 'dedicated,' 'high bandwidth,' 'low latency,' or 'consistent performance' for Direct Connect. Also, understand how Transit Gateway simplifies complex multi-VPC and hybrid network topologies.

Implementing Core AWS Networking Services

Common mistake

VPN, Direct Connect, and Transit Gateway

Confusing Site-to-Site VPN with Client VPN: Site-to-Site connects networks, Client VPN connects individual users.

Implementing Core AWS Networking Services

Common mistake

VPN, Direct Connect, and Transit Gateway

Underestimating Direct Connect setup time: It's a physical connection that can take weeks or months to provision.

Implementing Core AWS Networking Services

Common mistake

VPN, Direct Connect, and Transit Gateway

Not using Transit Gateway for complex multi-VPC environments: Relying on VPC peering can lead to unmanageable network sprawl.

Implementing Core AWS Networking Services

Key term

DNS

Domain Name System, translates domain names to IP addresses.

Implementing Core AWS Networking Services

Key term

Hosted Zone

A container for records that manage traffic for a domain.

Implementing Core AWS Networking Services

Key term

NAT Instance

An EC2 instance configured to perform Network Address Translation.

Implementing Core AWS Networking Services

Key term

Elastic IP (EIP)

A static, public IPv4 address designed for dynamic cloud computing.

Implementing Core AWS Networking Services

Key term

Source/Destination Check

Security feature on EC2 instances; must be disabled for NAT Instances.

Implementing Core AWS Networking Services

Memory trick

Configuring DNS Resolution and Network Address Translation

Route 53 is like a 'Road Map' (R53) for the internet, guiding traffic to the right destination. NAT Gateway is like a 'Neighborhood Access Tunnel' for your private resources.

Implementing Core AWS Networking Services

Exam tip

Configuring DNS Resolution and Network Address Translation

The exam often tests the differences between NAT Gateways and NAT Instances, emphasizing that NAT Gateways are the preferred, managed solution for high availability and scalability. Also, know that for private hosted zones to work, both 'DNS resolution' and 'DNS hostnames' must be enabled in the VPC.

Implementing Core AWS Networking Services

Common mistake

Configuring DNS Resolution and Network Address Translation

Forgetting to update the private subnet's route table to point to the NAT Gateway for internet-bound traffic.

Implementing Core AWS Networking Services

Common mistake

Configuring DNS Resolution and Network Address Translation

Not deploying NAT Gateways in multiple Availability Zones for cross-AZ high availability when needed.

Implementing Core AWS Networking Services

Common mistake

Configuring DNS Resolution and Network Address Translation

Failing to enable 'DNS hostnames' in the VPC settings, which can prevent private hosted zones from resolving correctly for instances.

Implementing Core AWS Networking Services

Key term

Elastic Load Balancing (ELB)

Distributes incoming application traffic across multiple targets.

Implementing Core AWS Networking Services

Key term

Application Load Balancer (ALB)

Layer 7 load balancer for HTTP/HTTPS, advanced routing.

Implementing Core AWS Networking Services

Key term

Network Load Balancer (NLB)

Layer 4 load balancer for TCP/UDP/TLS, high performance.

Implementing Core AWS Networking Services

Key term

Gateway Load Balancer (GWLB)

Layer 3 load balancer for deploying virtual appliances.

Implementing Core AWS Networking Services

Key term

Auto Scaling Group (ASG)

Dynamically adjusts EC2 instance count based on demand.

Implementing Core AWS Networking Services

Key term

Target Group

Logically groups targets for a load balancer to route traffic.

Implementing Core AWS Networking Services

Key term

Health Check

Monitors the availability and responsiveness of registered targets.

Implementing Core AWS Networking Services

Memory trick

Load Balancing & Auto Scaling for Network Resilience

ALB for 'App' Layer, NLB for 'Network' Layer, GWLB for 'Gateway' appliances. Remember the first letter helps with the layer!

Implementing Core AWS Networking Services

Exam tip

Load Balancing & Auto Scaling for Network Resilience

The exam often tests the differences between ALB, NLB, and GWLB. Memorize their OSI layer, supported protocols, and primary use cases. For example, ALB for HTTP/HTTPS, NLB for extreme TCP/UDP performance, and GWLB for virtual appliances.

Implementing Core AWS Networking Services

Common mistake

Load Balancing & Auto Scaling for Network Resilience

Confusing the use cases of ALB vs. NLB; remember ALB for HTTP features, NLB for raw TCP/UDP performance.

Implementing Core AWS Networking Services

Common mistake

Load Balancing & Auto Scaling for Network Resilience

Not configuring proper health checks, leading to traffic being sent to unhealthy instances.

Implementing Core AWS Networking Services

Common mistake

Load Balancing & Auto Scaling for Network Resilience

Forgetting that Auto Scaling Groups can launch instances across multiple Availability Zones for higher resilience.

Implementing Core AWS Networking Services

Key term

VPC Flow Logs

Captures IP traffic details for network interfaces.

Monitoring, Optimization, and Automation

Key term

CloudWatch

Monitoring service for metrics, logs, and events.

Monitoring, Optimization, and Automation

Key term

CloudTrail

Records API calls and account activity.

Monitoring, Optimization, and Automation

Key term

Reachability Analyzer

Simulates network paths to check connectivity.

Monitoring, Optimization, and Automation

Key term

CloudWatch Alarms

Notifies when metric thresholds are breached.

Monitoring, Optimization, and Automation

Key term

Network ACLs

Stateless subnet-level traffic filters.

Monitoring, Optimization, and Automation

Key term

Security Groups

Stateful instance-level traffic filters.

Monitoring, Optimization, and Automation

Key term

Route 53 Resolver Query Logs

Records DNS queries from your VPCs.

Monitoring, Optimization, and Automation

Memory trick

Monitoring, Logging, and Troubleshooting Network Issues

Flows are for traffic, Trails for calls, Watch for metrics, Analyzer for walls!

Monitoring, Optimization, and Automation

Exam tip

Monitoring, Logging, and Troubleshooting Network Issues

On the exam, be prepared to differentiate between the use cases for VPC Flow Logs (traffic analysis), CloudTrail (API activity), and CloudWatch (metrics and alarms). Know that Reachability Analyzer explicitly checks reachability, not performance.

Monitoring, Optimization, and Automation

Common mistake

Monitoring, Logging, and Troubleshooting Network Issues

Only checking security groups and forgetting about Network ACLs or route tables when troubleshooting connectivity.

Monitoring, Optimization, and Automation

Common mistake

Monitoring, Logging, and Troubleshooting Network Issues

Not enabling VPC Flow Logs or CloudTrail logging until an issue occurs, making root cause analysis difficult.

Monitoring, Optimization, and Automation

Common mistake

Monitoring, Logging, and Troubleshooting Network Issues

Ignoring CloudWatch metrics and relying solely on application-level monitoring for network issues.

Monitoring, Optimization, and Automation

Key term

Throughput

Amount of data transferred over a network per unit of time.

Monitoring, Optimization, and Automation

Key term

Latency

Time delay for data to travel from source to destination.

Monitoring, Optimization, and Automation

Key term

Jumbo Frames

Ethernet frames with an MTU greater than 1500 bytes, typically 9001.

Monitoring, Optimization, and Automation

Key term

Enhanced Networking

Feature providing higher bandwidth and lower latency for EC2 instances.

Monitoring, Optimization, and Automation

Key term

Placement Group

Logical grouping of EC2 instances to influence their underlying hardware placement.

Monitoring, Optimization, and Automation

Key term

AWS Global Accelerator

Service that improves application availability and performance for global users.

Monitoring, Optimization, and Automation

Key term

Amazon CloudFront

Content Delivery Network (CDN) service for fast content delivery.

Monitoring, Optimization, and Automation

Memory trick

Network Performance Optimization Techniques

Think of 'TALK' to remember key performance metrics: Throughput, Availability, Latency, and K-packet loss (packet loss).

Monitoring, Optimization, and Automation

Exam tip

Network Performance Optimization Techniques

The exam often tests your understanding of when to use specific services for performance. Remember that Global Accelerator optimizes for global traffic over the AWS backbone, while Direct Connect is for private, dedicated connections from on-premises. CloudFront is specifically for content caching at edge locations.

Monitoring, Optimization, and Automation

Common mistake

Network Performance Optimization Techniques

Not selecting appropriate EC2 instance types with sufficient network performance capabilities.

Monitoring, Optimization, and Automation

Common mistake

Network Performance Optimization Techniques

Failing to configure jumbo frames when applicable, missing out on potential throughput gains.

Monitoring, Optimization, and Automation

Common mistake

Network Performance Optimization Techniques

Underestimating the impact of public internet latency for global users and not leveraging services like Global Accelerator or CloudFront.

Monitoring, Optimization, and Automation

Key term

Egress Data Transfer

Data transferred out of an AWS region; typically incurs the highest costs.

Monitoring, Optimization, and Automation

Key term

VPC Endpoint

Private connection to AWS services from within your VPC.

Monitoring, Optimization, and Automation

Key term

CloudFront

Content Delivery Network (CDN) service by AWS.

Monitoring, Optimization, and Automation

Key term

AWS Budgets

Service to set custom cost and usage alerts.

Monitoring, Optimization, and Automation

Key term

AWS Cost Explorer

Tool to visualize and manage AWS costs and usage.

Monitoring, Optimization, and Automation

Memory trick

Cost Optimization for AWS Networking Resources

E-C-O-N: Egress costs are high, CloudFront helps; Optimize NAT and TGW; Never forget to monitor!

Monitoring, Optimization, and Automation

Exam tip

Cost Optimization for AWS Networking Resources

The exam frequently tests knowledge of data transfer pricing, especially the difference between intra-region, inter-region, and internet egress costs. Pay close attention to scenarios involving cross-AZ, cross-region, and internet-bound traffic for services like EC2, S3, and NAT Gateway. Remember that VPC Endpoints for S3 and DynamoDB are free, but other VPC Endpoints incur hourly charges and data processing fees.

Monitoring, Optimization, and Automation

Common mistake

Cost Optimization for AWS Networking Resources

Forgetting that data transfer between Availability Zones in the same region still incurs a cost, unlike within the same AZ.

Monitoring, Optimization, and Automation

Common mistake

Cost Optimization for AWS Networking Resources

Overlooking charges for unused Elastic IP addresses, which accumulate quickly.

Monitoring, Optimization, and Automation

Common mistake

Cost Optimization for AWS Networking Resources

Not leveraging VPC Endpoints for private connectivity to AWS services, leading to unnecessary NAT Gateway or internet egress costs.

Monitoring, Optimization, and Automation

Key term

Infrastructure as Code (IaC)

Managing infrastructure using configuration files.

Monitoring, Optimization, and Automation

Key term

Declarative Automation

Specifying the desired end state, not the steps.

Monitoring, Optimization, and Automation

Key term

Imperative Automation

Specifying the exact steps to achieve a state.

Monitoring, Optimization, and Automation

Key term

Idempotency

Applying an operation multiple times yields same result.

Monitoring, Optimization, and Automation

Key term

Configuration Drift

Actual configuration deviates from desired state.

Monitoring, Optimization, and Automation

Key term

AWS CloudFormation

AWS service for declarative IaC provisioning.

Monitoring, Optimization, and Automation

Key term

AWS Systems Manager

Operational insights and automation for AWS resources.

Monitoring, Optimization, and Automation

Memory trick

Automating Network Tasks and Configuration Management

IAC: 'I Always Code' my infrastructure, ensuring it's repeatable and version-controlled.

Monitoring, Optimization, and Automation

Exam tip

Automating Network Tasks and Configuration Management

The exam often tests your understanding of which AWS service is best suited for a particular automation task. Look for keywords like 'infrastructure as code,' 'desired state,' and 'repeatable deployments' for CloudFormation. For 'event-driven,' 'scripted actions,' or 'ad-hoc commands,' consider Lambda or Systems Manager Run Command.

Monitoring, Optimization, and Automation

Common mistake

Automating Network Tasks and Configuration Management

Confusing imperative with declarative automation: Remember CloudFormation is declarative (what), while a Boto3 script is often imperative (how).

Monitoring, Optimization, and Automation

Common mistake

Automating Network Tasks and Configuration Management

Underestimating the importance of version control for IaC: Treat your infrastructure definitions like application code.

Monitoring, Optimization, and Automation

Common mistake

Automating Network Tasks and Configuration Management

Ignoring drift detection: Without it, your 'desired state' can quickly become out of sync with reality.

Monitoring, Optimization, and Automation

Key term

Network ACL (NACL)

A subnet-level firewall that controls traffic in and out of subnets.

Securing AWS Network Infrastructure

Key term

AWS WAF

A web application firewall protecting web apps from common exploits.

Securing AWS Network Infrastructure

Key term

Stateful

Automatically allows return traffic once inbound is permitted (Security Groups).

Securing AWS Network Infrastructure

Key term

Stateless

Requires explicit rules for both inbound and outbound traffic (NACLs).

Securing AWS Network Infrastructure

Key term

Web ACL

A set of rules in AWS WAF to allow, block, or count web requests.

Securing AWS Network Infrastructure

Key term

Defense-in-depth

Employing multiple layers of security controls to protect resources.

Securing AWS Network Infrastructure

Memory trick

Security Groups, Network ACLs, and AWS WAF

S-G is S-tateful for S-ingle instances. N-ACL is N-ot S-tateful for N-etwork subnets.

Securing AWS Network Infrastructure

Exam tip

Security Groups, Network ACLs, and AWS WAF

The exam frequently tests the differences between Security Groups and Network ACLs. Remember: Security Groups are stateful, instance-level, and only allow rules. NACLs are stateless, subnet-level, and have both allow/deny rules evaluated in order. AWS WAF is Layer 7 for web applications.

Securing AWS Network Infrastructure

Common mistake

Security Groups, Network ACLs, and AWS WAF

Confusing stateful (Security Groups) with stateless (NACLs) behavior, leading to incomplete NACL rules.

Securing AWS Network Infrastructure

Common mistake

Security Groups, Network ACLs, and AWS WAF

Applying NACL rules to individual instances instead of subnets, or Security Group rules to subnets.

Securing AWS Network Infrastructure

Common mistake

Security Groups, Network ACLs, and AWS WAF

Forgetting that Security Groups are 'allow' only, and trying to use them to explicitly deny traffic.

Securing AWS Network Infrastructure

Key term

AWS Shield

Managed DDoS protection service for AWS applications.

Securing AWS Network Infrastructure

Key term

DDoS

Distributed Denial of Service attack, overwhelming a target.

Securing AWS Network Infrastructure

Key term

AWS Shield Advanced

Enhanced DDoS protection, DRT access, and cost protection.

Securing AWS Network Infrastructure

Key term

AWS Firewall Manager

Centrally configures and manages security policies across accounts.

Securing AWS Network Infrastructure

Key term

AWS Organizations

Service for centrally managing multiple AWS accounts.

Securing AWS Network Infrastructure

Key term

Amazon GuardDuty

Threat detection service monitoring for malicious activity.

Securing AWS Network Infrastructure

Key term

AWS Security Hub

Centralized view of security alerts and posture.

Securing AWS Network Infrastructure

Key term

DDoS Response Team (DRT)

24/7 expert support for AWS Shield Advanced customers.

Securing AWS Network Infrastructure

Memory trick

AWS Shield, Firewall Manager, and Intrusion Detection

Imagine a 'SHIELD' protecting your 'FIREWALL' from 'INTRUDERS'. Shield stops the big attacks, Firewall Manager organizes all your defenses, and GuardDuty is your watchful detective.

Securing AWS Network Infrastructure

Exam tip

AWS Shield, Firewall Manager, and Intrusion Detection

Remember that AWS Shield Standard is automatically enabled for all AWS customers, providing baseline DDoS protection. AWS Shield Advanced is an opt-in service that provides enhanced protections and access to the DDoS Response Team (DRT). Firewall Manager is key for centralizing WAF, Shield Advanced, Security Group, and Network Firewall policies across AWS Organizations.

Securing AWS Network Infrastructure

Common mistake

AWS Shield, Firewall Manager, and Intrusion Detection

Assuming Shield Standard provides sufficient protection for all critical applications without evaluating Shield Advanced.

Securing AWS Network Infrastructure

Common mistake

AWS Shield, Firewall Manager, and Intrusion Detection

Not using Firewall Manager for multi-account environments, leading to inconsistent security policies and increased manual effort.

Securing AWS Network Infrastructure

Common mistake

AWS Shield, Firewall Manager, and Intrusion Detection

Relying solely on AWS Shield for all security, neglecting other intrusion detection services like GuardDuty.

Securing AWS Network Infrastructure

Key term

Compliance

Adherence to laws, regulations, and industry standards.

Securing AWS Network Infrastructure

Key term

Encryption in Transit

Protecting data as it moves between network locations.

Securing AWS Network Infrastructure

Key term

TLS

Transport Layer Security, encrypts web and application traffic.

Securing AWS Network Infrastructure

Key term

IPsec

Internet Protocol Security, secures communication over IP networks.

Securing AWS Network Infrastructure

Key term

PCI DSS

Standard for securing credit card transaction data.

Securing AWS Network Infrastructure

Key term

HIPAA

US law protecting patient health information privacy.

Securing AWS Network Infrastructure

Key term

AWS KMS

Manages cryptographic keys for AWS services.

Securing AWS Network Infrastructure

Key term

ACM

AWS Certificate Manager, manages SSL/TLS certificates.

Securing AWS Network Infrastructure

Memory trick

Compliance and Data Encryption in Transit

To remember key compliance acronyms: 'HIPP-C' for Healthcare (HIPAA), Industry (PCI DSS), Privacy (GDPR), and Public Sector (FedRAMP).

Securing AWS Network Infrastructure

Exam tip

Compliance and Data Encryption in Transit

The exam often tests your knowledge of which AWS services provide native encryption in transit and how to configure them for specific compliance standards. Keywords to look for include 'PCI DSS,' 'HIPAA,' 'GDPR,' 'TLS versions,' and 'VPN encryption.' Remember that AWS KMS is central to key management for many encryption services.

Securing AWS Network Infrastructure

Common mistake

Compliance and Data Encryption in Transit

Assuming all AWS traffic is encrypted by default without verifying specific service configurations.

Securing AWS Network Infrastructure

Common mistake

Compliance and Data Encryption in Transit

Not enforcing minimum TLS versions or strong cipher suites on public-facing endpoints.

Securing AWS Network Infrastructure

Common mistake

Compliance and Data Encryption in Transit

Overlooking internal network traffic encryption requirements for certain compliance standards.

Securing AWS Network Infrastructure

Key term

IAM Policy

A document defining permissions for AWS actions and resources.

Securing AWS Network Infrastructure

Key term

Identity-Based Policy

An IAM policy attached to an IAM user, group, or role.

Securing AWS Network Infrastructure

Key term

Resource-Based Policy

A policy attached directly to an AWS resource, like an S3 bucket.

Securing AWS Network Infrastructure

Key term

Principle of Least Privilege

Granting only the minimum permissions required for a task.

Securing AWS Network Infrastructure

Key term

IAM Role

An IAM identity that you can assume to gain temporary permissions.

Securing AWS Network Infrastructure

Key term

VPC Endpoint Policy

A resource-based policy controlling access to services via VPC endpoints.

Securing AWS Network Infrastructure

Key term

Service Control Policy (SCP)

An AWS Organizations policy to set maximum permissions for accounts.

Securing AWS Network Infrastructure

Memory trick

Implementing Robust Access Control for Network Services

To remember the order of policy evaluation: 'I Really Can't Say' - Identity, Resource, SCP (Service Control Policy).

Securing AWS Network Infrastructure

Exam tip

Implementing Robust Access Control for Network Services

The exam often tests the interaction between different policy types. Remember that a request is only allowed if ALL applicable policies (identity, resource, SCP) explicitly allow it, and no explicit deny is present in any policy. An explicit deny always overrides an allow.

Securing AWS Network Infrastructure

Common mistake

Implementing Robust Access Control for Network Services

Granting overly permissive IAM policies, such as 'AdministratorAccess', to users or roles that only need specific network permissions.

Securing AWS Network Infrastructure

Common mistake

Implementing Robust Access Control for Network Services

Forgetting to apply resource-based policies, leaving services accessible through private endpoints to unauthorized principals.

Securing AWS Network Infrastructure

Common mistake

Implementing Robust Access Control for Network Services

Not regularly reviewing and auditing existing policies, leading to 'permission creep' where users retain unnecessary access over time.

Securing AWS Network Infrastructure