certslothcertsloth
← ANS-C01 overview

Advanced Networking Specialty / STUDY TOOLS

ANS-C01 quick review

Reviewed 10 October 2026 · Advanced Networking Specialty

Memory hook: Resolve the name; trace both routes; preserve state; prove the failure path.

Design 30%; implementation 26%; operations 20%; security and governance 24%.

Use this as a final revision pass after the chapters. Each task below maps to the published exam outline; the outline itself is not an exhaustive list of possible questions. Recheck the official guide for your booked exam version, especially beta releases.

Must remember by exam objective

1.1 — Design a solution that incorporates edge network services to optimize user performance and traffic management for global architectures

  • CloudFront caches HTTP content and separates cache policy from origin-request forwarding; Global Accelerator routes eligible TCP/UDP through static anycast entry points. Route 53 returns cached DNS answers. Select by protocol, global IP, caching, failover, origin security and latency requirements.

1.2 — Design DNS solutions that meet public, private, and hybrid requirements

  • Separate recursive resolution, authoritative zones and parent NS delegation. A/AAAA carry addresses, CNAME aliases names subject to apex restrictions, Route 53 Alias supports selected targets/apex use, and PTR supports reverse lookup. Private-zone association and Resolver context determine private answers; TTL and negative caching affect change visibility.

1.3 — Design solutions that integrate load balancing to meet high availability, scalability, and security requirements

  • ALB selects HTTP requests by content/host/path; NLB handles transport connections/static addressing patterns; GWLB distributes appliance traffic with GENEVE. Decide internal/public placement, target type, cross-zone behavior, health checks, source-IP/proxy metadata, stickiness and deregistration. TLS termination differs from passthrough; SNI selects certificates for hostnames.

1.4 — Define logging and monitoring requirements across AWS and hybrid networks

  • Choose Flow Logs for flow metadata, Traffic Mirroring for supported packets, load-balancer/CloudFront logs for request evidence, Resolver logs for queries and CloudWatch for metrics. Reachability Analyzer evaluates supported configuration paths. Establish baseline throughput, latency, loss and connection counts before diagnosing deviations.

1.5 — Design a routing strategy and connectivity architecture between on-premises networks and the AWS Cloud

  • Direct Connect needs physical connection, VLAN/VIF and BGP; public VIFs reach AWS public services, private VIFs reach supported private paths and transit VIFs connect through DX gateway to TGW. VPN supplies encrypted tunnels. Diversify devices/circuits/locations; SD-WAN/TGW Connect uses supported GRE/BGP integration.

1.6 — Design a routing strategy and connectivity architecture that include multiple AWS accounts, AWS Regions, and VPCs to support different connectivity patterns

  • Peering is direct and nontransitive; TGW routes among attachments; PrivateLink exposes a service rather than broad networks; RAM shares supported resources/subnets. Plan CIDRs, IPv6, DNS and account ownership. Overlap needs renumbering or a suitable translated/service-access design, not merely another route.

2.1 — Implement routing and connectivity between on-premises networks and the AWS Cloud

  • Validate link optics/LOA/cross-connect, VLAN, addressing, ASN, BGP session, advertised/accepted prefixes, filters and return preference separately. Use both VPN tunnels and verify backup capacity. DNS and firewall routes must work over the chosen hybrid path; physical link-up alone proves little.

2.2 — Implement routing and connectivity across multiple AWS accounts, Regions, and VPCs to support different connectivity patterns

  • TGW association selects the table used by traffic entering from an attachment; propagation adds routes into selected tables. Subnet routes still need the attachment path. Segment environments and preserve stateful inspection symmetry using appropriate appliance mode/endpoints. Peering and TGW peering have different propagation rules.

2.3 — Implement complex hybrid and multi-account DNS architectures

  • Inbound Resolver endpoints receive external queries into VPC resolver context; outbound endpoints/rules forward selected queries outward. Share/associate rules and zones deliberately, with resilient endpoints and TCP/UDP DNS access. Most-specific rules, forwarding loops, split-horizon names and DNSSEC chain/validation are common failure clues.

2.4 — Automate and configure network infrastructure

  • Use reviewed IaC with parameterized CIDRs, IDs, accounts and Regions; avoid brittle hard-coded values. IPAM and ownership conventions support controlled allocation. Stage route/security changes, validate expected reachability and preserve rollback. Event-driven repairs need idempotency and bounded scope.

3.1 — Maintain routing and connectivity on AWS and hybrid networks

  • Longest-prefix match comes before protocol/path preferences in the relevant routing system. BGP policy influences each direction independently; route summarization can hide failure or create black holes. Check quotas, propagation, accepted prefixes, MTU and DNS after changes. A DX gateway is not general-purpose transitive routing.

3.2 — Monitor and analyze network traffic to troubleshoot and optimize connectivity patterns

  • Troubleshoot by layer: DNS, address family, route, SG/NACL, stateful device, listener and TLS. Flow Logs do not contain payload; packet captures and application logs provide different evidence. Small-packet success with large-packet failure suggests MTU/MSS/path-MTU discovery; preserve required control traffic.

3.3 — Optimize AWS networks for performance, reliability, and cost-effectiveness

  • Compare complete costs: ports, NAT/endpoint hours, processing, cross-AZ/Region transfer and appliance capacity. Parallel paths do not necessarily aggregate one flow. Design resilience across actual failure domains, tune cache/connection use, and test failover with realistic traffic and quotas.

4.1 — Implement and maintain network features to meet security and compliance needs and requirements

  • Use SG stateful allows, NACL stateless allows/denies, endpoint policies, Network Firewall, DNS Firewall, WAF and Shield according to layer and requirement. Central inspection must have no bypass route and symmetric flows. IPv4 rules do not automatically protect IPv6; use egress-only IGW for suitable IPv6 outbound paths.

4.2 — Validate and audit security by using network monitoring and logging services

  • Centralize necessary flow/query/access/API evidence with restricted retention and key access. CloudTrail records control activity; Config detects supported configuration deviation. Validate the monitoring delivery path, alert routing and network policy after changes; a silent dashboard may mean missing telemetry.

4.3 — Implement and maintain confidentiality of data and communications of the network

  • Direct Connect is not inherently encrypted. IPsec protects tunnels, supported MACsec protects an eligible link segment, TLS protects application sessions and DNSSEC authenticates signed DNS data. ACM certificate placement, chain/hostname validation and private-key protection matter; encryption does not grant authorization.

Choose under exam pressure

Deciding clue Recall the distinction
One private service across overlapping networks PrivateLink where supported; not broad transitive routing.
On-premises must resolve a private zone Inbound Resolver, correct zone association and network return path.
VPC resolves corporate suffix Outbound Resolver rule/endpoints with reachable corporate resolvers.
Stateful appliance receives only one flow direction Inspect association, subnet routes, symmetry and appliance-mode design.
Static global IPs for TCP/UDP Global Accelerator; cacheable HTTP content instead points to CloudFront.

Traps

  • DNSSEC does not encrypt queries.
  • An AS-path preference cannot beat a more-specific route.
  • A LAG in one location is not geographic resilience.
  • An allowed endpoint policy is not a replacement for identity/resource permission.
  • Network connection sharing does not automatically share DNS zones.

Verification cues

  • Use dig against the workload’s resolver to inspect status, answer, authority and TTL; trace public delegation only where relevant.
  • For an unreachable destination, write every forward/return route and the table used at each hop.
  • Explain BGP session state, advertised prefixes and each direction’s selected route before changing preference.
  • Read load-balancer target-health reasons, Flow Log accept/reject metadata and TLS hostname/chain errors; keep application response tests separate from configuration analysis.

Last-pass active recall

1. What does a TGW association select?

The TGW route table used for traffic arriving from that attachment.

2. Can a public DX VIF provide ordinary internet transit?

No. It reaches supported AWS public service prefixes under its routing policy.

3. What happens if a matching private zone lacks the requested name?

It can return a negative answer rather than falling back to the public zone.

4. Why do NACLs often need ephemeral return ports?

They are stateless and evaluate return packets independently.

5. Does a healthy firewall prove all traffic is inspected?

No. Routes may bypass it or return through a different stateful context.

Sources and version check

The numbered chapters provide worked distinctions and further technical sources. These are original revision notes and original recall scenarios, not real exam questions.

Every topic at a glance

Open any topic to revisit its essential facts, decisions and exam traps. Use the full topic for active recall and supporting references.

01 · Networking: VPC

Memory hook: A working connection needs the right address, a forward route, permission and a return path.

Must remember

Addresses and routes come first

  • A VPC is a regional network boundary; a subnet occupies one AZ. Plan nonoverlapping CIDRs before connecting VPCs and on-premises networks. AWS reserves five IPv4 addresses in an ordinary subnet, so a /24 supplies 251 usable IPv4 addresses. Default-VPC conveniences should not be assumed in a custom VPC.
  • A route table selects the most specific matching destination route. A subnet is called public when it has an internet-gateway route, but an IPv4 instance also needs usable public addressing and suitable security rules. A public IP without the route, or the route without the public IP, is insufficient.
  • An internet gateway (IGW) supports the VPC's internet path. A bastion is a deliberate administrative hop; Session Manager can avoid inbound SSH by using the managed agent's outbound service connectivity and IAM permissions.
  • Private addressing does not itself guarantee isolation from every network. Check all routes: peering, transit, VPN and service endpoints may create intentional private connectivity.

Stateful and stateless filters

  • Security groups use stateful allow rules on interfaces/resources. Return traffic for an allowed connection is tracked; there is no explicit SG deny rule. Referencing another SG is useful for tier-to-tier access without maintaining individual IP lists.
  • NACLs apply ordered stateless allow/deny rules at subnet boundaries. Both directions need appropriate rules; HTTPS responses often need outbound ephemeral ports. Lower-numbered matching rules determine the decision, so an earlier deny can defeat a later allow.
  • A permitted filter cannot compensate for a missing route, and a correct route cannot override a denying filter. Trace the actual source/destination seen at each network hop.

Egress and service endpoints

  • NAT instances require operating-system management, routing, security rules and appropriate source/destination-check changes. NAT gateways reduce appliance management; time, processing and associated address charges still matter. NAT permits outbound-initiated connectivity, not unsolicited inbound sessions.
  • The traditional zonal public NAT gateway sits in a public subnet; same-AZ routing with one per required AZ avoids a single-AZ egress dependency. Current AWS also offers regional NAT gateways, which can automatically expand across AZs and do not require a hosting public subnet. Know which mode a question describes; regional mode currently does not provide private NAT. A single regional resource is not a promise of one-AZ pricing.
  • Gateway endpoints for S3 and DynamoDB add route-table targets without an endpoint-hour fee. They are not general transit access for clients in peered VPCs or on-premises networks.
  • Interface endpoints and AWS PrivateLink provide private access to supported services through endpoint networking and DNS, typically using private ENIs and SGs for interface endpoints. They can expose a particular service instead of granting full VPC-to-VPC routing. Hourly/per-AZ and data charges require comparison against the actual traffic pattern.
  • Endpoint policies, where supported, limit use through that endpoint. They do not override missing IAM permissions or a denying bucket/resource policy. Network reachability and API authorization are separate checks.

Connect networks and resolve names

  • VPC peering connects compatible nonoverlapping networks with explicit routes; it is not transitive. A–B and B–C do not establish an A–C path through B. Transit Gateway supplies a routed hub for many VPCs and on-premises connections; attachment and route-table configuration still control permitted paths.
  • Site-to-Site VPN connects networks using encrypted tunnels over IP connectivity. VPN CloudHub supports compatible hub-and-spoke VPN site communication. Client VPN supplies remote-user access, with authentication, authorization and routes; it is not the same workload as linking two corporate networks.
  • Direct Connect provides dedicated connectivity and more predictable network characteristics, with physical provisioning considerations. It is not encrypted by default. Use appropriate application TLS, supported MACsec or VPN designs when encryption is required. Direct Connect Gateway connects eligible virtual-interface designs to multiple VPCs/Regions; it is not an automatic transitive VPC router.
  • Route 53 Resolver inbound endpoints let external networks query supported AWS DNS namespaces. Outbound endpoints and forwarding rules send matching VPC queries toward external DNS. Direction follows the query, and DNS resolution still needs underlying network reachability. See DNS notes.

IPv6, observation and cost

  • Amazon-provided public IPv6 addresses are globally routable; routing and filters control reachability. An egress-only IGW permits outbound-initiated internet flows for public IPv6 addresses. Reaching IPv4-only destinations from IPv6 is a separate translation requirement.
  • AWS also supports private IPv6 through IPAM, including ULA and private GUA ranges. IGWs and egress-only IGWs drop these private ranges; internet access requires a suitable intermediary with public addressing. “Outbound-only” and “private IPv6 address” are different properties.
  • Flow logs summarize supported IP flows, including accepted/rejected traffic, rather than packet payloads. Delivering to S3 and querying with Athena supports analysis. Traffic mirroring copies supported packet traffic for inspection; Network Firewall provides managed network filtering/inspection. WAF specializes in supported HTTP request paths.
  • Add the whole path's cost: public IPv4, NAT processing, cross-AZ/Region transfer, endpoints, load balancers and inspection. Service quotas, subnet address capacity and standby-region limits can prevent scale-out even when an architecture diagram looks sound.

Choose under exam pressure

Clue in the requirement Choose or investigate
Private VPC workloads only need same-Region S3 Gateway endpoint and suitable policies
Expose one supported private service to another account PrivateLink rather than broad routed connectivity
Many VPCs need transitive routing Transit Gateway
Remote employees need authenticated private access Client VPN
On-premises DNS must query private AWS names Resolver inbound endpoint plus connectivity
VPC clients need corporate DNS zones Resolver outbound endpoint and rules
Outbound-only internet access using public IPv6 addresses Egress-only IGW
Inspect actual packet content Suitable mirroring/inspection design

Traps

  • A subnet name, SG rule or public IP alone does not establish a complete path.
  • A gateway endpoint is not a replacement for all interface endpoints or for hybrid connectivity.
  • Older “all NAT gateways are zonal” shorthand is incomplete. Preserve the availability mode and routing assumptions in the question.

Practise this topic

02 · Route 53

Memory hook: DNS chooses an answer that clients may cache; it does not inspect or balance every application request.

Must remember

Resolution, records and ownership

  • A recursive resolver finds an answer on a client's behalf, following cached information and authoritative DNS as needed. An authoritative hosted zone contains the records for its namespace.
  • A maps a name to IPv4; AAAA to IPv6; CNAME to another hostname; NS identifies authoritative name servers; MX identifies mail servers; TXT carries text/verification data; SOA carries zone metadata.
  • TTL controls how long a DNS answer may be cached. Lower TTL can improve the responsiveness of future changes but increases queries and cannot instantly invalidate previously cached answers.
  • Domain registration and DNS hosting are separate services. A third-party registrar can delegate a domain to Route 53 by using the correct Route 53 name servers. Moving DNS does not necessarily require transferring registration.
  • Creating a same-named public hosted zone does not configure delegation; resolvers need the correct authoritative chain.
  • A CNAME cannot occupy a zone apex alongside its required SOA/NS records. Route 53 Alias A/AAAA can map an apex to supported targets such as an ALB or CloudFront distribution.
  • Alias is an AWS DNS feature with supported target rules, not permission to point any apex record at an arbitrary hostname. Its TTL/health behavior depends on the target.

Every routing policy answers a different question

Requirement or clue Routing policy and meaning
Ordinary answer for one service Simple: basic response without specialized selection
Gradual rollout or relative distribution Weighted: choose among records according to relative weights
Best response latency among configured Regions Latency: use measured latency information, not just map distance
Primary/standby DNS recovery Failover: prefer healthy primary, otherwise secondary
Country/continent or location-specific content Geolocation: select by user location; define a default
Shift a geographic catchment boundary Geoproximity: resource/user location with adjustable bias
Known client-source CIDR requirements IP-based: use CIDR collections to choose destinations
Several healthy IP answers Multivalue: return a small set of healthy answers; not a full load balancer
  • Weights are relative, not required to total 100. Resolver caching and client reuse mean a 90/10 policy does not guarantee nine of each ten HTTP requests use one endpoint.
  • Latency and geography differ: the geographically nearest endpoint need not have the lowest measured network latency.
  • Geolocation is not authorization or residency enforcement; storage locations, cache distribution and access controls need separate policies.
  • Geoproximity bias changes the area attracted to a resource; it is not the same as changing an exact percentage weight.
  • Traffic Flow can compose visual traffic policies, with separate pricing/management considerations. It is a configuration facility rather than another universal per-request proxy.

Health and failover

  • An endpoint health check probes a supported publicly reachable endpoint using its configured protocol and conditions.
  • A calculated health check combines child checks using a threshold; a CloudWatch alarm-based health check derives health from supported alarm/metric behavior instead of a direct public probe.
  • Route 53 public health checkers cannot directly reach an ordinary private-only IP. A suitable metric/alarm integration is one way to express private resource health.
  • Health checks are separate resources and must be correctly associated with the DNS design. Supported Alias targets may provide Evaluate Target Health behavior instead of needing a duplicate direct endpoint probe.
  • Failover depends on detection time, DNS answers, resolver caches and application reconnection. A small TTL is not a promise that all clients switch instantly.
  • Secondary endpoints still need usable capacity and sufficiently current data; health checks preserve neither transactions nor state.

Private zones and hybrid DNS

  • Private hosted zones answer within associated VPCs through the appropriate resolver context. Required VPC DNS attributes, associations and application resolver configuration must be correct.
  • Split-view DNS uses the same namespace with different internal and external answers. A private zone can intentionally shadow public names.
  • If an associated matching private zone lacks the requested name/type, resolution can return NXDOMAIN, rather than automatically falling back to the public zone.
  • Route 53 VPC Resolver is the current name for the VPC service historically called Route 53 Resolver. Its inbound endpoints receive queries from on-premises/other connected networks.
  • Outbound endpoints and forwarding rules send matching VPC queries to external DNS servers. Think “inbound to the VPC” and “outbound from the VPC.”
  • Endpoints do not create the underlying VPN/Direct Connect route. DNS ports, security groups, routes, forwarding rules and resilient endpoint placement are separate requirements.
  • Private zones do not support every public-zone routing policy.

Choose under exam pressure

Situation Decision and reason
Apex domain must reach an eligible AWS load balancer Alias A/AAAA, not apex CNAME
Keep registrar but use Route 53 DNS Update authoritative delegation
Hybrid clients must resolve AWS private names Inbound Resolver endpoint and private connectivity
VPC clients must resolve corporate names Outbound endpoint with matching forwarding rules
Internal name exists publicly but fails inside VPC Inspect private-zone shadowing and record/type
Exact request-level canary split required DNS weighting alone cannot guarantee it
Private backend needs failover health Appropriate alarm/metric-based health integration

Traps

  • Resolution is not connectivity. A correct address does not open a firewall or establish a route.
  • Caching limits immediate control. DNS updates do not terminate established connections or flush every resolver.
  • Private and public evidence differ. A laptop using public DNS cannot prove a VPC-only record is absent.

Practise this topic

03 · CloudFront and Global Accelerator

Memory hook: CloudFront caches HTTP content, Global Accelerator routes network connections, and replication creates durable regional copies.

Must remember

Match the origin and cache behavior to the application

  • CloudFront accepts viewer HTTP(S) requests at edge locations. A distribution can use different origins and cache behaviors for static assets and dynamic API paths.
  • S3 REST origin plus OAC: CloudFront signs origin requests, and a bucket policy permits the intended distribution. The bucket can remain private. For SSE-KMS objects, the key policy also needs appropriate access.
  • An S3 website endpoint is a custom origin, cannot use OAC, and does not provide origin HTTPS. Do not choose it when the requirement is private S3 access through signed origin requests. S3 origin restrictions
  • ALB/EC2 origins serve dynamic HTTP applications. CloudFront can pass requests through without caching user-specific responses; “CDN” does not mean static files only.
  • Current VPC origins support eligible private-subnet ALBs, NLBs and EC2 instances, subject to service/Region constraints. Do not memorize the outdated rule that every application origin must be public. Public custom origins still need protection against bypassing the distribution. VPC origins

Keep caching separate from authorization

  • The cache key decides which requests can reuse a response. Include only relevant headers, cookies and query parameters: unnecessary variation lowers hit rate; missing user-specific variation can expose private content.
  • The origin request policy decides what reaches the backend. Forwarding a value and including it in the cache key are different decisions. Disable caching where that is the safest fit for personalized data.
  • TTL bounds freshness. Versioned object names make immutable assets easy to update without replacing the contents behind a cached URL. Invalidations remove cached paths earlier and may add cost.
  • Signed URLs suit individual restricted resources or clients that do not support cookies. Signed cookies suit access to multiple restricted files without rewriting each URL, such as a media presentation with many segments.
  • OAC authorizes CloudFront to S3; signed URLs/cookies authorize viewers to CloudFront. They solve different boundaries and may be used together. Signed access choices
  • Geo restriction controls viewer countries based on location signals. Price classes constrain the eligible edge footprint to trade price against reach. Neither determines the S3 bucket's storage Region or guarantees data residency.
  • TLS applies on both viewer and origin connections. For a CloudFront custom hostname using ACM, the viewer certificate is obtained in us-east-1; an ALB's certificate is regional to that ALB.

Distinguish routing, resilience and edge code

  • Global Accelerator provides static anycast IPs and routes TCP/UDP through AWS networking to supported healthy endpoints. Endpoint groups are regional; traffic dials and endpoint weights influence traffic distribution.
  • It does not cache S3 objects or replace application authorization. Its control API uses us-west-2, although application endpoints can be elsewhere. Global Accelerator overview
  • S3 CRR stores durable copies in another Region. CloudFront caches can expire or evict objects, so caching alone is not regional disaster recovery.
  • CloudFront Functions is for lightweight viewer request/response logic, such as URL or header changes. Lambda@Edge supports richer processing and origin events, with different limits and replicated-resource lifecycle behavior.
  • CloudFront changes/deletion need propagation. Lambda@Edge replicas can delay cleanup; avoid treating edge code as an ordinary instantly deleted regional function. See serverless services and S3 replication.

Choose under exam pressure

Requirement in the question Best direction
Millions of identical global HTTP downloads CloudFront caching
Private S3 origin with controlled viewer access OAC plus signed viewer access
Many restricted media segments Signed cookies
Static global IPs for TCP/UDP applications Global Accelerator
Durable regional recovery copy S3 CRR
Personalized API behind an ALB Appropriate cache policy or caching disabled
Simple viewer URL/header rewrite CloudFront Functions

Traps

  • A CDN cache is not a backup, and a replica is not an authorization mechanism.
  • Country filtering is not the same as choosing where original data is stored.
  • Allowing all CloudFront traffic to a public origin does not necessarily restrict access to your specific distribution.
  • A long TTL on a personalized response can be a security mistake, not just a freshness mistake.

Practise this topic

04 · ELB & Auto Scaling

Memory hook: A load balancer chooses a destination; an Auto Scaling group maintains capacity; application state must survive either decision.

Must remember

Pick the right traffic layer

  • Application Load Balancer (ALB) understands HTTP/HTTPS at layer 7. A listener receives traffic; ordered rules choose forward, redirect, authentication or fixed-response actions. Conditions can include host and path.
  • Target groups hold instances, IPs or supported Lambda destinations, with health checks/attributes. Path rules can select different groups.
  • Lower numbered listener priorities run first. A fixed response comes from the ALB and can succeed even when the application is unavailable.
  • Network Load Balancer (NLB) handles TCP/UDP/TLS at layer 4 and supplies static addresses per enabled AZ, with optional Elastic IPs for supported internet-facing deployments. It fits non-HTTP traffic and IP allowlist requirements.
  • NLB is not an HTTP path router. Modern NLBs support security groups in supported configurations; the old claim that NLBs never have security groups is unsafe.
  • Gateway Load Balancer (GWLB) steers traffic through network appliances using GENEVE/UDP 6081, rather than routing application URLs.
  • An internet-facing load balancer can forward to private backends; public users do not require public backend IPv4.

Connection behavior and health

  • Stickiness uses supported cookies/affinity mechanisms to favor a target. It does not replicate session memory or guarantee that target will survive.
  • Cross-zone load balancing allows a node to route across enabled AZs. ALB has it enabled at the load-balancer level, with target-group-level controls; NLB/GWLB default differently. Check transfer cost rules for the specific type.
  • Deregistration delay drains in-flight requests during removal. Too little can interrupt long work; excessive values can slow scale-in and deployments.
  • TLS termination uses listener certificates, often from ACM. SNI lets a compatible client indicate its hostname so a listener chooses the correct certificate. ALB certificates are regional; CloudFront ACM certificates use us-east-1.
  • Target health checks detect application reachability on the configured port/path. EC2 status health and application health answer different questions.
  • Health routing is not authorization: all-unhealthy/fail-open behavior can send traffic to unhealthy targets.

Scaling and replacement

  • Vertical scaling changes machine size and may require interruption; horizontal scaling changes the number of workers. Externalized state makes horizontal replacement safer.
  • AWS Auto Scaling plans coordinate resources. EC2 Auto Scaling manages instance groups; Application Auto Scaling handles supported dimensions such as ECS task counts. Plans can migrate to direct policies.
  • Launch templates describe AMIs, type, user data, interfaces and related launch settings. Updating a template does not automatically update every already-running instance.
  • An ASG maintains desired capacity between minimum and maximum bounds. Enable appropriate ELB health when application failures should cause replacement; EC2-only checks may miss a broken web process.
  • Instance refresh rolls out launch changes with health, warmup and capacity constraints.
  • Target tracking maintains a chosen metric target; step scaling changes capacity according to alarm severity; scheduled scaling anticipates known times; predictive scaling forecasts recurring demand.
  • Choose a demand-related metric: CPU can fit compute-bound servers, ALB request count per target can fit web workers, and queue backlog per worker can fit asynchronous processing.
  • Warmup/cooldown reduce unstable decisions during startup; grace periods do not prove readiness.
  • Multi-AZ subnets with desired capacity one do not provide two active replicas. Production resilience needs sufficient surviving capacity and dependencies.

Choose under exam pressure

Requirement Decision and reason
Several web apps under paths or hostnames ALB listener rules and target groups
Static addresses for TCP/UDP clients NLB
Third-party network inspection fleet GWLB
Scale before a known daily opening Scheduled scaling
Maintain utilization near a target Target tracking
Replace instances with a broken web process ASG using relevant ELB health
Roll out a new AMI to existing capacity Controlled instance refresh

Traps

  • Scaling and healing differ. Replacing an unhealthy instance can preserve the same desired capacity without adding demand capacity.
  • A cookie is not a session database. Target loss still destroys target-local state.
  • A successful listener test can bypass dependencies. Fixed responses do not prove backend, cache or database health.

Practise this topic

05 · Monitoring & Audit

Memory hook: Metrics show symptoms, logs explain events, traces follow requests, and audit records identify changes.

Must remember

Separate the evidence questions

  • CloudWatch: how is the workload behaving? Use metrics, logs, dashboards and alarms for operational evidence. CloudTrail: which identity called which API, against what resource and when? AWS Config: what resource configuration existed, and did an evaluated rule consider it compliant?
  • These sources complement each other. A slow API can require a latency alarm, application logs and a trace; identifying an administrator's change requires audit evidence. Check that the needed events, resources and retention were actually configured before promising historical answers.
  • AWS X-Ray follows instrumented requests across services and downstream calls. Its trace map helps find latency, errors and bottlenecks. Traces are not a replacement for every application log or API audit event; instrumentation and sampling affect visibility.

Metrics and logs

  • A metric is a numeric time series identified by namespace, name and dimensions. Choose meaningful statistics and evaluation periods: average latency can conceal slow tail requests, while a total error count without request volume may mislead.
  • Alarms evaluate metric conditions; actions notify or invoke supported responses. Composite alarms combine alarm states to reduce noisy paging. Treat missing data intentionally rather than assuming missing means healthy. Metric streams continuously deliver selected metric updates to downstream consumers.
  • Logs Insights queries log events. Metric filters count matching events into metrics. Subscriptions forward matching logs to supported destinations; export writes log data to S3 for a different processing workflow. These are distinct mechanisms.
  • The CloudWatch agent collects additional guest-OS and application signals. Standard EC2 metrics do not automatically reveal every filesystem or memory measurement.
  • Container Insights and Lambda Insights add workload-specific visibility; Contributor Insights identifies prominent contributors; Application Insights helps correlate application problems. Their scope and collection costs need deliberate configuration.

Events, audit and compliance

  • EventBridge rules match events on buses and deliver them to targets. Scheduler invokes targets on time-based schedules. An archive retains selected events for replay; a replay can repeat a business action, so consumers still need idempotency.
  • A successfully accepted event can fail to match a rule or fail later delivery. Check source/detail pattern, bus, target configuration, resource permissions and retry/dead-letter behavior separately.
  • CloudTrail management events describe control-plane activity; selected data events provide supported resource-level activity. CloudTrail Insights detects unusual supported API activity. A rule reacting to an API call via EventBridge needs the appropriate event path and coverage.
  • Config recording tracks selected resource configurations; rules evaluate compliance. Notifications and remediation are separately configured. A remediation role can mutate resources, so evaluation should not be confused with automatic repair.

Additional published-scope tools

  • Amazon Managed Service for Prometheus stores and queries compatible operational metrics, especially for container workloads using PromQL. Amazon Managed Grafana visualizes metrics, logs and traces from multiple sources. The dashboard layer is different from the metric storage/query layer.
  • AWS Health Dashboard reports AWS service events and account-relevant impacts. Combine it with workload telemetry: a healthy AWS status does not prove your application or configuration is healthy.
  • Keep logs and traces useful: redact sensitive data, set retention, scope collection and correlate request identifiers. Broad logging can create both sensitive-data exposure and substantial ingestion charges.

Choose under exam pressure

Clue in the requirement Choose or investigate
Alert on errors or latency CloudWatch metric alarm with an action
Determine who deleted a database CloudTrail audit events
Review a resource's historical configuration compliance Config history and rule evaluations
Find the slow downstream call in a distributed request X-Ray tracing
Query container metrics using PromQL Managed Service for Prometheus
Visualize several telemetry sources together Managed Grafana
Trigger work for matching application events EventBridge rule and target
Investigate a relevant AWS service disruption AWS Health Dashboard

Traps

  • An alarm with no action is not an email subscription; rule creation alone does not establish every permission needed for delivery.
  • A trace sample or a log metric is not a complete security audit record.
  • A Config rule can report a problem without correcting it. Replaying an event can repeat side effects rather than merely replaying a picture of history.

Practise this topic

06 · Hybrid Routing, BGP and Direct Connect

Memory hook: Longest prefix first; then compare the preference rules of the actual routing system.

Must remember

  • Calculate CIDR ranges before designing connectivity. A /24 contains 256 IPv4 addresses; AWS reserves addresses in ordinary VPC subnets, so total addresses are not all usable. Overlapping networks cannot simply be joined with peering or Transit Gateway routing; renumber or use an explicitly supported translation/service-access design.
  • Direct Connect supplies connectivity through virtual interfaces: public VIFs reach AWS public services; private VIFs support private connectivity through compatible virtual gateways/Direct Connect gateways; transit VIFs connect through Direct Connect gateway to Transit Gateway. A DX gateway is not a general-purpose VPC router.
  • A VLAN identifies the Layer 2 virtual interface; BGP exchanges routes. Verify link/VLAN, peer addresses, ASN, BGP status, advertisements and accepted-prefix limits separately. A working physical link does not prove useful prefixes are exchanged.
  • For private/transit VIF return routing, AWS evaluates prefix specificity before local preference, then AS-path and later tie-breakers. Supported local-preference communities include 7224:7100 low, 7224:7200 medium and 7224:7300 high. These influence AWS-to-on-premises traffic; your routers independently control the opposite direction. Public VIF policy and community semantics differ.
  • Site-to-Site VPN uses IPsec tunnels and supports static or dynamic routing according to configuration. Use both tunnels and test failure. Transit Gateway can support eligible ECMP VPN paths; a single flow does not necessarily receive the aggregate bandwidth of all paths.
  • Direct Connect is not inherently encrypted. Evaluate IPsec over the appropriate connectivity or supported MACsec when its scope meets the requirement. MACsec protects an eligible link segment; application TLS protects the application connection.
  • Redundancy must remove shared device, circuit and location failure domains. LAG aggregates eligible connections but is not a substitute for separate locations. BFD and routing convergence affect failure detection; application recovery depends on more than a BGP timer.

Choose under exam pressure

Requirement Choice and reason
Primary and backup equal-prefix DX paths Use supported preference policy and verify both traffic directions.
Regional hub routing from hybrid networks Transit VIF, DX gateway and Transit Gateway as supported.
A dedicated connection must also encrypt traffic Add an appropriate encryption mechanism.

Traps

  • AS-path manipulation cannot defeat a more-specific route.
  • A public VIF is not general transit to every internet destination.
  • Redundant cables in one failure domain are not geographic resilience.

Practise this topic

07 · Hybrid DNS and Resolver Design

Memory hook: Inbound lets external clients ask AWS; outbound lets AWS forward selected questions elsewhere.

Must remember

  • A recursive resolver obtains answers for clients; authoritative servers host zone records. Public delegation uses NS records at the parent. Private hosted-zone answers depend on VPC association and resolver context. A DNS name can have different public and private answers.
  • Route 53 Resolver inbound endpoints accept queries from reachable external networks for the associated resolver context. Outbound endpoints send queries matching forwarding rules to configured target resolvers. Associate/share rules deliberately across VPCs; a network attachment does not automatically share DNS zones.
  • Use multiple endpoint IPs across AZs for availability and allow required UDP/TCP DNS traffic. TCP is needed for cases such as large/truncated responses. Hybrid routing, security groups and return paths are required in addition to DNS configuration.
  • Match the most-specific relevant domain/rule. Avoid forwarding loops such as AWS forwarding a zone on-premises while the on-premises server forwards the same unresolved name back. Split-horizon DNS needs clear ownership and deliberate public/private records.
  • A private zone that matches a queried namespace but lacks the record may return a negative answer rather than falling back to an unrelated public answer. Negative caching and TTL can prolong an apparent failure after a fix. Test from the same network and resolver context as the application.
  • Resolver DNS Firewall filters supported resolver queries. Query logs help identify resolution behaviour; DNSSEC validation verifies supported signed answers, not confidentiality. Encryption in transit and DNS answer authenticity are different requirements.
  • Use dig/nslookup to inspect record type, answer, authority, TTL and status. Trace public delegation where relevant; query the intended resolver directly when diagnosing split DNS. A cached success from your laptop is not proof a workload VPC resolves identically.

Choose under exam pressure

Requirement Choice and reason
On-premises clients resolve AWS private names Inbound Resolver endpoints plus private-zone association and network access.
VPC workloads resolve a corporate suffix Outbound endpoints and a forwarding rule.
Repeated NXDOMAIN after adding a record Inspect negative caching and the queried resolver/zone.

Traps

  • Transit Gateway connectivity alone does not share private hosted zones.
  • DNSSEC does not encrypt DNS traffic.
  • An Alias and a CNAME have different allowed targets and apex behaviour.

Practise this topic

08 · Transit, Inspection and Network Diagnostics

Memory hook: Every stateful flow needs a coherent forward and return path through the same inspection context.

Must remember

  • A Transit Gateway attachment associates with a route table used for traffic arriving from it; propagation supplies learned routes into selected tables. Separate tables can isolate environments while exposing shared services. VPC subnet route tables must also point to the correct attachment path.
  • Place attachment subnets in the AZs that need connectivity. Overlapping VPC prefixes are not solved by propagation. Peering does not provide unrestricted transitive routing; distinguish VPC peering, TGW peering and supported route propagation behaviour.
  • Centralised stateful inspection needs symmetric routing and appropriate appliance behaviour. TGW appliance mode helps preserve an appliance-AZ flow path on supported VPC attachments. GWLB distributes traffic to virtual appliances using GENEVE; Network Firewall provides managed network inspection. A bypass route can invalidate the security design even if the firewall itself is healthy.
  • PrivateLink exposes a supported service through endpoints without broad network connectivity. Interface endpoints use ENIs, DNS and security groups; gateway endpoints route supported S3/DynamoDB traffic differently. Endpoint policies add controls but do not create missing identity/resource grants.
  • IPv6 needs its own routes and controls. An egress-only internet gateway allows outbound IPv6 internet connectivity with responses; it is not IPv4 NAT. NAT64/DNS64 address specific IPv6-to-IPv4 access patterns. Check dual-stack service support and avoid assuming an IPv4 firewall rule protects IPv6.
  • Use Flow Logs for connection metadata, Traffic Mirroring for supported packet inspection, Reachability Analyzer for configuration paths and CloudWatch for metrics. Monitor drops, throughput, connection counts and DNS errors. MTU, MSS and path-MTU discovery explain failures where small packets work but larger ones stall.
  • Automate network changes through reviewed IaC, staged rollout and rollback; track IP space with IPAM, quotas and ownership. Compare NAT, endpoints, TGW processing, cross-AZ transfer and cross-Region transfer over the expected traffic volume. Lowest hourly infrastructure cost may not minimise total transfer cost.

Choose under exam pressure

Requirement Choice and reason
Isolate production and test attached to one TGW Separate association/propagation designs with only required routes.
Expose one service without joining whole networks PrivateLink when supported.
Stateful firewall sees only one direction Inspect symmetry, route tables and appliance-mode design.

Traps

  • A route existing in TGW does not create the VPC subnet route.
  • A firewall can be bypassed by a more-specific route.
  • Packet capture and flow metadata provide different evidence.

Practise this topic

Search across every published topic.