1. A SysOps administrator is configuring a new VPC and needs to ensure that EC2 instances in a private subnet can initiate outbound connections to the internet for software updates and patches, but external hosts cannot initiate inbound connections to these instances. Which AWS networking component should be deployed in a public subnet to allow this?
Networking and Content Delivery
A.Internet Gateway (IGW)
B.VPC Endpoint
C.NAT Gateway
D.Virtual Private Gateway (VGW)
Show answerAnswer
C. NAT Gateway
A NAT Gateway allows instances in a private subnet to connect to the internet while preventing the internet from initiating connections to those instances. It is deployed in a public subnet and routes traffic through an Internet Gateway.
2. A company is deploying a new web application in a VPC. The application's EC2 instances are in a private subnet, and an Application Load Balancer (ALB) is in a public subnet. The security team requires that all outbound internet traffic from the EC2 instances be inspected by a third-party firewall appliance running on another EC2 instance, also in a private subnet. Which AWS service is best suited to route all outbound internet traffic from the application instances through the firewall appliance?
Networking and Content Delivery
A.Gateway Load Balancer (GWLB)
B.Internet Gateway
C.VPC Endpoint
D.NAT Gateway
Show answerAnswer
A. Gateway Load Balancer (GWLB)
Gateway Load Balancer (GWLB) is specifically designed to deploy, scale, and manage virtual appliances such as firewalls, intrusion detection systems, and deep packet inspection systems. It acts as a transparent network gateway for all traffic, routing it through the appliance fleet before it reaches its destination (either the internet or other VPCs). This allows the third-party firewall to inspect all outbound traffic from the application instances.
3. A SysOps administrator needs to configure a highly available and scalable DNS solution for a new web application. The application will be accessed by users globally. The administrator wants to use a custom domain name (example.com) and ensure that if the primary application endpoint becomes unhealthy, traffic is automatically routed to a secondary, healthy endpoint in another region. Which Amazon Route 53 routing policy should be used to achieve this failover capability?
Networking and Content Delivery
A.Failover routing policy
B.Latency routing policy
C.Weighted routing policy
D.Simple routing policy
Show answerAnswer
A. Failover routing policy
The Failover routing policy in Route 53 allows you to route traffic to a resource when the primary resource is unhealthy. It requires associating health checks with records to automatically switch to a secondary endpoint if the primary fails.
4. A company is hosting a multi-tier application in a VPC. The web tier is in public subnets, and the application and database tiers are in private subnets. The application tier needs to connect to the database tier, and both tiers need to be able to communicate with backend services hosted in another VPC in the same AWS Region. The solution must be highly available and support transitive routing. Which AWS service should be used to connect the two VPCs?
Networking and Content Delivery
A.VPN Gateway
B.VPC Peering
C.AWS Transit Gateway
D.AWS Direct Connect
Show answerAnswer
C. AWS Transit Gateway
AWS Transit Gateway is designed for connecting multiple VPCs and on-premises networks in a hub-and-spoke model, supporting transitive routing. This means that resources in one VPC connected to the Transit Gateway can communicate with resources in another VPC connected to the same Transit Gateway, which is not possible with VPC Peering. Given the need for communication between multiple tiers across VPCs and transitive routing, Transit Gateway is the appropriate solution.
5. A SysOps administrator is configuring a new VPC and needs to ensure that EC2 instances in a private subnet can download patches and updates from the internet but cannot receive unsolicited inbound connections from the internet. Which TWO AWS networking components must be configured to achieve this securely and efficiently?
Networking and Content Delivery
A.VPC Endpoint and Security Group
B.Virtual Private Gateway and Network ACL
C.NAT Gateway and Route Table
D.Internet Gateway and Security Group
Show answerAnswer
C. NAT Gateway and Route Table
A NAT Gateway allows instances in a private subnet to connect to the internet (e.g., for patches) but prevents the internet from initiating connections to those instances. A Route Table must be configured in the private subnet to direct outbound internet-bound traffic (0.0.0.0/0) to the NAT Gateway in a public subnet. This combination ensures secure outbound-only internet access.
6. A SysOps administrator is designing a network architecture for a new application that requires very high throughput and low latency between EC2 instances in different subnets within the same VPC. The application is sensitive to network jitter. What is the MOST suitable networking feature to ensure optimal performance between these instances?
Networking and Content Delivery
A.VPC Peering
B.Jumbo Frames (MTU 9001)
C.Placement Groups (Cluster or Spread)
D.Enhanced Networking with ENA
Show answerAnswer
D. Enhanced Networking with ENA
Enhanced Networking with Elastic Network Adapter (ENA) provides significantly higher packet per second (PPS) performance, lower inter-instance latency, and lower network jitter compared to traditional network interfaces. This is crucial for applications requiring very high throughput and low latency within a VPC and sensitive to jitter. While Jumbo Frames can help with throughput by reducing packet overhead, ENA provides the fundamental performance improvement.
7. A developer has deployed a new application on EC2 instances within a private subnet. The application needs to securely access Amazon S3 and Amazon DynamoDB without traversing the public internet. Which AWS networking component should the SysOps administrator configure to meet this requirement?
Networking and Content Delivery
A.Internet Gateway
B.NAT Gateway
C.AWS Direct Connect
D.VPC Endpoint
Show answerAnswer
D. VPC Endpoint
VPC Endpoints allow you to privately connect your VPC to supported AWS services and VPC endpoint services powered by PrivateLink without requiring an internet gateway, NAT device, VPN connection, or AWS Direct Connect connection. Specifically, Gateway Endpoints for S3 and Interface Endpoints for DynamoDB enable secure access from private subnets.
8. A company is using an Application Load Balancer (ALB) to distribute traffic to EC2 instances. They want to ensure that only authenticated users can access a specific path of their application (e.g., /admin/*) and that users are redirected to an identity provider (IdP) for authentication if they are not authenticated. Which ALB feature should be configured?
Networking and Content Delivery
A.Target Group Health Checks
B.Path-based Routing
C.Listener Rules with Authentication Actions
D.Sticky Sessions
Show answerAnswer
C. Listener Rules with Authentication Actions
ALB Listener Rules allow you to define actions based on various conditions, including path patterns. One of the powerful actions is 'Authenticate', which enables integration with identity providers (IdPs) like Amazon Cognito, OIDC, or SAML. This action can be configured to redirect unauthenticated users to the IdP and then forward authenticated requests to a target group, precisely meeting the requirement for path-based authentication.
9. A company is hosting a static website on Amazon S3 and wants to ensure that users access the content over HTTPS. They also need to improve performance by caching content at edge locations globally. Which AWS service should the company use to achieve these requirements?
Networking and Content Delivery
A.Amazon CloudFront
B.Elastic Load Balancing (ELB)
C.Amazon API Gateway
D.AWS Global Accelerator
Show answerAnswer
A. Amazon CloudFront
Amazon CloudFront is a content delivery network (CDN) service that securely delivers data, videos, applications, and APIs to customers globally with low latency and high transfer speeds. It supports HTTPS and integrates directly with S3 for static website hosting.
10. A company is using AWS Transit Gateway to connect multiple VPCs and on-premises networks. A SysOps administrator needs to ensure that traffic between two specific VPCs (VPC A and VPC B) connected to the Transit Gateway never traverses the public internet, even if they are in different AWS regions. Which Transit Gateway feature is required?
Networking and Content Delivery
A.VPC peering connection.
B.AWS Site-to-Site VPN.
C.AWS Direct Connect.
D.Transit Gateway peering.
Show answerAnswer
D. Transit Gateway peering.
Transit Gateway peering allows you to connect two Transit Gateways across different AWS Regions. This establishes a direct, private connection between the Transit Gateways, enabling traffic to flow between attached VPCs in different regions without traversing the public internet, ensuring secure and low-latency communication.
11. A company is deploying a multi-tier application in an AWS VPC. The web tier is in public subnets, and the application and database tiers are in private subnets. The application tier needs to connect to the database tier, and both need to connect to an external logging service over the internet. The SysOps administrator wants to simplify network management and routing between these tiers and to the internet, avoiding complex peering connections between multiple VPCs if the architecture scales. Which AWS networking service provides a centralized hub for this connectivity?
Networking and Content Delivery
A.AWS Transit Gateway.
B.Internet Gateway.
C.VPC Peering.
D.NAT Gateway.
Show answerAnswer
A. AWS Transit Gateway.
AWS Transit Gateway acts as a central hub that connects VPCs, AWS accounts, and on-premises networks. It simplifies network architecture by eliminating the need for complex, mesh-like VPC peering connections as the number of VPCs grows, providing centralized routing and management for inter-VPC and hybrid cloud connectivity.
12. A company is deploying a new web application that requires high availability across multiple Availability Zones and wants to distribute incoming HTTP/HTTPS traffic to targets based on URL paths. Which type of load balancer should the SysOps administrator choose?
Networking and Content Delivery
A.Network Load Balancer (NLB)
B.Classic Load Balancer (CLB)
C.Application Load Balancer (ALB)
D.Gateway Load Balancer (GWLB)
Show answerAnswer
C. Application Load Balancer (ALB)
An Application Load Balancer (ALB) operates at the application layer (Layer 7) and supports path-based routing, allowing it to route requests to different target groups based on the URL path. It also provides high availability and fault tolerance across multiple Availability Zones.
13. A SysOps administrator needs to configure a highly available and scalable network architecture for a web application. The application will be hosted on Amazon EC2 instances in a private subnet, and users must access it via a public IP address. Security requirements dictate that only HTTP and HTTPS traffic should reach the application instances. Which combination of AWS services should be used?
Networking and Content Delivery
A.NAT Gateway, Direct Connect, Gateway Load Balancer, VPC Peering
D.Internet Gateway, NAT Gateway, Application Load Balancer (ALB), Security Group
Show answerAnswer
D. Internet Gateway, NAT Gateway, Application Load Balancer (ALB), Security Group
An Internet Gateway provides internet connectivity for the VPC. An Application Load Balancer (ALB) distributes HTTP/HTTPS traffic to EC2 instances in private subnets and can be configured with listeners for these protocols. A Security Group acts as a virtual firewall for the instances, allowing only specified traffic (HTTP/HTTPS). If instances are in private subnets, they don't need a NAT Gateway for inbound traffic from the internet through an ALB, but the ALB itself would be in a public subnet. The question implies public access to the application, and the ALB provides this while routing to private instances.
14. An application is served globally via Amazon CloudFront, with an Amazon S3 bucket as its origin. Users are reporting occasional '403 Access Denied' errors when trying to access specific objects. The S3 bucket policy allows public read access. What is the MOST likely cause of these errors?
Networking and Content Delivery
A.The objects in the S3 bucket are encrypted with a customer-managed key (CMK) in AWS KMS.
B.The S3 bucket policy explicitly denies access to CloudFront.
C.The CloudFront distribution's cache behavior is not set to forward query strings.
D.The CloudFront distribution is not configured with an Origin Access Control (OAC) or Origin Access Identity (OAI).
Show answerAnswer
D. The CloudFront distribution is not configured with an Origin Access Control (OAC) or Origin Access Identity (OAI).
If the S3 bucket policy allows public read access, CloudFront can fetch objects. However, a common best practice (and often the default for new S3 buckets) is to have 'Block public access' enabled, even if the bucket policy tries to grant public access. The most secure way for CloudFront to access a private S3 bucket (or one with 'Block public access' enabled) is by using an Origin Access Control (OAC) or the older Origin Access Identity (OAI). Without OAC/OAI, CloudFront might not have permission to fetch objects, leading to 403 errors, especially if S3's 'Block Public Access' settings are enabled, overriding the bucket policy.
15. A SysOps administrator is configuring a new VPC and needs to ensure that EC2 instances in a private subnet can download operating system patches from the internet, but cannot be directly accessed from the internet. The solution must be highly available and managed by AWS. Which networking component should be used?
Networking and Content Delivery
A.NAT Gateway.
B.NAT instance.
C.Internet Gateway.
D.VPC Endpoint.
Show answerAnswer
A. NAT Gateway.
A NAT Gateway provides a highly available and managed solution for instances in a private subnet to initiate outbound connections to the internet (e.g., for OS patches) while preventing unsolicited inbound connections from the internet. It operates from a public subnet and uses an Elastic IP.
16. A SysOps administrator needs to configure a custom domain name (example.com) for a static website hosted on Amazon S3 and delivered via Amazon CloudFront. The domain name is managed by Amazon Route 53. Which type of Route 53 record should be created to point the custom domain name to the CloudFront distribution?
Networking and Content Delivery
A.A CNAME record pointing to the S3 bucket URL.
B.An ALIAS record pointing to the CloudFront distribution's domain name.
C.An A record pointing to the CloudFront distribution's domain name.
D.A PTR record pointing to the CloudFront distribution's domain name.
Show answerAnswer
B. An ALIAS record pointing to the CloudFront distribution's domain name.
To map a root domain (like example.com) or a subdomain to a CloudFront distribution, an ALIAS record in Route 53 is the recommended and most efficient method. ALIAS records are a Route 53-specific extension to DNS that allow you to map your apex domain (e.g., example.com) directly to AWS resources like CloudFront distributions, without incurring DNS query charges and providing faster resolution than CNAMEs for apex domains.
17. A SysOps administrator needs to configure a highly available and scalable DNS solution for an application running on EC2 instances behind an Application Load Balancer (ALB). The solution must route traffic based on latency to the nearest region and perform health checks on the endpoints. Which AWS service should be used?
Networking and Content Delivery
A.Amazon Route 53 with Latency Routing Policy
B.Amazon Route 53 with Simple Routing Policy
C.Amazon CloudFront with origin failover
D.AWS Global Accelerator with custom routing
Show answerAnswer
A. Amazon Route 53 with Latency Routing Policy
Amazon Route 53's Latency Routing Policy is specifically designed to route user requests to the AWS Region that provides the lowest latency for the user. It also supports health checks to determine the availability of endpoints, redirecting traffic away from unhealthy ones. This perfectly matches the requirements for highly available, latency-based routing with health checks.
18. A SysOps administrator is configuring a highly available DNS solution for a critical web application. The application is hosted on EC2 instances behind an Application Load Balancer (ALB) in multiple AWS regions. The administrator needs to direct users to the nearest healthy endpoint based on their geographic location. If the primary region becomes unhealthy, traffic should automatically fail over to a healthy secondary region. Which Amazon Route 53 routing policy should be used?
Networking and Content Delivery
A.Latency routing policy.
B.Failover routing policy combined with Geolocation routing.
C.Geolocation routing policy.
D.Weighted routing policy.
Show answerAnswer
B. Failover routing policy combined with Geolocation routing.
To meet both requirements, a Geolocation routing policy is needed to direct users to the nearest endpoint based on their location. To add automatic failover if that endpoint (or region) becomes unhealthy, health checks must be associated, and this is typically combined with a Failover routing policy. You can combine Geolocation routing with health checks to achieve regional failover based on user location.
19. A SysOps administrator is troubleshooting intermittent connectivity issues for an EC2 instance in a private subnet. The instance needs to connect to an external API over the internet. The security groups and network ACLs are correctly configured. The instance has no public IP address. What is the most likely missing component that prevents the instance from reaching the internet?
Networking and Content Delivery
A.A NAT Gateway in a public subnet with a route from the private subnet.
B.An Internet Gateway attached to the VPC.
C.A VPC Endpoint configured for the external API.
D.An Elastic IP address associated with the EC2 instance.
Show answerAnswer
A. A NAT Gateway in a public subnet with a route from the private subnet.
EC2 instances in a private subnet with no public IP address cannot directly initiate outbound connections to the internet. A NAT Gateway, placed in a public subnet, allows instances in private subnets to connect to the internet while preventing inbound connections initiated from the internet. The private subnet's route table must have a route to the NAT Gateway.
20. An organization relies on an Application Load Balancer (ALB) to route traffic to its web application. The security team has mandated that all user sessions must be authenticated using corporate credentials before reaching the backend application. The SysOps administrator needs to configure the ALB to handle this authentication requirement seamlessly. Which ALB feature should be utilized?
Networking and Content Delivery
A.Cross-Zone Load Balancing
B.Target Group health checks
C.Listener rules with host-based routing
D.Authentication with Identity Providers (IdPs)
Show answerAnswer
D. Authentication with Identity Providers (IdPs)
ALB supports native integration with various Identity Providers (IdPs) like Amazon Cognito, Microsoft Active Directory (via SAML), or OpenID Connect. This allows the ALB to handle user authentication before forwarding authenticated requests to the backend targets, meeting the security mandate.
21. A company is experiencing intermittent connectivity issues to an EC2 instance in a private subnet from an on-premises data center connected via AWS Direct Connect. The network team has verified that the Direct Connect connection itself is stable, and the on-premises router has the correct routes for the VPC CIDR. However, ping and SSH to the instance fail. What is the MOST likely cause of this issue?
Networking and Content Delivery
A.The Network Access Control List (NACL) associated with the private subnet is blocking the traffic.
B.The Security Group attached to the EC2 instance is blocking the incoming traffic.
C.The Direct Connect Gateway is not associated with the correct Virtual Private Gateway.
D.The EC2 instance is in a public subnet, and its public IP address is being used.
Show answerAnswer
B. The Security Group attached to the EC2 instance is blocking the incoming traffic.
Given that Direct Connect is stable, on-premises routes are correct, and the instance is in a private subnet, the most common issue for failing ping and SSH (which use specific ports) is a restrictive Security Group. Security Groups act as stateful firewalls for instances, and if they don't explicitly allow ICMP for ping or TCP port 22 for SSH from the on-premises IP ranges, the connection will fail. NACLs are stateless and apply at the subnet level, often configured to be more permissive, but Security Groups are usually the first place to check for instance-specific traffic blocking.
22. A company is migrating a legacy application to AWS. The application uses UDP port 5000 for inter-service communication and requires extremely low latency and high throughput. The SysOps administrator needs to distribute UDP traffic to a fleet of EC2 instances. Which AWS service is the most appropriate for this requirement?
Networking and Content Delivery
A.Classic Load Balancer (CLB).
B.Network Load Balancer (NLB).
C.Amazon CloudFront.
D.Application Load Balancer (ALB).
Show answerAnswer
B. Network Load Balancer (NLB).
A Network Load Balancer (NLB) operates at Layer 4 (TCP/UDP) and is designed for extreme performance, high throughput, and ultra-low latency. It is the only Elastic Load Balancing type that supports UDP traffic distribution, making it ideal for the given requirements.
23. A company is deploying a new application that will process sensitive customer data. The application requires dedicated network performance and a consistent network experience between its on-premises data center and the AWS Cloud. The existing internet VPN connection is not meeting the performance and reliability requirements. Which AWS service should the company use to establish this connection?
Networking and Content Delivery
A.AWS Direct Connect
B.AWS Site-to-Site VPN
C.AWS Transit Gateway
D.VPC Peering
Show answerAnswer
A. AWS Direct Connect
AWS Direct Connect provides a dedicated private network connection from your premises to AWS. This offers consistent network performance, reduced cost for high bandwidth, and a more reliable experience compared to internet-based VPN connections, which is crucial for sensitive data and dedicated performance requirements.
24. A SysOps administrator needs to deploy a new security appliance (e.g., firewall, intrusion detection system) within a VPC. This appliance must inspect all north-south (internet-bound) and east-west (VPC internal) traffic between specific subnets. The appliance should be highly available, scalable, and transparently inserted into the network path without requiring manual route table changes for every new subnet or instance. Which AWS networking service is designed for this transparent traffic inspection and routing?
Networking and Content Delivery
A.Network Load Balancer (NLB)
B.Application Load Balancer (ALB)
C.AWS Transit Gateway
D.Gateway Load Balancer (GWLB)
Show answerAnswer
D. Gateway Load Balancer (GWLB)
The Gateway Load Balancer (GWLB) is specifically designed to deploy, scale, and manage virtual appliances such as firewalls, intrusion detection/prevention systems, and deep packet inspection systems. It acts as a transparent network gateway, directing all traffic to the appliance fleet and then back to its destination.
25. A SysOps administrator needs to establish a secure and dedicated network connection between an on-premises data center and an AWS VPC. The connection must offer consistent network performance and lower latency than an internet-based VPN connection. The company requires a private connection for transferring large datasets frequently. Which AWS service should the administrator recommend?
Networking and Content Delivery
A.VPC Peering.
B.AWS Direct Connect.
C.AWS Site-to-Site VPN.
D.Internet Gateway.
Show answerAnswer
B. AWS Direct Connect.
AWS Direct Connect provides a dedicated, private network connection from your on-premises data center to AWS. It offers consistent network performance, reduced network costs, and lower latency compared to internet-based connections like Site-to-Site VPN, making it ideal for transferring large datasets and critical applications.
A Network Address Translation (NAT) service that enables instances in a private subnet to connect to the internet or other AWS services, but prevents the internet from initiating a connection with those instances.
A service that makes it easy to deploy, scale, and manage virtual appliances such as firewalls, intrusion detection systems, and deep packet inspection systems.
Acts as a transparent network gateway.
Routes traffic to a fleet of virtual appliances.
Ensures all traffic passes through appliances for inspection/processing.
A Route 53 routing policy that allows you to route traffic to a primary resource when it's healthy, and to a secondary resource when the primary is unhealthy.
An Application Load Balancer feature that allows for direct authentication of users against an identity provider (IdP) before forwarding requests to backend targets.
Supports OIDC, Amazon Cognito, and SAML-based IdPs.
Can be configured as an action in listener rules.
Enables path-based authentication for different parts of an application.
Transit Gateway peering allows you to connect two Transit Gateways across different AWS Regions, enabling private communication between their attached VPCs and on-premises networks.
An Application Load Balancer (ALB) distributes incoming application traffic across multiple targets, such as EC2 instances, in multiple Availability Zones.
Operates at Layer 7 (HTTP/HTTPS).
Supports path-based, host-based, and query string-based routing.
A CloudFront feature that enables you to restrict access to your Amazon S3 bucket origins, allowing only CloudFront to retrieve content from the bucket.
Replaces the older Origin Access Identity (OAI).
Ensures S3 content is only accessible via CloudFront URLs.
Protects S3 buckets from direct public access while allowing CloudFront to serve content.
A Route 53-specific record type that provides a CNAME-like functionality for apex domains (root domains) to AWS resources, such as CloudFront distributions, without the limitations of CNAMEs.
Can be used for apex domains (e.g., example.com).
Points to specific AWS resources (CloudFront, ELB, S3 bucket).
Geolocation routing directs traffic based on user location, while Failover routing redirects traffic to a secondary resource if the primary becomes unhealthy, often used together for regional resilience.
Geolocation: Directs users to nearest endpoint.
Failover: Redirects if primary is unhealthy.
Combine for location-aware, resilient applications.
A systematic approach to diagnose and resolve network connectivity issues within an AWS environment, often starting with the most common points of failure.
A Network Load Balancer (NLB) operates at Layer 4 (TCP/UDP) and is optimized for extreme performance, high throughput, and ultra-low latency, making it suitable for demanding network traffic distribution.
Supports TCP and UDP protocols.
Handles millions of requests per second.
Provides static IP addresses per Availability Zone.
AWS Direct Connect creates a dedicated network connection from your premises to AWS, bypassing the public internet to offer consistent performance, reduced costs, and enhanced security.
Dedicated, private connection.
Consistent network performance and lower latency.
Ideal for large data transfers and hybrid environments.
A VPC Endpoint allows EC2 instances in private subnets to securely communicate with AWS Systems Manager without requiring an internet gateway, NAT device, or public IP addresses.
Enables private connectivity to AWS services.
Bypasses the public internet for enhanced security.
AWS CodePipeline automatically detects changes in an AWS CodeCommit repository when configured as a source stage, triggering pipeline executions without extra manual steps.
AWS SAM is a framework that extends AWS CloudFormation to provide a simplified way of defining serverless applications, bundling multiple components (Lambda, API Gateway, DynamoDB, etc.) into a single deployable unit.
Uses a simplified YAML/JSON template syntax.
Builds upon CloudFormation, transpiles to CloudFormation.
Includes SAM CLI for local development and testing.
S3 Object Lock in Compliance mode provides the highest level of data immutability, preventing objects from being overwritten or deleted by any user, including the root user, for a specified retention period.
WORM protection for S3 objects.
Prevents deletion/modification by all users, including root.
Questions are original practice items written to match the published exam objectives. Step2Study is not affiliated with or endorsed by any certification body.