Step2Study
IT & TechnologySOA-C02100% Free

AWS Certified SysOps Administrator – Associate

Practice bank
200 Qs
Real exam
65 Qs
Time limit
180 min
Passing
Score of 720 out of 1,000

Exam blueprint

Monitoring, Logging, and Remediation
20%
Reliability and Business Continuity
16%
Deployment, Provisioning, and Automation
18%
Networking and Content Delivery
18%
Security and Compliance
16%
Cost and Performance Optimization
12%

Practice

Untimed · instant feedback · 4 practice tests of 90 questions

Questions per test

Custom practice

Flashcard on every question Mental map when you miss

Exam simulation

4 timed tests · 90 questions each · 249 min · pass 72% · 200 questions in the bank

+50 XP per test · +100 XP for a pass

Random simulation (weighted by domain)

Everything is open to everyone. Create a free account to save scores, XP, badges and get progress emails.

Free study resources

All resources →

Study with friends

Challenge a friend to beat your score.

AWS Certified SysOps Administrator – Associate practice test questions

Sample questions from the 200-question bank, with answers and explanations.

All questions
  1. 1. A SysOps administrator is configuring a new VPC and needs to ensure that EC2 instances in a private subnet can initiate outbound connections to the internet for software updates and patches, but external hosts cannot initiate inbound connections to these instances. Which AWS networking component should be deployed in a public subnet to allow this?

    Networking and Content Delivery

    • A. Internet Gateway (IGW)
    • B. VPC Endpoint
    • C. NAT Gateway
    • D. Virtual Private Gateway (VGW)
    Show answer

    C. NAT Gateway

    A NAT Gateway allows instances in a private subnet to connect to the internet while preventing the internet from initiating connections to those instances. It is deployed in a public subnet and routes traffic through an Internet Gateway.

  2. 2. A company is deploying a new web application in a VPC. The application's EC2 instances are in a private subnet, and an Application Load Balancer (ALB) is in a public subnet. The security team requires that all outbound internet traffic from the EC2 instances be inspected by a third-party firewall appliance running on another EC2 instance, also in a private subnet. Which AWS service is best suited to route all outbound internet traffic from the application instances through the firewall appliance?

    Networking and Content Delivery

    • A. Gateway Load Balancer (GWLB)
    • B. Internet Gateway
    • C. VPC Endpoint
    • D. NAT Gateway
    Show answer

    A. Gateway Load Balancer (GWLB)

    Gateway Load Balancer (GWLB) is specifically designed to deploy, scale, and manage virtual appliances such as firewalls, intrusion detection systems, and deep packet inspection systems. It acts as a transparent network gateway for all traffic, routing it through the appliance fleet before it reaches its destination (either the internet or other VPCs). This allows the third-party firewall to inspect all outbound traffic from the application instances.

  3. 3. A SysOps administrator needs to configure a highly available and scalable DNS solution for a new web application. The application will be accessed by users globally. The administrator wants to use a custom domain name (example.com) and ensure that if the primary application endpoint becomes unhealthy, traffic is automatically routed to a secondary, healthy endpoint in another region. Which Amazon Route 53 routing policy should be used to achieve this failover capability?

    Networking and Content Delivery

    • A. Failover routing policy
    • B. Latency routing policy
    • C. Weighted routing policy
    • D. Simple routing policy
    Show answer

    A. Failover routing policy

    The Failover routing policy in Route 53 allows you to route traffic to a resource when the primary resource is unhealthy. It requires associating health checks with records to automatically switch to a secondary endpoint if the primary fails.

  4. 4. A company is hosting a multi-tier application in a VPC. The web tier is in public subnets, and the application and database tiers are in private subnets. The application tier needs to connect to the database tier, and both tiers need to be able to communicate with backend services hosted in another VPC in the same AWS Region. The solution must be highly available and support transitive routing. Which AWS service should be used to connect the two VPCs?

    Networking and Content Delivery

    • A. VPN Gateway
    • B. VPC Peering
    • C. AWS Transit Gateway
    • D. AWS Direct Connect
    Show answer

    C. AWS Transit Gateway

    AWS Transit Gateway is designed for connecting multiple VPCs and on-premises networks in a hub-and-spoke model, supporting transitive routing. This means that resources in one VPC connected to the Transit Gateway can communicate with resources in another VPC connected to the same Transit Gateway, which is not possible with VPC Peering. Given the need for communication between multiple tiers across VPCs and transitive routing, Transit Gateway is the appropriate solution.

  5. 5. A SysOps administrator is configuring a new VPC and needs to ensure that EC2 instances in a private subnet can download patches and updates from the internet but cannot receive unsolicited inbound connections from the internet. Which TWO AWS networking components must be configured to achieve this securely and efficiently?

    Networking and Content Delivery

    • A. VPC Endpoint and Security Group
    • B. Virtual Private Gateway and Network ACL
    • C. NAT Gateway and Route Table
    • D. Internet Gateway and Security Group
    Show answer

    C. NAT Gateway and Route Table

    A NAT Gateway allows instances in a private subnet to connect to the internet (e.g., for patches) but prevents the internet from initiating connections to those instances. A Route Table must be configured in the private subnet to direct outbound internet-bound traffic (0.0.0.0/0) to the NAT Gateway in a public subnet. This combination ensures secure outbound-only internet access.

  6. 6. A SysOps administrator is designing a network architecture for a new application that requires very high throughput and low latency between EC2 instances in different subnets within the same VPC. The application is sensitive to network jitter. What is the MOST suitable networking feature to ensure optimal performance between these instances?

    Networking and Content Delivery

    • A. VPC Peering
    • B. Jumbo Frames (MTU 9001)
    • C. Placement Groups (Cluster or Spread)
    • D. Enhanced Networking with ENA
    Show answer

    D. Enhanced Networking with ENA

    Enhanced Networking with Elastic Network Adapter (ENA) provides significantly higher packet per second (PPS) performance, lower inter-instance latency, and lower network jitter compared to traditional network interfaces. This is crucial for applications requiring very high throughput and low latency within a VPC and sensitive to jitter. While Jumbo Frames can help with throughput by reducing packet overhead, ENA provides the fundamental performance improvement.

  7. 7. A developer has deployed a new application on EC2 instances within a private subnet. The application needs to securely access Amazon S3 and Amazon DynamoDB without traversing the public internet. Which AWS networking component should the SysOps administrator configure to meet this requirement?

    Networking and Content Delivery

    • A. Internet Gateway
    • B. NAT Gateway
    • C. AWS Direct Connect
    • D. VPC Endpoint
    Show answer

    D. VPC Endpoint

    VPC Endpoints allow you to privately connect your VPC to supported AWS services and VPC endpoint services powered by PrivateLink without requiring an internet gateway, NAT device, VPN connection, or AWS Direct Connect connection. Specifically, Gateway Endpoints for S3 and Interface Endpoints for DynamoDB enable secure access from private subnets.

  8. 8. A company is using an Application Load Balancer (ALB) to distribute traffic to EC2 instances. They want to ensure that only authenticated users can access a specific path of their application (e.g., /admin/*) and that users are redirected to an identity provider (IdP) for authentication if they are not authenticated. Which ALB feature should be configured?

    Networking and Content Delivery

    • A. Target Group Health Checks
    • B. Path-based Routing
    • C. Listener Rules with Authentication Actions
    • D. Sticky Sessions
    Show answer

    C. Listener Rules with Authentication Actions

    ALB Listener Rules allow you to define actions based on various conditions, including path patterns. One of the powerful actions is 'Authenticate', which enables integration with identity providers (IdPs) like Amazon Cognito, OIDC, or SAML. This action can be configured to redirect unauthenticated users to the IdP and then forward authenticated requests to a target group, precisely meeting the requirement for path-based authentication.

  9. 9. A company is hosting a static website on Amazon S3 and wants to ensure that users access the content over HTTPS. They also need to improve performance by caching content at edge locations globally. Which AWS service should the company use to achieve these requirements?

    Networking and Content Delivery

    • A. Amazon CloudFront
    • B. Elastic Load Balancing (ELB)
    • C. Amazon API Gateway
    • D. AWS Global Accelerator
    Show answer

    A. Amazon CloudFront

    Amazon CloudFront is a content delivery network (CDN) service that securely delivers data, videos, applications, and APIs to customers globally with low latency and high transfer speeds. It supports HTTPS and integrates directly with S3 for static website hosting.

  10. 10. A company is using AWS Transit Gateway to connect multiple VPCs and on-premises networks. A SysOps administrator needs to ensure that traffic between two specific VPCs (VPC A and VPC B) connected to the Transit Gateway never traverses the public internet, even if they are in different AWS regions. Which Transit Gateway feature is required?

    Networking and Content Delivery

    • A. VPC peering connection.
    • B. AWS Site-to-Site VPN.
    • C. AWS Direct Connect.
    • D. Transit Gateway peering.
    Show answer

    D. Transit Gateway peering.

    Transit Gateway peering allows you to connect two Transit Gateways across different AWS Regions. This establishes a direct, private connection between the Transit Gateways, enabling traffic to flow between attached VPCs in different regions without traversing the public internet, ensuring secure and low-latency communication.

  11. 11. A company is deploying a multi-tier application in an AWS VPC. The web tier is in public subnets, and the application and database tiers are in private subnets. The application tier needs to connect to the database tier, and both need to connect to an external logging service over the internet. The SysOps administrator wants to simplify network management and routing between these tiers and to the internet, avoiding complex peering connections between multiple VPCs if the architecture scales. Which AWS networking service provides a centralized hub for this connectivity?

    Networking and Content Delivery

    • A. AWS Transit Gateway.
    • B. Internet Gateway.
    • C. VPC Peering.
    • D. NAT Gateway.
    Show answer

    A. AWS Transit Gateway.

    AWS Transit Gateway acts as a central hub that connects VPCs, AWS accounts, and on-premises networks. It simplifies network architecture by eliminating the need for complex, mesh-like VPC peering connections as the number of VPCs grows, providing centralized routing and management for inter-VPC and hybrid cloud connectivity.

  12. 12. A company is deploying a new web application that requires high availability across multiple Availability Zones and wants to distribute incoming HTTP/HTTPS traffic to targets based on URL paths. Which type of load balancer should the SysOps administrator choose?

    Networking and Content Delivery

    • A. Network Load Balancer (NLB)
    • B. Classic Load Balancer (CLB)
    • C. Application Load Balancer (ALB)
    • D. Gateway Load Balancer (GWLB)
    Show answer

    C. Application Load Balancer (ALB)

    An Application Load Balancer (ALB) operates at the application layer (Layer 7) and supports path-based routing, allowing it to route requests to different target groups based on the URL path. It also provides high availability and fault tolerance across multiple Availability Zones.

  13. 13. A SysOps administrator needs to configure a highly available and scalable network architecture for a web application. The application will be hosted on Amazon EC2 instances in a private subnet, and users must access it via a public IP address. Security requirements dictate that only HTTP and HTTPS traffic should reach the application instances. Which combination of AWS services should be used?

    Networking and Content Delivery

    • A. NAT Gateway, Direct Connect, Gateway Load Balancer, VPC Peering
    • B. Virtual Private Gateway, Transit Gateway, Network Load Balancer (NLB), NACL
    • C. Internet Gateway, VPC Endpoint, Classic Load Balancer (CLB), Route Table
    • D. Internet Gateway, NAT Gateway, Application Load Balancer (ALB), Security Group
    Show answer

    D. Internet Gateway, NAT Gateway, Application Load Balancer (ALB), Security Group

    An Internet Gateway provides internet connectivity for the VPC. An Application Load Balancer (ALB) distributes HTTP/HTTPS traffic to EC2 instances in private subnets and can be configured with listeners for these protocols. A Security Group acts as a virtual firewall for the instances, allowing only specified traffic (HTTP/HTTPS). If instances are in private subnets, they don't need a NAT Gateway for inbound traffic from the internet through an ALB, but the ALB itself would be in a public subnet. The question implies public access to the application, and the ALB provides this while routing to private instances.

  14. 14. An application is served globally via Amazon CloudFront, with an Amazon S3 bucket as its origin. Users are reporting occasional '403 Access Denied' errors when trying to access specific objects. The S3 bucket policy allows public read access. What is the MOST likely cause of these errors?

    Networking and Content Delivery

    • A. The objects in the S3 bucket are encrypted with a customer-managed key (CMK) in AWS KMS.
    • B. The S3 bucket policy explicitly denies access to CloudFront.
    • C. The CloudFront distribution's cache behavior is not set to forward query strings.
    • D. The CloudFront distribution is not configured with an Origin Access Control (OAC) or Origin Access Identity (OAI).
    Show answer

    D. The CloudFront distribution is not configured with an Origin Access Control (OAC) or Origin Access Identity (OAI).

    If the S3 bucket policy allows public read access, CloudFront can fetch objects. However, a common best practice (and often the default for new S3 buckets) is to have 'Block public access' enabled, even if the bucket policy tries to grant public access. The most secure way for CloudFront to access a private S3 bucket (or one with 'Block public access' enabled) is by using an Origin Access Control (OAC) or the older Origin Access Identity (OAI). Without OAC/OAI, CloudFront might not have permission to fetch objects, leading to 403 errors, especially if S3's 'Block Public Access' settings are enabled, overriding the bucket policy.

  15. 15. A SysOps administrator is configuring a new VPC and needs to ensure that EC2 instances in a private subnet can download operating system patches from the internet, but cannot be directly accessed from the internet. The solution must be highly available and managed by AWS. Which networking component should be used?

    Networking and Content Delivery

    • A. NAT Gateway.
    • B. NAT instance.
    • C. Internet Gateway.
    • D. VPC Endpoint.
    Show answer

    A. NAT Gateway.

    A NAT Gateway provides a highly available and managed solution for instances in a private subnet to initiate outbound connections to the internet (e.g., for OS patches) while preventing unsolicited inbound connections from the internet. It operates from a public subnet and uses an Elastic IP.

  16. 16. A SysOps administrator needs to configure a custom domain name (example.com) for a static website hosted on Amazon S3 and delivered via Amazon CloudFront. The domain name is managed by Amazon Route 53. Which type of Route 53 record should be created to point the custom domain name to the CloudFront distribution?

    Networking and Content Delivery

    • A. A CNAME record pointing to the S3 bucket URL.
    • B. An ALIAS record pointing to the CloudFront distribution's domain name.
    • C. An A record pointing to the CloudFront distribution's domain name.
    • D. A PTR record pointing to the CloudFront distribution's domain name.
    Show answer

    B. An ALIAS record pointing to the CloudFront distribution's domain name.

    To map a root domain (like example.com) or a subdomain to a CloudFront distribution, an ALIAS record in Route 53 is the recommended and most efficient method. ALIAS records are a Route 53-specific extension to DNS that allow you to map your apex domain (e.g., example.com) directly to AWS resources like CloudFront distributions, without incurring DNS query charges and providing faster resolution than CNAMEs for apex domains.

  17. 17. A SysOps administrator needs to configure a highly available and scalable DNS solution for an application running on EC2 instances behind an Application Load Balancer (ALB). The solution must route traffic based on latency to the nearest region and perform health checks on the endpoints. Which AWS service should be used?

    Networking and Content Delivery

    • A. Amazon Route 53 with Latency Routing Policy
    • B. Amazon Route 53 with Simple Routing Policy
    • C. Amazon CloudFront with origin failover
    • D. AWS Global Accelerator with custom routing
    Show answer

    A. Amazon Route 53 with Latency Routing Policy

    Amazon Route 53's Latency Routing Policy is specifically designed to route user requests to the AWS Region that provides the lowest latency for the user. It also supports health checks to determine the availability of endpoints, redirecting traffic away from unhealthy ones. This perfectly matches the requirements for highly available, latency-based routing with health checks.

  18. 18. A SysOps administrator is configuring a highly available DNS solution for a critical web application. The application is hosted on EC2 instances behind an Application Load Balancer (ALB) in multiple AWS regions. The administrator needs to direct users to the nearest healthy endpoint based on their geographic location. If the primary region becomes unhealthy, traffic should automatically fail over to a healthy secondary region. Which Amazon Route 53 routing policy should be used?

    Networking and Content Delivery

    • A. Latency routing policy.
    • B. Failover routing policy combined with Geolocation routing.
    • C. Geolocation routing policy.
    • D. Weighted routing policy.
    Show answer

    B. Failover routing policy combined with Geolocation routing.

    To meet both requirements, a Geolocation routing policy is needed to direct users to the nearest endpoint based on their location. To add automatic failover if that endpoint (or region) becomes unhealthy, health checks must be associated, and this is typically combined with a Failover routing policy. You can combine Geolocation routing with health checks to achieve regional failover based on user location.

  19. 19. A SysOps administrator is troubleshooting intermittent connectivity issues for an EC2 instance in a private subnet. The instance needs to connect to an external API over the internet. The security groups and network ACLs are correctly configured. The instance has no public IP address. What is the most likely missing component that prevents the instance from reaching the internet?

    Networking and Content Delivery

    • A. A NAT Gateway in a public subnet with a route from the private subnet.
    • B. An Internet Gateway attached to the VPC.
    • C. A VPC Endpoint configured for the external API.
    • D. An Elastic IP address associated with the EC2 instance.
    Show answer

    A. A NAT Gateway in a public subnet with a route from the private subnet.

    EC2 instances in a private subnet with no public IP address cannot directly initiate outbound connections to the internet. A NAT Gateway, placed in a public subnet, allows instances in private subnets to connect to the internet while preventing inbound connections initiated from the internet. The private subnet's route table must have a route to the NAT Gateway.

  20. 20. An organization relies on an Application Load Balancer (ALB) to route traffic to its web application. The security team has mandated that all user sessions must be authenticated using corporate credentials before reaching the backend application. The SysOps administrator needs to configure the ALB to handle this authentication requirement seamlessly. Which ALB feature should be utilized?

    Networking and Content Delivery

    • A. Cross-Zone Load Balancing
    • B. Target Group health checks
    • C. Listener rules with host-based routing
    • D. Authentication with Identity Providers (IdPs)
    Show answer

    D. Authentication with Identity Providers (IdPs)

    ALB supports native integration with various Identity Providers (IdPs) like Amazon Cognito, Microsoft Active Directory (via SAML), or OpenID Connect. This allows the ALB to handle user authentication before forwarding authenticated requests to the backend targets, meeting the security mandate.

  21. 21. A company is experiencing intermittent connectivity issues to an EC2 instance in a private subnet from an on-premises data center connected via AWS Direct Connect. The network team has verified that the Direct Connect connection itself is stable, and the on-premises router has the correct routes for the VPC CIDR. However, ping and SSH to the instance fail. What is the MOST likely cause of this issue?

    Networking and Content Delivery

    • A. The Network Access Control List (NACL) associated with the private subnet is blocking the traffic.
    • B. The Security Group attached to the EC2 instance is blocking the incoming traffic.
    • C. The Direct Connect Gateway is not associated with the correct Virtual Private Gateway.
    • D. The EC2 instance is in a public subnet, and its public IP address is being used.
    Show answer

    B. The Security Group attached to the EC2 instance is blocking the incoming traffic.

    Given that Direct Connect is stable, on-premises routes are correct, and the instance is in a private subnet, the most common issue for failing ping and SSH (which use specific ports) is a restrictive Security Group. Security Groups act as stateful firewalls for instances, and if they don't explicitly allow ICMP for ping or TCP port 22 for SSH from the on-premises IP ranges, the connection will fail. NACLs are stateless and apply at the subnet level, often configured to be more permissive, but Security Groups are usually the first place to check for instance-specific traffic blocking.

  22. 22. A company is migrating a legacy application to AWS. The application uses UDP port 5000 for inter-service communication and requires extremely low latency and high throughput. The SysOps administrator needs to distribute UDP traffic to a fleet of EC2 instances. Which AWS service is the most appropriate for this requirement?

    Networking and Content Delivery

    • A. Classic Load Balancer (CLB).
    • B. Network Load Balancer (NLB).
    • C. Amazon CloudFront.
    • D. Application Load Balancer (ALB).
    Show answer

    B. Network Load Balancer (NLB).

    A Network Load Balancer (NLB) operates at Layer 4 (TCP/UDP) and is designed for extreme performance, high throughput, and ultra-low latency. It is the only Elastic Load Balancing type that supports UDP traffic distribution, making it ideal for the given requirements.

  23. 23. A company is deploying a new application that will process sensitive customer data. The application requires dedicated network performance and a consistent network experience between its on-premises data center and the AWS Cloud. The existing internet VPN connection is not meeting the performance and reliability requirements. Which AWS service should the company use to establish this connection?

    Networking and Content Delivery

    • A. AWS Direct Connect
    • B. AWS Site-to-Site VPN
    • C. AWS Transit Gateway
    • D. VPC Peering
    Show answer

    A. AWS Direct Connect

    AWS Direct Connect provides a dedicated private network connection from your premises to AWS. This offers consistent network performance, reduced cost for high bandwidth, and a more reliable experience compared to internet-based VPN connections, which is crucial for sensitive data and dedicated performance requirements.

  24. 24. A SysOps administrator needs to deploy a new security appliance (e.g., firewall, intrusion detection system) within a VPC. This appliance must inspect all north-south (internet-bound) and east-west (VPC internal) traffic between specific subnets. The appliance should be highly available, scalable, and transparently inserted into the network path without requiring manual route table changes for every new subnet or instance. Which AWS networking service is designed for this transparent traffic inspection and routing?

    Networking and Content Delivery

    • A. Network Load Balancer (NLB)
    • B. Application Load Balancer (ALB)
    • C. AWS Transit Gateway
    • D. Gateway Load Balancer (GWLB)
    Show answer

    D. Gateway Load Balancer (GWLB)

    The Gateway Load Balancer (GWLB) is specifically designed to deploy, scale, and manage virtual appliances such as firewalls, intrusion detection/prevention systems, and deep packet inspection systems. It acts as a transparent network gateway, directing all traffic to the appliance fleet and then back to its destination.

  25. 25. A SysOps administrator needs to establish a secure and dedicated network connection between an on-premises data center and an AWS VPC. The connection must offer consistent network performance and lower latency than an internet-based VPN connection. The company requires a private connection for transferring large datasets frequently. Which AWS service should the administrator recommend?

    Networking and Content Delivery

    • A. VPC Peering.
    • B. AWS Direct Connect.
    • C. AWS Site-to-Site VPN.
    • D. Internet Gateway.
    Show answer

    B. AWS Direct Connect.

    AWS Direct Connect provides a dedicated, private network connection from your on-premises data center to AWS. It offers consistent network performance, reduced network costs, and lower latency compared to internet-based connections like Site-to-Site VPN, making it ideal for transferring large datasets and critical applications.

AWS Certified SysOps Administrator – Associate flashcards

Tap a card to flip it. 146 flashcards in the full deck.

  • NAT Gateway

    Flip card

    A Network Address Translation (NAT) service that enables instances in a private subnet to connect to the internet or other AWS services, but prevents the internet from initiating a connection with those instances.

    • Deployed in a public subnet
    • Requires an Elastic IP address
    • Routes traffic through an Internet Gateway
    Study this card →
  • AWS Gateway Load Balancer (GWLB)

    Flip card

    A service that makes it easy to deploy, scale, and manage virtual appliances such as firewalls, intrusion detection systems, and deep packet inspection systems.

    • Acts as a transparent network gateway.
    • Routes traffic to a fleet of virtual appliances.
    • Ensures all traffic passes through appliances for inspection/processing.
    Study this card →
  • Route 53 Failover Routing Policy

    Flip card

    A Route 53 routing policy that allows you to route traffic to a primary resource when it's healthy, and to a secondary resource when the primary is unhealthy.

    • Requires Route 53 health checks
    • Supports active-passive failover configurations
    • Ideal for disaster recovery and high availability
    Study this card →
  • AWS Transit Gateway

    Flip card

    A network transit hub that you can use to interconnect your virtual private clouds (VPCs) and on-premises networks to a single gateway.

    • Supports transitive routing between connected VPCs.
    • Simplifies network architecture for many VPCs.
    • Acts as a central hub for network connectivity.
    Study this card →
  • EC2 Enhanced Networking

    Flip card

    A feature that provides significantly higher packet per second (PPS) performance, lower network jitter, and lower latency for EC2 instances.

    • Uses Elastic Network Adapter (ENA) or Intel 82599 Virtual Function (VF) interface.
    • Crucial for high-performance computing (HPC) and network-intensive applications.
    • Must be enabled on supported instance types.
    Study this card →
  • AWS VPC Endpoints

    Flip card

    A feature that enables you to privately connect your VPC to supported AWS services and VPC endpoint services powered by AWS PrivateLink.

    • Traffic stays within the Amazon network.
    • Eliminates need for Internet Gateway or NAT Gateway for service access.
    • Two types: Interface Endpoints (powered by PrivateLink) and Gateway Endpoints (for S3, DynamoDB).
    Study this card →
  • ALB Listener Authentication

    Flip card

    An Application Load Balancer feature that allows for direct authentication of users against an identity provider (IdP) before forwarding requests to backend targets.

    • Supports OIDC, Amazon Cognito, and SAML-based IdPs.
    • Can be configured as an action in listener rules.
    • Enables path-based authentication for different parts of an application.
    Study this card →
  • Amazon CloudFront

    Flip card

    A global content delivery network (CDN) service that securely delivers data, videos, applications, and APIs to customers globally with low latency.

    • Caches content at edge locations for improved performance.
    • Supports HTTPS for secure content delivery.
    • Integrates with S3 for static website hosting.
    Study this card →
  • Transit Gateway Peering

    Flip card

    Transit Gateway peering allows you to connect two Transit Gateways across different AWS Regions, enabling private communication between their attached VPCs and on-premises networks.

    • Connects Transit Gateways across regions.
    • Enables private, low-latency cross-region traffic.
    • Extends the Transit Gateway network globally.
    Study this card →
  • Application Load Balancer (ALB)

    Flip card

    An Application Load Balancer (ALB) distributes incoming application traffic across multiple targets, such as EC2 instances, in multiple Availability Zones.

    • Operates at Layer 7 (HTTP/HTTPS).
    • Supports path-based, host-based, and query string-based routing.
    • Provides high availability and scalability.
    Study this card →
  • Public-facing Web Architecture

    Flip card

    A common AWS architecture for hosting web applications that are accessible from the internet, ensuring high availability, scalability, and security.

    • Uses Internet Gateway for internet connectivity.
    • Employs Load Balancers (ALB for HTTP/HTTPS) for traffic distribution.
    • Security Groups protect instances at the network interface level.
    Study this card →
  • CloudFront Origin Access Control (OAC)

    Flip card

    A CloudFront feature that enables you to restrict access to your Amazon S3 bucket origins, allowing only CloudFront to retrieve content from the bucket.

    • Replaces the older Origin Access Identity (OAI).
    • Ensures S3 content is only accessible via CloudFront URLs.
    • Protects S3 buckets from direct public access while allowing CloudFront to serve content.
    Study this card →
  • Route 53 ALIAS Record

    Flip card

    A Route 53-specific record type that provides a CNAME-like functionality for apex domains (root domains) to AWS resources, such as CloudFront distributions, without the limitations of CNAMEs.

    • Can be used for apex domains (e.g., example.com).
    • Points to specific AWS resources (CloudFront, ELB, S3 bucket).
    • No extra DNS query charges for ALIAS queries.
    Study this card →
  • Route 53 Routing Policies

    Flip card

    Different strategies used by Amazon Route 53 to determine how DNS queries are responded to, enabling various traffic management capabilities.

    • Simple: Default, basic DNS.
    • Latency: Routes to region with lowest latency.
    • Failover: Routes to primary, falls back to secondary on failure.
    Study this card →
  • Route 53 Geolocation & Failover Routing

    Flip card

    Geolocation routing directs traffic based on user location, while Failover routing redirects traffic to a secondary resource if the primary becomes unhealthy, often used together for regional resilience.

    • Geolocation: Directs users to nearest endpoint.
    • Failover: Redirects if primary is unhealthy.
    • Combine for location-aware, resilient applications.
    Study this card →
  • AWS Network Troubleshooting Flow

    Flip card

    A systematic approach to diagnose and resolve network connectivity issues within an AWS environment, often starting with the most common points of failure.

    • Verify network path components (Direct Connect, VPN, VPC, Subnets).
    • Check routing tables for correct pathing.
    • Inspect Security Groups and NACLs for traffic filtering.
    Study this card →
  • Network Load Balancer (NLB)

    Flip card

    A Network Load Balancer (NLB) operates at Layer 4 (TCP/UDP) and is optimized for extreme performance, high throughput, and ultra-low latency, making it suitable for demanding network traffic distribution.

    • Supports TCP and UDP protocols.
    • Handles millions of requests per second.
    • Provides static IP addresses per Availability Zone.
    Study this card →
  • AWS Hybrid Cloud Connectivity

    Flip card

    Services that enable connecting on-premises data centers to the AWS cloud, facilitating hybrid cloud architectures.

    • AWS Site-to-Site VPN uses the public internet, encrypted.
    • AWS Direct Connect provides a dedicated private connection.
    • Choice depends on performance, reliability, and security needs.
    Study this card →
  • AWS Direct Connect

    Flip card

    AWS Direct Connect creates a dedicated network connection from your premises to AWS, bypassing the public internet to offer consistent performance, reduced costs, and enhanced security.

    • Dedicated, private connection.
    • Consistent network performance and lower latency.
    • Ideal for large data transfers and hybrid environments.
    Study this card →
  • VPC Endpoint for Systems Manager

    Flip card

    A VPC Endpoint allows EC2 instances in private subnets to securely communicate with AWS Systems Manager without requiring an internet gateway, NAT device, or public IP addresses.

    • Enables private connectivity to AWS services.
    • Bypasses the public internet for enhanced security.
    • Supports Systems Manager for instance management.
    Study this card →
  • EC2 Enhanced Networking (ENA)

    Flip card

    A feature that uses single root I/O virtualization (SR-IOV) to provide high-performance networking capabilities on supported EC2 instance types.

    • Significantly higher packet per second (PPS) performance
    • Lower network latency
    • Lower network jitter
    Study this card →
  • CodePipeline CodeCommit Integration

    Flip card

    AWS CodePipeline automatically detects changes in an AWS CodeCommit repository when configured as a source stage, triggering pipeline executions without extra manual steps.

    • Uses CloudWatch Events rules internally.
    • Supports specific branches or all branches.
    • Simplifies CI/CD setup for CodeCommit users.
    Study this card →
  • AWS Serverless Application Model (SAM)

    Flip card

    AWS SAM is a framework that extends AWS CloudFormation to provide a simplified way of defining serverless applications, bundling multiple components (Lambda, API Gateway, DynamoDB, etc.) into a single deployable unit.

    • Uses a simplified YAML/JSON template syntax.
    • Builds upon CloudFormation, transpiles to CloudFormation.
    • Includes SAM CLI for local development and testing.
    Study this card →
  • S3 Object Lock Compliance Mode

    Flip card

    S3 Object Lock in Compliance mode provides the highest level of data immutability, preventing objects from being overwritten or deleted by any user, including the root user, for a specified retention period.

    • WORM protection for S3 objects.
    • Prevents deletion/modification by all users, including root.
    • Essential for strict regulatory compliance.
    Study this card →

Questions are original practice items written to match the published exam objectives. Step2Study is not affiliated with or endorsed by any certification body.