---
tags:
- cloud
- l1
- flashcard-deck
- aws-networking
---
<!-- wiki:breadcrumb:start -->
[Portal](../../../../library/portal/index.md) | **Level:** [L1: Foundations](../../../../library/portal/levels.md) | **Topics:** [AWS Networking](../../../../library/portal/topics.md) | **Domain:** Cloud
<!-- wiki:breadcrumb:end -->

id	category	difficulty	tags	question	answer	source_path
aws-networking/0562ac7b9e5f	aws-networking	medium	aws, elb	"Explain ""health checks"" in the context of AWS ELB"	Health checks used by ELB to check whether EC2 instance(s) are properly working. \nIf health checks fail, ELB knows to not forward traffic to that specific EC2 instance where the health checks failed.\n\nRemember: ELB health checks: interval (how often), threshold (consecutive successes/failures), timeout (how long to wait). Unhealthy targets are removed from rotation until they recover.	projects/knowledge/interview/aws/181-explain-health-checks-in-the-context-of-aws-elb.txt
aws-networking/0fcc75823553	aws-networking	medium	aws, elb	True or False? AWS ELB health checks are done on a port and a route	True.\n\nFor example, port `2017` and endpoint `/health`.\n\nRemember: ELB health checks: interval (how often), threshold (consecutive successes/failures), timeout (how long to wait). Unhealthy targets are removed from rotation until they recover.	projects/knowledge/interview/aws/182-true-or-false-aws-elb-health-checks-are-done-on-a-.txt
aws-networking/10324e876851	aws-networking	medium	aws, nacl, security-group, subnet	Explain the significance of Security Groups and NACLs in AWS.	Security Groups: Act as virtual firewalls for EC2 instances to control inbound and outbound traffic. They're stateful and evaluate traffic rules at the instance level.\nNetwork Access Control Lists (NACLs): They're an additional layer of security, acting as a firewall for controlling traffic in and out of subnets. NACLs are stateless and work at the subnet level.\n\nRemember: NACLs are stateless (rules for inbound AND outbound needed), evaluated by rule number (lowest first), allow AND deny rules. Security groups are stateful, allow-only.\n\nRemember: SG = stateful allow-only (return traffic auto-allowed). NACL = stateless allow+deny (must explicitly allow return traffic). SG at instance level, NACL at subnet level.	projects/knowledge/interview/aws/421-explain-the-significance-of-security-groups-and-na.txt
aws-networking/107d39b9b693	aws-networking	easy	aws, elb, route53	What is AWS Route 53 and what DNS capabilities does it provide?	"[AWS Route 53](https://aws.amazon.com/route53): ""Amazon Route 53 is a highly available and scalable cloud Domain Name System (DNS) web service...""\n\nSome of Route 53 features:\n  * Register domains\n  * DNS service - domain name translations\n  * Health checks - verify your app is available\n  * Not a feature but its SLA is 100% availability\n\nRemember: Route 53 = AWS DNS. Supports A, AAAA, CNAME, MX, TXT, and alias records. Routing policies: Simple, Weighted, Latency, Failover, Geolocation.\n\nName origin: port 53 is the DNS port. Route 53 = DNS routing on port 53."	projects/knowledge/interview/aws/301-what-is-route-53.txt
aws-networking/122a731f7a85	aws-networking	hard	aws, route53	Explain the geoproximity routing policy	* Route based on the geographic location of resources\n* Shifting routing is done based on the `bias` value\n* Resources can be of AWS and non-AWS type\n    * For non-AWS you have to specify latitude and longitude in addition to AWS region as done in AWS-based resources\n* To use it, you have to use Route 53 traffic flow\n\nRemember: geolocation routes by user location (continent/country). Geoproximity routes by resource location with adjustable bias to shift traffic between regions.	projects/knowledge/interview/aws/315-explain-the-geoproximity-routing-policy.txt
aws-networking/15e6458b7eb9	aws-networking	medium	aws, security-group	You get time out when trying reach your application which runs on an EC2 instance. Specify one reason why it would possibly happen	Security group isn't configured properly.\n\nGotcha: AWS networking issues are almost always security group or route table misconfigurations. Check these first before investigating application-level problems.\n\nRemember: AWS networking debug flow: Security Group -> NACL -> Route Table -> IGW/NAT -> DNS resolution. Work from most specific to broadest.	projects/knowledge/interview/aws/076-you-get-time-out-when-trying-reach-your-applicatio.txt
aws-networking/15e64f2cdf05	aws-networking	medium	aws, elb	At what network level/layer a Network Load Balancer operates?	Layer 4 (Transport). NLB routes TCP/UDP connections based on IP and port, offering ultra-low latency and millions of requests per second — but no HTTP-level inspection.\n\nRemember: ALB = Layer 7 (HTTP/HTTPS, path/host routing). NLB = Layer 4 (TCP/UDP, ultra-low latency). CLB = legacy, avoid for new deployments.	projects/knowledge/interview/aws/200-at-what-network-levellayer-a-network-load-balancer.txt
aws-networking/15f002b73e96	aws-networking	medium	aws, elastic-ip, elb, route53	What are the best practices around Elastic IP?	The best practice is actually not using them in the first place. It's more common to use a load balancer without a public IP or use a random public IP and register a DNS record to it\n\nRemember: EIP = static public IPv4 address. Free when attached to a running instance. Charges apply when unattached (to discourage hoarding).	projects/knowledge/interview/aws/115-what-are-the-best-practices-around-elastic-ip.txt
aws-networking/1ea90cfacbac	aws-networking	hard	aws, elb	You are running an ALB that routes traffic using two hostnames: a.b.com and d.e.com. Is it possible to configure HTTPS for both of the hostnames?	Yes, using SNI (Server Name Indication) each application can has its own SSL certificate (This is supported from 2017).\n\nRemember: ALB = Layer 7 (HTTP/HTTPS, path/host routing). NLB = Layer 4 (TCP/UDP, ultra-low latency). CLB = legacy, avoid for new deployments.	projects/knowledge/interview/aws/393-you-are-running-an-alb-that-routes-traffic-using-t.txt
aws-networking/2238736954a0	aws-networking	hard	aws, privatelink, vpc	What is AWS Private Link ?	Allows secure connectivity between VPCs and supported AWS services without traversing the internet.\n\nRemember: AWS networking troubleshooting flow: VPC Flow Logs show allowed/denied traffic. Reachability Analyzer tests paths. Security groups and NACLs are the most common culprits.	projects/knowledge/interview/aws/456-what-is-aws-private-link.txt
aws-networking/268d9020ae32	aws-networking	medium	aws, eni	True or False? Fargate creates an ENI for every task it runs	True. Fargate creates a dedicated ENI (Elastic Network Interface) for each task, giving it its own private IP within the VPC.\n\nRemember: AWS networking troubleshooting flow: VPC Flow Logs show allowed/denied traffic. Reachability Analyzer tests paths. Security groups and NACLs are the most common culprits.	projects/knowledge/interview/aws/139-true-or-false-fargate-creates-an-eni-for-every-tas.txt
aws-networking/2708806b0e0d	aws-networking	easy	aws, networking	"What is an ""Amazon VPC""?"	A service to launch AWS resources in a logically isolated network.\n\nRemember: AWS networking troubleshooting flow: VPC Flow Logs show allowed/denied traffic. Reachability Analyzer tests paths. Security groups and NACLs are the most common culprits.	projects/knowledge/interview/aws/471-amazon-vpc.txt
aws-networking/27301488fae9	aws-networking	medium	aws, vpc	True or False? Multiple Internet Gateways can be attached to one VPC	False. Only one internet gateway can be attached to a single VPC.\n\nRemember: AWS networking troubleshooting flow: VPC Flow Logs show allowed/denied traffic. Reachability Analyzer tests paths. Security groups and NACLs are the most common culprits.	projects/knowledge/interview/aws/110-true-or-false-multiple-internet-gateways-can-be-at.txt
aws-networking/2a66609ca578	aws-networking	medium	aws, subnet, vpc	True or False? Subnets belong to the same VPC, can be in different availability zones	True. Just to clarify, a single subnet resides entirely in one AZ.\n\nRemember: AWS networking troubleshooting flow: VPC Flow Logs show allowed/denied traffic. Reachability Analyzer tests paths. Security groups and NACLs are the most common culprits.	projects/knowledge/interview/aws/104-true-or-false-subnets-belong-to-the-same-vpc-can-b.txt
aws-networking/2ad22bb39853	aws-networking	medium	aws, security-groups, nacl, networking	What's the difference between Security Groups and Network ACLs in AWS?	Security Groups are stateful firewalls that act at the instance level (controlling inbound/outbound traffic for EC2 instances, etc.), while Network ACLs are stateless firewalls at the subnet level (controlling traffic in and out of subnets). Security Groups remember connections (stateful) and apply to associated instances; NACLs apply to all traffic in a subnet and evaluate rules in order for every packet (stateless).\n\nRemember: NACLs are stateless (rules for inbound AND outbound needed), evaluated by rule number (lowest first), allow AND deny rules. Security groups are stateful, allow-only.	projects/knowledge/interview/aws/472-security-groups-vs-nacls.txt
aws-networking/2ce6ed400194	aws-networking	easy	aws, elb	What is one possible use case for using calculated health checks?	Performing maintenance for a website without causing all the health checks to fail.\n\nRemember: ELB health checks: interval (how often), threshold (consecutive successes/failures), timeout (how long to wait). Unhealthy targets are removed from rotation until they recover.	projects/knowledge/interview/aws/325-what-is-one-possible-use-case-for-using-calculated.txt
aws-networking/2d36607f983e	aws-networking	medium	aws, route53	You would like to use a routing policy based on the user location. Which one would you use?	Geolocation routing policy. It's based on user location.\n\nDon't confuse it with latency-based routing policy. While shorter distance may result in lower latency, this is not the requirement in the question.\n\nGotcha: always test networking changes in a non-production VPC first. A misconfigured route table or NACL can instantly isolate your entire application.	projects/knowledge/interview/aws/326-you-would-like-to-use-a-routing-policy-based-on-th.txt
aws-networking/33cb252d4279	aws-networking	easy	aws, transit-gateway, vpc	What is VPC peering and how does it enable cross-VPC communication?	"[docs.aws](https://docs.aws.amazon.com/vpc/latest/peering/what-is-vpc-peering.html): ""A VPC peering connection is a networking connection between two VPCs that enables you to route traffic between them using private IPv4 addresses or IPv6 addresses.""\n\nRemember: VPC peering = direct, non-transitive connection between two VPCs. Traffic stays on the AWS backbone. No transitive routing (A-B-C won't work)."	projects/knowledge/interview/aws/109-what-is-vpc-peering.txt
aws-networking/34004262ab40	aws-networking	medium	aws, elb	What types of AWS load balancers are there?	* Classic Load Balancer (CLB): Mainly for TCP (layer 4) and HTTP, HTTPS (layer 7)\n* Application Load Balancer (ALB): Mainly for HTTP, HTTPS and WebSocket\n* Network Load Balancer (NLB): Mainly for TCP, TLS and UDP\n* Gateway Load Balancer (GWLB): Mainly for layer 3 operations (IP protocol)\n\nRemember: ALB = Layer 7 (HTTP/HTTPS, path/host routing). NLB = Layer 4 (TCP/UDP, ultra-low latency). CLB = legacy, avoid for new deployments.	projects/knowledge/interview/aws/178-what-types-of-aws-load-balancers-are-there.txt
aws-networking/34dd0381c208	aws-networking	medium	aws, cloudfront, route53	How does AWS CloudFront work and what are its features?	CloudFront: It's a content delivery network (CDN) service, distributing content globally with low latency and high data transfer speeds. \nFeatures: Edge locations, caching, and origin fetch optimization are key functionalities. projects/knowledge/interview/aws/445-how-does-aws-cloudfront-work-and-what-are-its-feat.txt\n\nRemember: CloudFront = AWS CDN. Edge locations cache content globally. Origin can be S3, ALB, or custom HTTP server. Use Origin Access Control (OAC) to restrict S3 access to CloudFront only.	
aws-networking/3a666c9f197c	aws-networking	hard	aws, elb	Explain Deregistration Delay (or Connection Draining) in regards to ELB	"The period of time or process of ""draining"" instances from requests/traffic (basically let it complete all active connections but don't start new ones) so it can be de-registered eventually and ELB won't send requests/traffic to it anymore.\n\nGotcha: always test networking changes in a non-production VPC first. A misconfigured route table or NACL can instantly isolate your entire application."	projects/knowledge/interview/aws/199-explain-deregistration-delay-or-connection-drainin.txt
aws-networking/3b440ba1e8f0	aws-networking	hard	aws, elb	You have a load balancer running and behind it 5 web servers. Users complain that some times when they try to use the application it doesn't works. You've found out that sometimes some of the instances crash. How would you deal with it?	One possible way is to use health checks with the load balancer to ensure the instances are ready to be used before forwarding traffic to them.\n\nRemember: ALB = Layer 7 (HTTP/HTTPS, path/host routing). NLB = Layer 4 (TCP/UDP, ultra-low latency). CLB = legacy, avoid for new deployments.	projects/knowledge/interview/aws/391-you-have-a-load-balancer-running-and-behind-it-5-w.txt
aws-networking/3d5c8b237991	aws-networking	medium	aws, route53	True or False? Domain registrar and DNS service is inherently the same thing	False. DNS service can be Route 53 (where you manage DNS records) while the domain itself can be purchased from other sources that aren't Amazon related (e.g. GoDadday).\n\nRemember: Route 53 = AWS DNS. Supports A, AAAA, CNAME, MX, TXT, and alias records. Routing policies: Simple, Weighted, Latency, Failover, Geolocation.\n\nName origin: port 53 is the DNS port. Route 53 = DNS routing on port 53.	projects/knowledge/interview/aws/328-true-or-false-domain-registrar-and-dns-service-is-.txt
aws-networking/3ebe6d1537f3	aws-networking	medium	aws, direct-connect	Describe AWS Direct Connect and its benefits.	AWS Direct Connect: It's a dedicated network connection from on-premises networks to AWS. It's used to reduce network costs, increase bandwidth throughput, and provide a consistent network experience.\n\nRemember: Direct Connect = dedicated physical link from your datacenter to AWS. Lower latency, consistent bandwidth vs. VPN over internet.	projects/knowledge/interview/aws/434-describe-aws-direct-connect-and-its-benefits.txt
aws-networking/41236f44a5fd	aws-networking	medium	aws, security-group	True or False? Based on the shared responsibility model, Amazon is responsible for physical CPUs and security groups on instances	False. It is responsible for Hardware in its sites but not for security groups which created and managed by the users.\n\nRemember: AWS networking troubleshooting flow: VPC Flow Logs show allowed/denied traffic. Reachability Analyzer tests paths. Security groups and NACLs are the most common culprits.	projects/knowledge/interview/aws/215-true-or-false-based-on-the-shared-responsibility-m.txt
aws-networking/41b529263d26	aws-networking	medium	aws, elastic-ip	Why would you use an Elastic IP address?	Let's say you have an instance that you need to shutdown or perform some maintenance on. In that case, what you would want to do is to move the Elastic IP address to another instance that is operational, until you finish to perform the maintenance and then you can move it back to the original instance (or keep it assigned to the second one).\n\nRemember: EIP = static public IPv4 address. Free when attached to a running instance. Charges apply when unattached (to discourage hoarding).	projects/knowledge/interview/aws/114-why-would-you-use-an-elastic-ip-address.txt
aws-networking/472ae857d51b	aws-networking	hard	aws, elb, route53	Who has better latency? Application Load Balancer or Network Load Balancer?	Network Load Balancer (~100 ms) as ALB has a latency of ~400 ms\n\nRemember: ALB = Layer 7 (HTTP/HTTPS, path/host routing). NLB = Layer 4 (TCP/UDP, ultra-low latency). CLB = legacy, avoid for new deployments.	projects/knowledge/interview/aws/188-who-has-better-latency-application-load-balancer-o.txt
aws-networking/4b0fa6a62668	aws-networking	medium	aws, route53	"What it means that ""Route 53 is an Authoritative DNS""?"	The customer can update DNS records\n\nRemember: Route 53 = AWS DNS. Supports A, AAAA, CNAME, MX, TXT, and alias records. Routing policies: Simple, Weighted, Latency, Failover, Geolocation.\n\nName origin: port 53 is the DNS port. Route 53 = DNS routing on port 53.	projects/knowledge/interview/aws/302-what-it-means-that-route-53-is-an-authoritative-dn.txt
aws-networking/4b1005218ff0	aws-networking	medium	aws, subnet, vpc	Explain subnets and regions to management body.	Subnets are like different sections within your office building (VPC). Each section is for different departments or teams. Regions, on the other hand, are like different cities where you can have your office. Each city can have its own set of office buildings (VPCs).\nSubnets are partitions within a VPC and are associated with a specific Availability Zone. Regions are separate geographic areas where AWS data centers are located.\n\nGotcha: always test networking changes in a non-production VPC first. A misconfigured route table or NACL can instantly isolate your entire application.	projects/knowledge/interview/aws/403-explain-subnets-and-regions-to-management-body.txt
aws-networking/4d2060962d75	aws-networking	easy	aws, route-table, vpc	What is an Internet Gateway?	"[AWS Docs](https://docs.aws.amazon.com/vpc/latest/userguide/VPC_Internet_Gateway.html): ""component that allows communication between instances in your VPC and the internet""\n\nIn addition it's good to know that IGW is:\n  * Highly available and redundant\n  * Not porivding internet access by its own (you need route tables to be edited)\n  * Created separately from VPC\n\nGotcha: always test networking changes in a non-production VPC first. A misconfigured route table or NACL can instantly isolate your entire application."	projects/knowledge/interview/aws/107-what-is-an-internet-gateway.txt
aws-networking/4d4262d713b9	aws-networking	easy	aws, route53, dns	What is Amazon Route 53?	Route 53 is AWS's scalable Domain Name System (DNS) web service. It's used for domain registration, DNS routing (translating domain names to IP addresses of AWS or non-AWS resources), and health checking.\n\nRemember: Route 53 = AWS DNS. Supports A, AAAA, CNAME, MX, TXT, and alias records. Routing policies: Simple, Weighted, Latency, Failover, Geolocation.\n\nName origin: port 53 is the DNS port. Route 53 = DNS routing on port 53.	projects/knowledge/interview/aws/473-what-is-route53.txt
aws-networking/4f48247e4b5d	aws-networking	easy	aws, subnet, vpc	You have noticed your VPC's subnets (which use x.x.x.x/20 CIDR) have 4096 available IP addresses although this CIDR should have 4096 addresses. What is the reason for that?	AWS reserves 5 IP addresses in each subnet - first 4 and the last one, and so they aren't available for use.\n\nRemember: /16 = 65,536 IPs, /24 = 256 IPs, /28 = 16 IPs. AWS reserves 5 IPs per subnet (network, router, DNS, future, broadcast).	projects/knowledge/interview/aws/105-you-have-noticed-your-vpcs-subnets-which-use-xxxx2.txt
aws-networking/505819329c14	aws-networking	hard	aws, elb	You have a load balancer running and behind it 5 web servers. Users complain that every time they move to a new page, they have to authenticate, instead of doing it once. How can you solve it?	Enable sticky sessions. This way, the user keep working against the same instance, instead of being redirected to a different instance every request.\n\nRemember: ALB = Layer 7 (HTTP/HTTPS, path/host routing). NLB = Layer 4 (TCP/UDP, ultra-low latency). CLB = legacy, avoid for new deployments.	projects/knowledge/interview/aws/390-you-have-a-load-balancer-running-and-behind-it-5-w.txt
aws-networking/57d1017fa9b3	aws-networking	hard	aws, vpc	What is a VPC analyzer ?	A tool for monitoring and identifying risks and threats in VPC flow logs.\n\nRemember: AWS networking troubleshooting flow: VPC Flow Logs show allowed/denied traffic. Reachability Analyzer tests paths. Security groups and NACLs are the most common culprits.	projects/knowledge/interview/aws/455-what-is-a-vpc-analyzer.txt
aws-networking/59bbbe137d16	aws-networking	hard	aws, elb, route53	How can a company ensure their web application continues to operate if it becomes unavailable in its current single region?	Deploy the application in multiple Regions. Use Amazon Route 53 DNS health checks to route traffic to a healthy Region\n\nRemember: AWS networking troubleshooting flow: VPC Flow Logs show allowed/denied traffic. Reachability Analyzer tests paths. Security groups and NACLs are the most common culprits.	projects/knowledge/interview/aws/175-how-can-a-company-ensure-their-web-application-con.txt
aws-networking/5c68060e4e8b	aws-networking	medium	aws, elb	True or False? Network load balancers operate in layer 4	True. They forward TCP, UDP traffic.\n\nRemember: ALB = Layer 7 (HTTP/HTTPS, path/host routing). NLB = Layer 4 (TCP/UDP, ultra-low latency). CLB = legacy, avoid for new deployments.	projects/knowledge/interview/aws/194-true-or-false-network-load-balancers-operate-in-la.txt
aws-networking/5c9533000183	aws-networking	medium	aws, elb	What are possible target groups for ALB (Application Load Balancer)?	* EC2 tasks\n* ECS instances\n* Lambda functions\n* Private IP Addresses\n\nRemember: ALB = Layer 7 (HTTP/HTTPS, path/host routing). NLB = Layer 4 (TCP/UDP, ultra-low latency). CLB = legacy, avoid for new deployments.	projects/knowledge/interview/aws/185-what-are-possible-target-groups-for-alb-applicatio.txt
aws-networking/5d1dfaf81eda	aws-networking	medium	aws, security-group	True or False? Security groups only contain deny rules	False. Security groups only contain allow rules.\n\nGotcha: AWS networking issues are almost always security group or route table misconfigurations. Check these first before investigating application-level problems.\n\nRemember: AWS networking debug flow: Security Group -> NACL -> Route Table -> IGW/NAT -> DNS resolution. Work from most specific to broadest.	projects/knowledge/interview/aws/069-true-or-false-security-groups-only-contain-deny-ru.txt
aws-networking/5dc3f930bd0d	aws-networking	medium	aws, route53	True or False? Route 53 simple routing policy supports both single and multiple values	True.\n\nIf multiple values are returned from Route 53 then, the client chooses a single value to use.\n\nRemember: Route 53 = AWS DNS. Supports A, AAAA, CNAME, MX, TXT, and alias records. Routing policies: Simple, Weighted, Latency, Failover, Geolocation.\n\nName origin: port 53 is the DNS port. Route 53 = DNS routing on port 53.	projects/knowledge/interview/aws/317-true-or-false-route-53-simple-routing-policy-suppo.txt
aws-networking/5e352e2e6d2e	aws-networking	medium	aws, elb	True or False? Network load balancer has one static IP per availability zone	True. NLB provides one static IP per AZ, making it ideal for whitelisting. ALB, by contrast, uses dynamic IPs behind a DNS name.\n\nRemember: ALB = Layer 7 (HTTP/HTTPS, path/host routing). NLB = Layer 4 (TCP/UDP, ultra-low latency). CLB = legacy, avoid for new deployments.	projects/knowledge/interview/aws/189-true-or-false-network-load-balancer-has-one-static.txt
aws-networking/5ed83a669cbe	aws-networking	medium	aws, route53	You would like to use a routing policy that will take latency into account and will route to the resource with the lowest latency. Which routing policy would you use?	Latency-based routing policy.\n\nGotcha: AWS networking issues are almost always security group or route table misconfigurations. Check these first before investigating application-level problems.\n\nRemember: AWS networking debug flow: Security Group -> NACL -> Route Table -> IGW/NAT -> DNS resolution. Work from most specific to broadest.	projects/knowledge/interview/aws/319-you-would-like-to-use-a-routing-policy-that-will-t.txt
aws-networking/608e90f9fdbf	aws-networking	medium	aws, route53	True or False? In weighted routing DNS records must have the same name but not the same type	False. They must have the same name AND type.\n\nRemember: Route 53 = AWS DNS. Supports A, AAAA, CNAME, MX, TXT, and alias records. Routing policies: Simple, Weighted, Latency, Failover, Geolocation.\n\nName origin: port 53 is the DNS port. Route 53 = DNS routing on port 53.	projects/knowledge/interview/aws/318-true-or-false-in-weighted-routing-dns-records-must.txt
aws-networking/6148e4a90e8b	aws-networking	easy	aws, direct-connect	What is AWS Direct Connect?	Allows you to connect your corporate network to AWS network.\n\nRemember: Direct Connect = dedicated physical link from your datacenter to AWS. Lower latency, consistent bandwidth vs. VPN over internet.	projects/knowledge/interview/aws/119-what-is-aws-direct-connect.txt
aws-networking/671651036a26	aws-networking	medium	aws, route53	Suppose you need to route % of your traffic to a certain instance and the rest of the traffic, to another instance. Which routing policy would you choose?	Weighted routing policy.\n\nGotcha: AWS networking issues are almost always security group or route table misconfigurations. Check these first before investigating application-level problems.\n\nRemember: AWS networking debug flow: Security Group -> NACL -> Route Table -> IGW/NAT -> DNS resolution. Work from most specific to broadest.	projects/knowledge/interview/aws/311-suppose-you-need-to-route-of-your-traffic-to-a-cer.txt
aws-networking/67adf107b1e2	aws-networking	medium	aws, security-group, vpc	True or False? Security groups are not locked down to a region and VPC (meaning you don't have to create a new one when switching regions)	False. They are locked down to regions and VPC.\n\nGotcha: AWS networking issues are almost always security group or route table misconfigurations. Check these first before investigating application-level problems.\n\nRemember: AWS networking debug flow: Security Group -> NACL -> Route Table -> IGW/NAT -> DNS resolution. Work from most specific to broadest.	projects/knowledge/interview/aws/070-true-or-false-security-groups-are-not-locked-down-.txt
aws-networking/69d4f2be9358	aws-networking	medium	aws, elb	What types of load balancers are supported in EC2 and what are they used for?	* Application LB - layer 7 traffic \n* Network LB - ultra-high performances or static IP address (layer 4) \n* Classic LB - low costs, good for test or dev environments (retired by August 15, 2022) \n* Gateway LB - transparent network gateway and distributes traffic such as firewalls, intrusion detection and prevention systems, and deep packet inspection systems. (layer 3)\n\nRemember: ALB = Layer 7 (HTTP/HTTPS, path/host routing). NLB = Layer 4 (TCP/UDP, ultra-low latency). CLB = legacy, avoid for new deployments.	projects/knowledge/interview/aws/183-what-types-of-load-balancers-are-supported-in-ec2-.txt
aws-networking/6acae81472cb	aws-networking	medium	aws, route53	Which service would you use for creating DNS record?	Amazon Route 53. It provides DNS hosting, domain registration, health checks, and routing policies (latency-based, geo, weighted, failover).\n\nRemember: Route 53 = AWS DNS. Supports A, AAAA, CNAME, MX, TXT, and alias records. Routing policies: Simple, Weighted, Latency, Failover, Geolocation.\n\nName origin: port 53 is the DNS port. Route 53 = DNS routing on port 53.	projects/knowledge/interview/aws/289-which-service-would-you-use-for-creating-dns-recor.txt
aws-networking/6f89d294272e	aws-networking	medium	aws, vpc	True or False? VPC spans multiple regions	False. A VPC spans a single region. It can span multiple Availability Zones within that region, but not across regions. For cross-region connectivity, use VPC peering or Transit Gateway.\n\nRemember: AWS networking troubleshooting flow: VPC Flow Logs show allowed/denied traffic. Reachability Analyzer tests paths. Security groups and NACLs are the most common culprits.	projects/knowledge/interview/aws/102-true-or-false-vpc-spans-multiple-regions.txt
aws-networking/7066dfd6bd71	aws-networking	medium	aws, elb	Which type of AWS load balancer is used in the following drawing?	Application Load Balancer (routing based on different endpoints + HTTP is used).\n\nRemember: ALB = Layer 7 (HTTP/HTTPS, path/host routing). NLB = Layer 4 (TCP/UDP, ultra-low latency). CLB = legacy, avoid for new deployments.	projects/knowledge/interview/aws/184-which-type-of-aws-load-balancer-is-used-in-the-fol.txt
aws-networking/7099a993ac32	aws-networking	medium	aws, elastic-ip	You've restarted your EC2 instance and the public IP has changed. How would you deal with it so it won't happen?	Use Elastic IP which provides you a fixed IP address.\n\nRemember: AWS networking troubleshooting flow: VPC Flow Logs show allowed/denied traffic. Reachability Analyzer tests paths. Security groups and NACLs are the most common culprits.	projects/knowledge/interview/aws/111-youve-restarted-your-ec2-instance-and-the-public-i.txt
aws-networking/7151d8e0ba03	aws-networking	easy	aws, route53	What is a routing policy in regards to AWS Route 53?	A routing policy routing defines how Route 53 responds to DNS queries.\n\nRemember: Route 53 = AWS DNS. Supports A, AAAA, CNAME, MX, TXT, and alias records. Routing policies: Simple, Weighted, Latency, Failover, Geolocation.\n\nName origin: port 53 is the DNS port. Route 53 = DNS routing on port 53.	projects/knowledge/interview/aws/309-what-is-a-routing-policy-in-regards-to-aws-route-5.txt
aws-networking/72d6a4f9bbb7	aws-networking	medium	aws, eni	True or False? ENI are not bound to a specific availability zone	False. ENI are bound to specific availability zone.\n\nGotcha: AWS networking issues are almost always security group or route table misconfigurations. Check these first before investigating application-level problems.\n\nRemember: AWS networking debug flow: Security Group -> NACL -> Route Table -> IGW/NAT -> DNS resolution. Work from most specific to broadest.	projects/knowledge/interview/aws/094-true-or-false-eni-are-not-bound-to-a-specific-avai.txt
aws-networking/73cb38223d4b	aws-networking	hard	aws, api-gateway	What's one of the issues with the current architecture?	Users shouldn't access directly AWS Lambda directly. If you'd to like to expose your Lambda function to users a better approach would be to set up API Gateway endpoint between the users and the Lambda function.\n\nThis not only provides enhanced security but also easier access for the user where he can use HTTP or HTTPS for accessing the function.\n\nGotcha: always test networking changes in a non-production VPC first. A misconfigured route table or NACL can instantly isolate your entire application.	projects/knowledge/interview/aws/128-whats-one-of-the-issues-with-the-current-architect.txt
aws-networking/7698547da5a2	aws-networking	medium	aws, elb, route53	Describe AWS Route 53 and its key features.	Route 53: It's a scalable domain name system (DNS) web service providing domain registration and routing internet traffic to resources. \nKey Features: Health checks, traffic flow, domain registration, and global data propagation are significant functionalities. projects/knowledge/interview/aws/440-describe-aws-route-53-and-its-key-features.txt\n\nRemember: Route 53 = AWS DNS. Supports A, AAAA, CNAME, MX, TXT, and alias records. Routing policies: Simple, Weighted, Latency, Failover, Geolocation.\n\nName origin: port 53 is the DNS port. Route 53 = DNS routing on port 53.	
aws-networking/7835381522af	aws-networking	hard	aws, elb	If you wanted to analyze network traffic, you would use the `____ load balancer`	Gateway Load Balancer\n\nRemember: ALB = Layer 7 (HTTP/HTTPS, path/host routing). NLB = Layer 4 (TCP/UDP, ultra-low latency). CLB = legacy, avoid for new deployments.	projects/knowledge/interview/aws/187-if-you-wanted-to-analyze-network-traffic-you-would.txt
aws-networking/792f346a717a	aws-networking	medium	aws, elb	True or False? With ALB (Application Load Balancer) it's possible to do routing based on query string and/or headers	True. ALB supports advanced routing rules based on path, host header, query strings, HTTP headers, and source IP — enabling microservice-style routing.\n\nRemember: ALB = Layer 7 (HTTP/HTTPS, path/host routing). NLB = Layer 4 (TCP/UDP, ultra-low latency). CLB = legacy, avoid for new deployments.	projects/knowledge/interview/aws/201-true-or-false-with-alb-application-load-balancer-i.txt
aws-networking/7a2ae2404d19	aws-networking	medium	aws, eni, vpc	Explain Elastic Network Interfaces (ENI)	"[AWS Docs](https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/using-eni.html): ""An elastic network interface is a logical networking component in a VPC that represents a virtual network card.""\n\nRemember: AWS networking troubleshooting flow: VPC Flow Logs show allowed/denied traffic. Reachability Analyzer tests paths. Security groups and NACLs are the most common culprits."	projects/knowledge/interview/aws/092-explain-elastic-network-interfaces-eni.txt
aws-networking/7ac22441d430	aws-networking	hard	aws, elb	True or False? In regards to cross zone load balancing, AWS charges you for inter AZ data in network load balancer but no in application load balancer	True. It charges for inter AZ data in network load balancer, but not in application load balancer\n\nRemember: ALB = Layer 7 (HTTP/HTTPS, path/host routing). NLB = Layer 4 (TCP/UDP, ultra-low latency). CLB = legacy, avoid for new deployments.	projects/knowledge/interview/aws/198-true-or-false-in-regards-to-cross-zone-load-balanc.txt
aws-networking/7b2a3e5738c5	aws-networking	easy	aws, cloudfront, route53	Explain what is CloudFront	"AWS definition: ""Amazon CloudFront is a fast content delivery network (CDN) service that securely delivers data, videos, applications, and APIs to customers globally with low latency, high transfer speeds, all within a developer-friendly environment.""\n\nMore on CloudFront [here](https://aws.amazon.com/cloudfront)\n\nRemember: CloudFront = AWS CDN. Edge locations cache content globally. Origin can be S3, ALB, or custom HTTP server. Use Origin Access Control (OAC) to restrict S3 access to CloudFront only."	projects/knowledge/interview/aws/173-explain-what-is-cloudfront.txt
aws-networking/7ea745766a8a	aws-networking	medium	aws, security-group	What are some of the properties/configuration options of EC2 instances that can be set or modified?	* OS (Linux, Windows)\n* RAM and CPU\n* Networking - IP, Card properties like speed\n* Storage Space - (EBS, EFS, EC2 Instance Store)\n* EC2 User Data\n* Security groups\n\nRemember: AWS networking troubleshooting flow: VPC Flow Logs show allowed/denied traffic. Reachability Analyzer tests paths. Security groups and NACLs are the most common culprits.	projects/knowledge/interview/aws/022-what-are-some-of-the-propertiesconfiguration-optio.txt
aws-networking/8028ce27d74a	aws-networking	hard	aws, route53, vpc	True or False? Default VPC doesn't have internet connectivity and any launched EC2 will only have a private IP assigned	False. The default VPC has internet connectivity and any launched EC2 instance gets a public IPv4 address.\n\nIn addition, any launched EC2 instance gets a public and private DNS names.\n\nRemember: AWS networking troubleshooting flow: VPC Flow Logs show allowed/denied traffic. Reachability Analyzer tests paths. Security groups and NACLs are the most common culprits.	projects/knowledge/interview/aws/123-true-or-false-default-vpc-doesnt-have-internet-con.txt
aws-networking/81310f250eb0	aws-networking	medium	aws, elb	True or False? Elastic Load Balancer is a managed resource (= AWS takes care of it)	True. AWS responsible for making sure ELB is operational and takes care of lifecycle operations like upgrades, maintenance and high availability.\n\nRemember: ALB = Layer 7 (HTTP/HTTPS, path/host routing). NLB = Layer 4 (TCP/UDP, ultra-low latency). CLB = legacy, avoid for new deployments.	projects/knowledge/interview/aws/177-true-or-false-elastic-load-balancer-is-a-managed-r.txt
aws-networking/814e4f19b877	aws-networking	medium	aws, route53	True or False? Alias record can be set up for an EC2 DNS name	False. Alias records cannot target EC2 instance DNS names directly. They work with AWS resources like ELB, CloudFront, S3, and API Gateway. Use a CNAME or A record for EC2.\n\nRemember: Route 53 = AWS DNS. Supports A, AAAA, CNAME, MX, TXT, and alias records. Routing policies: Simple, Weighted, Latency, Failover, Geolocation.\n\nName origin: port 53 is the DNS port. Route 53 = DNS routing on port 53.	projects/knowledge/interview/aws/308-true-or-false-alias-record-can-be-set-up-for-an-ec.txt
aws-networking/8155ad197574	aws-networking	medium	aws, elb	What are the supported target groups for gateway load balancer?	* EC2 instance\n* IP addresses (must be private IPs)\n\nRemember: ALB = Layer 7 (HTTP/HTTPS, path/host routing). NLB = Layer 4 (TCP/UDP, ultra-low latency). CLB = legacy, avoid for new deployments.	projects/knowledge/interview/aws/191-what-are-the-supported-target-groups-for-gateway-l.txt
aws-networking/846cbc2506f9	aws-networking	medium	aws, vpc	True or False? It's possible to have multiple VPCs in one region	True. As of today, the soft limit is 5.\n\nGotcha: AWS networking issues are almost always security group or route table misconfigurations. Check these first before investigating application-level problems.\n\nRemember: AWS networking debug flow: Security Group -> NACL -> Route Table -> IGW/NAT -> DNS resolution. Work from most specific to broadest.	projects/knowledge/interview/aws/103-true-or-false-its-possible-to-have-multiple-vpcs-i.txt
aws-networking/89a10e3df3e3	aws-networking	medium	aws, elastic-ip	What would you use if you need a fixed public IP for your EC2 instance?	Elastic IP. It's a static public IPv4 address you allocate to your account and associate with an instance or NAT gateway. It persists across stop/start cycles.\n\nRemember: AWS networking troubleshooting flow: VPC Flow Logs show allowed/denied traffic. Reachability Analyzer tests paths. Security groups and NACLs are the most common culprits.	projects/knowledge/interview/aws/120-what-would-you-use-if-you-need-a-fixed-public-ip-f.txt
aws-networking/91c77593de09	aws-networking	easy	aws, elb	What is ELB (Elastic Load Balancing)?	"[AWS Docs](https://aws.amazon.com/elasticloadbalancing): ""Elastic Load Balancing automatically distributes incoming application traffic across multiple targets, such as Amazon EC2 instances, containers, IP addresses, and Lambda functions.""\n\nRemember: AWS networking troubleshooting flow: VPC Flow Logs show allowed/denied traffic. Reachability Analyzer tests paths. Security groups and NACLs are the most common culprits."	projects/knowledge/interview/aws/176-what-is-elb-elastic-load-balancing.txt
aws-networking/966c198c8856	aws-networking	hard	aws, elb, route53	True or False? Route 53 Multi Value is a substitute for those who want cheaper solution than ELB	False. Route 53 Multi Value is not a substitute for ELB. It's focused on client-side load balancing as opposed to ELB.\n\nRemember: Route 53 = AWS DNS. Supports A, AAAA, CNAME, MX, TXT, and alias records. Routing policies: Simple, Weighted, Latency, Failover, Geolocation.\n\nName origin: port 53 is the DNS port. Route 53 = DNS routing on port 53.	projects/knowledge/interview/aws/327-true-or-false-route-53-multi-value-is-a-substitute.txt
aws-networking/9d504c1d1837	aws-networking	hard	aws, elb, route53	You've been asked to design an architecture for high performance and low-latency application (millions of requests per second). Which load balancer would you use?	Network Load Balancer\n\nRemember: ALB = Layer 7 (HTTP/HTTPS, path/host routing). NLB = Layer 4 (TCP/UDP, ultra-low latency). CLB = legacy, avoid for new deployments.	projects/knowledge/interview/aws/398-youve-been-asked-to-design-an-architecture-for-hig.txt
aws-networking/9d85dd23bf36	aws-networking	medium	aws, vpc	True or False? By default, any new account has a default VPC	True. Every new AWS account comes with a default VPC in each region, pre-configured with a public subnet per AZ, internet gateway, and route table.\n\nRemember: AWS networking troubleshooting flow: VPC Flow Logs show allowed/denied traffic. Reachability Analyzer tests paths. Security groups and NACLs are the most common culprits.	projects/knowledge/interview/aws/122-true-or-false-by-default-any-new-account-has-a-def.txt
aws-networking/9f4397da2f66	aws-networking	hard	aws, nacl, security-group, subnet	If security groups are there then why do we need NACLs or vice versa.	Security groups are like bouncers at the entrance of your office building, deciding who gets in or out of the entire building. NACLs are more like security guards stationed in different sections of the building (subnets), controlling movement within. Thus Security Groups act at the instance level, while NACLs act at the subnet level, offering an additional layer of security.\n\nRemember: NACLs are stateless (rules for inbound AND outbound needed), evaluated by rule number (lowest first), allow AND deny rules. Security groups are stateful, allow-only.\n\nRemember: SG = stateful allow-only (return traffic auto-allowed). NACL = stateless allow+deny (must explicitly allow return traffic). SG at instance level, NACL at subnet level.	projects/knowledge/interview/aws/407-if-security-groups-are-there-then-why-do-we-need-n.txt
aws-networking/9f72bdb7c67e	aws-networking	medium	aws, route53	Explain the geolocation routing policy	* Routing based on user location\n* Location can be specified by continent, country or US state\n* It's recommended to have a default record in case there is no match on location\n\nRemember: geolocation routes by user location (continent/country). Geoproximity routes by resource location with adjustable bias to shift traffic between regions.	projects/knowledge/interview/aws/313-explain-the-geolocation-routing-policy.txt
aws-networking/a55484a80114	aws-networking	medium	aws, elb	True or False? ALB can route only to a single route group	False. ALB can route to multiple target groups.\n\nRemember: ALB = Layer 7 (HTTP/HTTPS, path/host routing). NLB = Layer 4 (TCP/UDP, ultra-low latency). CLB = legacy, avoid for new deployments.	projects/knowledge/interview/aws/186-true-or-false-alb-can-route-only-to-a-single-route.txt
aws-networking/a5581d91b6ea	aws-networking	medium	aws, route-table	True or False? Route Tables used to allow or deny traffic from the internet to AWS instances	False. Route tables control where network traffic is directed (routing), not access control. Security Groups and Network ACLs handle allow/deny decisions.\n\nRemember: AWS networking troubleshooting flow: VPC Flow Logs show allowed/denied traffic. Reachability Analyzer tests paths. Security groups and NACLs are the most common culprits.	projects/knowledge/interview/aws/117-true-or-false-route-tables-used-to-allow-or-deny-t.txt
aws-networking/a650ab5a83ff	aws-networking	medium	aws, route-table, subnet, vpc	Explain the concept of VPC (Virtual Private Cloud) in AWS.	**VPC:** Imagine a VPC as your own virtual space in the cloud. It's like your personal office building in a city full of skyscrapers. Your VPC is where you control your network, your own space with its own address and security. You decide who can come in, what rooms they can access, and how they move around. It's a virtual network dedicated to your AWS account. It allows you to select your IP address range, create subnets, and configure route tables and network gateways. VPC provides isolation and control over your network environment.	projects/knowledge/interview/aws/428-explain-the-concept-of-vpc-virtual-private-cloud-i.txt
aws-networking/aa23cb1d2dfb	aws-networking	medium	aws, route53	Suppose you need to route traffic to a single source with Route 53, without any other requirements, which routing policy would you choose?	The `simple` routing policy\n\nRemember: Route 53 = AWS DNS. Supports A, AAAA, CNAME, MX, TXT, and alias records. Routing policies: Simple, Weighted, Latency, Failover, Geolocation.\n\nName origin: port 53 is the DNS port. Route 53 = DNS routing on port 53.	projects/knowledge/interview/aws/312-suppose-you-need-to-route-traffic-to-a-single-sour.txt
aws-networking/ab4f09702765	aws-networking	medium	aws, route53	What are some use cases for using geolocation routing policy?	* Restrict content distribution\n* App localization\n* Load balancing\n\nRemember: geolocation routes by user location (continent/country). Geoproximity routes by resource location with adjustable bias to shift traffic between regions.	projects/knowledge/interview/aws/314-what-are-some-use-cases-for-using-geolocation-rout.txt
aws-networking/ac24c81ddc72	aws-networking	medium	aws, route53	what all algorithms are supported by Route53 ?	Route 53 is like a guide giving directions. It supports different methods of directing traffic to the right places, ensuring the quickest and most efficient routes for your services. It supports a variety of DNS routing algorithms like Simple, Weighted, Latency-based, and Geolocation routing.\n\nGotcha: always test networking changes in a non-production VPC first. A misconfigured route table or NACL can instantly isolate your entire application.	projects/knowledge/interview/aws/415-what-all-algorithms-are-supported-by-route53.txt
aws-networking/ac59653f1925	aws-networking	easy	aws, security, networking	"What is a ""Security Group""?"	A virtual firewall controlling traffic for EC2 instances.\n\nGotcha: AWS networking issues are almost always security group or route table misconfigurations. Check these first before investigating application-level problems.\n\nRemember: AWS networking debug flow: Security Group -> NACL -> Route Table -> IGW/NAT -> DNS resolution. Work from most specific to broadest.	projects/knowledge/interview/aws/473-security-group.txt
aws-networking/aca6696b816a	aws-networking	hard	aws, elb	What are some use cases for using Gateway Load Balancer?	* Intrusion Detection\n* Firewall\n* Payload manipulation\n\nRemember: ALB = Layer 7 (HTTP/HTTPS, path/host routing). NLB = Layer 4 (TCP/UDP, ultra-low latency). CLB = legacy, avoid for new deployments.	projects/knowledge/interview/aws/180-what-are-some-use-cases-for-using-gateway-load-bal.txt
aws-networking/add4d06c06fe	aws-networking	medium	aws, elastic-ip	What would you use to check how many unassociated Elastic IP address you have?	Trusted Advisor\n\nRemember: EIP = static public IPv4 address. Free when attached to a running instance. Charges apply when unattached (to discourage hoarding).	projects/knowledge/interview/aws/272-what-would-you-use-to-check-how-many-unassociated-.txt
aws-networking/af0cfa789eb2	aws-networking	medium	aws, route53	What DNS record types does Route 53 supports?	* A\n* AAAA\n* CNAME\n* NS\n* DS\n* CAA\n* SOA\n* MX\n* TXT\n* SPF\n* SRV\n* NAPTR\n* PTR\n\nRemember: Route 53 = AWS DNS. Supports A, AAAA, CNAME, MX, TXT, and alias records. Routing policies: Simple, Weighted, Latency, Failover, Geolocation.\n\nName origin: port 53 is the DNS port. Route 53 = DNS routing on port 53.	projects/knowledge/interview/aws/304-what-dns-record-types-does-route-53-supports.txt
aws-networking/b1b420191eab	aws-networking	hard	aws, elb	What are calculated health checks?	When you combine the results of multiple health checks into a single health check.\n\nRemember: ELB health checks: interval (how often), threshold (consecutive successes/failures), timeout (how long to wait). Unhealthy targets are removed from rotation until they recover.	projects/knowledge/interview/aws/324-what-are-calculated-health-checks.txt
aws-networking/b21b6726a96b	aws-networking	easy	aws, elastic-ip	What is an Elastic IP address?	"[AWS Docs](https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/elastic-ip-addresses-eip.html): ""An Elastic IP address is a static IPv4 address designed for dynamic cloud computing. An Elastic IP address is allocated to your AWS account, and is yours until you release it. By using an Elastic IP address, you can mask the failure of an instance or software by rapidly remapping the address to another instance in your account.""\n\nRemember: EIP = static public IPv4 address. Free when attached to a running instance. Charges apply when unattached (to discourage hoarding)."	projects/knowledge/interview/aws/113-what-is-an-elastic-ip-address.txt
aws-networking/b22d81733e64	aws-networking	medium	aws, api-gateway	Which services are involved in getting a custom string (based on the input) when inserting a URL in the browser?	Lambda - to define a function that gets an input and returns a certain string \nAPI Gateway - to define the URL trigger (= when you insert the URL, the function is invoked).\n\nGotcha: always test networking changes in a non-production VPC first. A misconfigured route table or NACL can instantly isolate your entire application.	projects/knowledge/interview/aws/297-which-services-are-involved-in-getting-a-custom-st.txt
aws-networking/ba0831d7d1ed	aws-networking	medium	aws, vpc	Which of the following is included with default VPC?	All of the listed items are included with the default VPC: a public subnet in each Availability Zone, an internet gateway, a default route table with a route to the internet gateway, a default security group, and a default network ACL.\n\nGotcha: always test networking changes in a non-production VPC first. A misconfigured route table or NACL can instantly isolate your entire application.	projects/knowledge/interview/aws/124-which-of-the-following-is-included-with-default-vp.txt
aws-networking/bafd2a4e1219	aws-networking	medium	aws, route53	What Route 53 routing policies are there?	* Simple \n* Geolocation\n* Failover\n* Latency based\n* Geoproximity\n* Multi-Value Answer\n* Weighted\n\nRemember: Route 53 = AWS DNS. Supports A, AAAA, CNAME, MX, TXT, and alias records. Routing policies: Simple, Weighted, Latency, Failover, Geolocation.\n\nName origin: port 53 is the DNS port. Route 53 = DNS routing on port 53.	projects/knowledge/interview/aws/310-what-route-53-routing-policies-are-there.txt
aws-networking/bb18c8df474e	aws-networking	medium	aws, elb	Which load balancer would you use for services which use HTTP or HTTPS traffic?	Application Load Balancer (ALB).\n\nRemember: ALB = Layer 7 (HTTP/HTTPS, path/host routing). NLB = Layer 4 (TCP/UDP, ultra-low latency). CLB = legacy, avoid for new deployments.	projects/knowledge/interview/aws/179-which-load-balancer-would-you-use-for-services-whi.txt
aws-networking/bd285a123cde	aws-networking	medium	aws, vpc	What is an ec2 instance ?	An EC2 instance is like a computer that lives in your virtual office (VPC). It's where you can run programs, websites, or anything you'd usually do on your computer, but it's located in the cloud.\n\nGotcha: always test networking changes in a non-production VPC first. A misconfigured route table or NACL can instantly isolate your entire application.	projects/knowledge/interview/aws/404-what-is-an-ec2-instance.txt
aws-networking/c18f323a940c	aws-networking	hard	aws, elastic-ip, route53	Describe in high-level how to upgrade a system on AWS with (near) zero downtime	One way is through launching a new instance. In more detail:\n\n1. Launch a new instance\n2. Install all the updates and applications\n3. Test the instance\n4. If all tests passed successfully, you can start using the new instance and perform the switch with the old one, in one of various ways:\n  1. Go to route53 and update the record with the IP of the new instance\n  2. If you are using an Elastic IP then move it to the new instance\n  ...	projects/knowledge/interview/aws/383-describe-in-high-level-how-to-upgrade-a-system-on-.txt
aws-networking/c33b2fc88857	aws-networking	medium	aws, route53	You would like to use a routing policy based on the resource location and be able to shift more traffic to some resources. Which one would you use?	Geoproximity routing policy\n\nGotcha: AWS networking issues are almost always security group or route table misconfigurations. Check these first before investigating application-level problems.\n\nRemember: AWS networking debug flow: Security Group -> NACL -> Route Table -> IGW/NAT -> DNS resolution. Work from most specific to broadest.	projects/knowledge/interview/aws/322-you-would-like-to-use-a-routing-policy-based-on-th.txt
aws-networking/c41ddb4d6150	aws-networking	hard	aws, elb	Name one use case for using application load balancer as a target group for network load balancer	You might want to have a fixed IP address (NLB) and then forward HTTP traffic based on path, query, ... which is then done by ALB\n\nRemember: ALB = Layer 7 (HTTP/HTTPS, path/host routing). NLB = Layer 4 (TCP/UDP, ultra-low latency). CLB = legacy, avoid for new deployments.	projects/knowledge/interview/aws/192-name-one-use-case-for-using-application-load-balan.txt
aws-networking/c6bdbe52b3d0	aws-networking	hard	aws, elb	You run your application on 5 EC2 instances on one AZ and on 10 EC2 instances in another AZ. You distribute traffic between all of them using a network load balancer, but it seems that instances in one AZ have higher CPU rates than the instances in the other AZ. What might be the issue and how to solve it?	It's possible that traffic is distributed evenly between the AZs but that doesn't mean it's distributed equally across all instances evenly.\n\nTo distribute it evenly between all the instances, you have to enable cross-zone load balancing.\n\nRemember: ALB = Layer 7 (HTTP/HTTPS, path/host routing). NLB = Layer 4 (TCP/UDP, ultra-low latency). CLB = legacy, avoid for new deployments.	projects/knowledge/interview/aws/392-you-run-your-application-on-5-ec2-instances-on-one.txt
aws-networking/c8ac3bd6a3cd	aws-networking	hard	aws, elb, security-group	You've created a network load balancer but it doesn't work (you can't reach your app on your EC2 instance). What might be a possible reason?	"Missing security group or misconfigured one.\nFor example, if you go to your instances in the AWS console you might see that the instances under your NLB are in ""unhealthy status"" and if you didn't create a dedicated security group for your NLB, that means that the security group used is the one attached to the EC2 instances.\n\nGo to the security group of your instance(s) and enable the traffic that NLB should forward (e.g. TCP on port 80).\n\nRemember: ALB = Layer 7 (HTTP/HTTPS, path/host routing). NLB = Layer 4 (TCP/UDP, ultra-low latency). CLB = legacy, avoid for new deployments."	projects/knowledge/interview/aws/389-youve-created-a-network-load-balancer-but-it-doesn.txt
aws-networking/ca77deaaa0bf	aws-networking	medium	aws, route53	What are hosted zones?	A container that includes records for defining how to route traffic from a domain and its subdomains\n\nRemember: AWS networking troubleshooting flow: VPC Flow Logs show allowed/denied traffic. Reachability Analyzer tests paths. Security groups and NACLs are the most common culprits.	projects/knowledge/interview/aws/305-what-are-hosted-zones.txt
aws-networking/ca86aae379af	aws-networking	medium	aws, cloudfront	True or False? A user is not allowed to perform penetration testing on any of the AWS services	False. On some services, like EC2, CloudFront and RDS, penetration testing is allowed.\n\nRemember: AWS networking troubleshooting flow: VPC Flow Logs show allowed/denied traffic. Reachability Analyzer tests paths. Security groups and NACLs are the most common culprits.	projects/knowledge/interview/aws/225-true-or-false-a-user-is-not-allowed-to-perform-pen.txt
aws-networking/cf7a51268f10	aws-networking	hard	aws, transit-gateway, vpc	What is Transit VPC ?	A method to interconnect multiple VPCs, enabling connectivity between them.\n\nRemember: AWS networking troubleshooting flow: VPC Flow Logs show allowed/denied traffic. Reachability Analyzer tests paths. Security groups and NACLs are the most common culprits.	projects/knowledge/interview/aws/454-what-is-transit-vpc.txt
aws-networking/d07f068f9017	aws-networking	hard	aws, subnet	Kratos, your colleague, decided to use a subnet of /27 because he needs 29 IP addresses for EC2 instances. Is Kratos right?	No. Since AWS reserves 5 IP addresses for every subnet, Kratos will have 32-5=27 addresses and this is less than what he needs (29).\n\nIt's better if Kratos uses a subnet of size /26 but good luck telling him that.\n\nGotcha: always test networking changes in a non-production VPC first. A misconfigured route table or NACL can instantly isolate your entire application.	projects/knowledge/interview/aws/121-kratos-your-colleague-decided-to-use-a-subnet-of-2.txt
aws-networking/d0e52bfc4db1	aws-networking	medium	aws, elb	What are some use cases for using Network Load Balancer?	* TCP, UDP traffic\n* Extreme performance\n\nRemember: ALB = Layer 7 (HTTP/HTTPS, path/host routing). NLB = Layer 4 (TCP/UDP, ultra-low latency). CLB = legacy, avoid for new deployments.	projects/knowledge/interview/aws/193-what-are-some-use-cases-for-using-network-load-bal.txt
aws-networking/d16d699538bb	aws-networking	medium	aws, vpc	True or False? One or more VPCs can be attached to one Internet Gateway	False. Only one VPC can be attached to one IGW and vice versa\n\nRemember: AWS networking troubleshooting flow: VPC Flow Logs show allowed/denied traffic. Reachability Analyzer tests paths. Security groups and NACLs are the most common culprits.	projects/knowledge/interview/aws/108-true-or-false-one-or-more-vpcs-can-be-attached-to-.txt
aws-networking/d47c92496eef	aws-networking	medium	aws, elb	True or False? It's possible to enable sticky session for network load balancer so the same client is always redirected to the same instance	False. This is only supported in Classic Load Balancer and Application Load Balancer.\n\nRemember: ALB = Layer 7 (HTTP/HTTPS, path/host routing). NLB = Layer 4 (TCP/UDP, ultra-low latency). CLB = legacy, avoid for new deployments.	projects/knowledge/interview/aws/195-true-or-false-its-possible-to-enable-sticky-sessio.txt
aws-networking/d688abe2b297	aws-networking	medium	aws, security-group	What are Security Groups?	A security group acts as a virtual firewall that controls the traffic for one or more instances\nMore on this subject [here](https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/ec2-security-groups.html)\n\nRemember: AWS networking troubleshooting flow: VPC Flow Logs show allowed/denied traffic. Reachability Analyzer tests paths. Security groups and NACLs are the most common culprits.	projects/knowledge/interview/aws/068-what-are-security-groups.txt
aws-networking/d6ec6409724d	aws-networking	easy	aws, vpc	What is a VPC (Virtual Private Cloud) in AWS networking?	A logically isolated section of the AWS cloud where you can launch AWS resources in a virtual network that you define\nRead more about it [here](https://aws.amazon.com/vpc).\n\nRemember: AWS networking troubleshooting flow: VPC Flow Logs show allowed/denied traffic. Reachability Analyzer tests paths. Security groups and NACLs are the most common culprits.	projects/knowledge/interview/aws/101-what-is-vpc.txt
aws-networking/d785d16cbaee	aws-networking	easy	aws, route53	What is the difference between CNAME record and an Alias record?	CNAME is used for mapping one hostname to any other hostname while Alias is used to map an hostname to an AWS resource.\n\nIn addition, Alias work for both root domain (somedomain.com) and non-root domain, while CNAME works only with non-root domain (foo.somedomain.com)\n\nGotcha: always test networking changes in a non-production VPC first. A misconfigured route table or NACL can instantly isolate your entire application.	projects/knowledge/interview/aws/307-what-is-the-difference-between-cname-record-and-an.txt
aws-networking/d91ec14920aa	aws-networking	medium	aws, security-group	What allows you to control inbound and outbound instance traffic?	Security Groups\n\nGotcha: AWS networking issues are almost always security group or route table misconfigurations. Check these first before investigating application-level problems.\n\nRemember: AWS networking debug flow: Security Group -> NACL -> Route Table -> IGW/NAT -> DNS resolution. Work from most specific to broadest.	projects/knowledge/interview/aws/074-what-allows-you-to-control-inbound-and-outbound-in.txt
aws-networking/d9bf4a7c575b	aws-networking	medium	aws, route53	What are some use cases for weighted routing policy?	* Load balancing between regions\n* Testing new applications versions\n\nGotcha: AWS networking issues are almost always security group or route table misconfigurations. Check these first before investigating application-level problems.\n\nRemember: AWS networking debug flow: Security Group -> NACL -> Route Table -> IGW/NAT -> DNS resolution. Work from most specific to broadest.	projects/knowledge/interview/aws/316-what-are-some-use-cases-for-weighted-routing-polic.txt
aws-networking/dc5827e1a1f3	aws-networking	medium	aws, route53, vpc	What AWS uses the 5 reserved IP addresses for?	x.x.x.0 - network address\nx.x.x.1 - VPC router\nx.x.x.2 - DNS mapping\nx.x.x.3 - future use\nx.x.x.255 - broadcast address\n\nRemember: AWS networking troubleshooting flow: VPC Flow Logs show allowed/denied traffic. Reachability Analyzer tests paths. Security groups and NACLs are the most common culprits.	projects/knowledge/interview/aws/106-what-aws-uses-the-5-reserved-ip-addresses-for.txt
aws-networking/dd1297cbf846	aws-networking	easy	aws, global-accelerator	What is AWS Global Accelerator?	"Amazon definition: ""AWS Global Accelerator is a service that improves the availability and performance of your applications with local or global users...""\n\nLearn more [here](https://aws.amazon.com/global-accelerator)\n\nRemember: AWS networking troubleshooting flow: VPC Flow Logs show allowed/denied traffic. Reachability Analyzer tests paths. Security groups and NACLs are the most common culprits."	projects/knowledge/interview/aws/363-what-is-aws-global-accelerator.txt
aws-networking/dd5d9126016b	aws-networking	medium	aws, route53, vpc	What types of hosted zones are there?	* Public Hosted Zones - include records to specify how to route traffic on the internet\n* Private Hosted Zones - contain records that specify how you traffic within VPC(s)\n\nRemember: AWS networking troubleshooting flow: VPC Flow Logs show allowed/denied traffic. Reachability Analyzer tests paths. Security groups and NACLs are the most common culprits.	projects/knowledge/interview/aws/306-what-types-of-hosted-zones-are-there.txt
aws-networking/dfa4bf55342c	aws-networking	medium	aws, eni	True or False? ENI can be created independently of EC2 instances	True. They can be attached later on and on the fly (for failover purposes).\n\nRemember: AWS networking troubleshooting flow: VPC Flow Logs show allowed/denied traffic. Reachability Analyzer tests paths. Security groups and NACLs are the most common culprits.	projects/knowledge/interview/aws/095-true-or-false-eni-can-be-created-independently-of-.txt
aws-networking/e26d8abf277c	aws-networking	hard	aws, route53	Explain Route 53 Traffic Flow feature	It's a visual editor for managing complex routing decision trees. It allows you to simplify the process of managing records.\n\nConfiguration can be saved (as Traffic Flow Policy) and applied to different domains/hosted zones. In addition, it supports versioning\n\nRemember: Route 53 = AWS DNS. Supports A, AAAA, CNAME, MX, TXT, and alias records. Routing policies: Simple, Weighted, Latency, Failover, Geolocation.\n\nName origin: port 53 is the DNS port. Route 53 = DNS routing on port 53.	projects/knowledge/interview/aws/323-explain-route-53-traffic-flow-feature.txt
aws-networking/e36ef1ae146e	aws-networking	medium	aws, elb	What are some metrics/rules used for auto scaling	* Network In/Out\n* Number of requests on ELB per instance\n* Average CPU, RAM usage\n\nRemember: AWS networking troubleshooting flow: VPC Flow Logs show allowed/denied traffic. Reachability Analyzer tests paths. Security groups and NACLs are the most common culprits.	projects/knowledge/interview/aws/205-what-are-some-metricsrules-used-for-auto-scaling.txt
aws-networking/e5fe3ce91e37	aws-networking	easy	aws, vpc, networking	What is Amazon VPC and how does it provide network isolation in AWS?	Amazon Virtual Private Cloud (VPC) lets you provision a logically isolated virtual network in AWS where you can launch resources with your defined IP ranges, subnets, route tables, etc. It's like having your own network in the cloud, with full control over network settings.\n\nGotcha: always test networking changes in a non-production VPC first. A misconfigured route table or NACL can instantly isolate your entire application.	projects/knowledge/interview/aws/467-what-is-vpc.txt
aws-networking/e975514ee790	aws-networking	medium	aws, elastic-ip	True or False? An Elastic IP is free, as long it's not associated with an EC2 instance	False. An Elastic IP is free of charge as long as **it is ** associated with an EC2 instance. This instance should be running and should have only one Elastic IP.\n\nRemember: EIP = static public IPv4 address. Free when attached to a running instance. Charges apply when unattached (to discourage hoarding).	projects/knowledge/interview/aws/116-true-or-false-an-elastic-ip-is-free-as-long-its-no.txt
aws-networking/ea57fa183e7e	aws-networking	easy	aws, networking	"What is an ""Elastic IP""?"	A static public IP address that can be moved between instances.\n\nRemember: EIP = static public IPv4 address. Free when attached to a running instance. Charges apply when unattached (to discourage hoarding).	projects/knowledge/interview/aws/476-elastic-ip.txt
aws-networking/ed11b2a43dda	aws-networking	medium	aws, route53	What each Route 53 record contains?	* Domain/subdomain name (e.g. blipblop.com)\n* Value (e.g. 201.7.202.2)\n* Record type (e.g. A, AAAA, MX)\n* TTL: amount of time the  record is going to be cached\n* Routing Policy: how to respond to queries\n\nRemember: Route 53 = AWS DNS. Supports A, AAAA, CNAME, MX, TXT, and alias records. Routing policies: Simple, Weighted, Latency, Failover, Geolocation.\n\nName origin: port 53 is the DNS port. Route 53 = DNS routing on port 53.	projects/knowledge/interview/aws/303-what-each-route-53-record-contains.txt
aws-networking/f2830e085bd1	aws-networking	medium	aws, nacl, security-group, subnet	Explain Security Groups and Network ACLs	* NACL - security layer on the subnet level.\n* Security Group - security layer on the instance level.\n\nRead more about it [here](https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/ec2-security-groups.html) and [here](https://docs.aws.amazon.com/vpc/latest/userguide/VPC_SecurityGroups.html)\n\nRemember: NACLs are stateless (rules for inbound AND outbound needed), evaluated by rule number (lowest first), allow AND deny rules. Security groups are stateful, allow-only.	projects/knowledge/interview/aws/118-explain-security-groups-and-network-acls.txt
aws-networking/f2c0e1bbcc8c	aws-networking	hard	aws, route53	What happens when you set all records to weight 0 when using Weighted routing policy?	All records are used equally.\n\nGotcha: AWS networking issues are almost always security group or route table misconfigurations. Check these first before investigating application-level problems.\n\nRemember: AWS networking debug flow: Security Group -> NACL -> Route Table -> IGW/NAT -> DNS resolution. Work from most specific to broadest.	projects/knowledge/interview/aws/320-what-happens-when-you-set-all-records-to-weight-0-.txt
aws-networking/f50ce40d8624	aws-networking	hard	aws, elb	True or False? For network load balancer, cross zone load balancing is always on and can't be disabled	False. It's disabled by default\n\nRemember: ALB = Layer 7 (HTTP/HTTPS, path/host routing). NLB = Layer 4 (TCP/UDP, ultra-low latency). CLB = legacy, avoid for new deployments.	projects/knowledge/interview/aws/197-true-or-false-for-network-load-balancer-cross-zone.txt
aws-networking/f5965fe42478	aws-networking	easy	aws, vpc	"When creating a new VPC, there is an option called ""Tenancy"". What is it used for?"	[AWS Docs](https://docs.aws.amazon.com/vpc/latest/userguide/create-vpc.html): `Tenancy` option defines if EC2 instances that you launch into the VPC will run on hardware that's shared with other AWS accounts or on hardware that's dedicated for your use only.\n\nGotcha: always test networking changes in a non-production VPC first. A misconfigured route table or NACL can instantly isolate your entire application.	projects/knowledge/interview/aws/112-when-creating-a-new-vpc-there-is-an-option-called-.txt
aws-networking/f95a8711a4e9	aws-networking	medium	aws, elb	Explain Cross Zone Load Balancing	With cross zone load balancing, traffic distributed evenly across all (registered) instances in all the availability zones.\n\nRemember: AWS networking troubleshooting flow: VPC Flow Logs show allowed/denied traffic. Reachability Analyzer tests paths. Security groups and NACLs are the most common culprits.	projects/knowledge/interview/aws/196-explain-cross-zone-load-balancing.txt
aws-networking/fb0ac5900045	aws-networking	medium	aws, eni, vpc	Name at least three attributes the Elastic Network Interfaces (ENI) can include	1. One public IPv4 address\n2. Mac Address\n3. A primary private IPv4 address (from the address range of your VPC)\n\nRemember: AWS networking troubleshooting flow: VPC Flow Logs show allowed/denied traffic. Reachability Analyzer tests paths. Security groups and NACLs are the most common culprits.	projects/knowledge/interview/aws/093-name-at-least-three-attributes-the-elastic-network.txt
aws-networking/fd7128dd8206	aws-networking	medium	aws, elb	What are the supported target groups for network load balancer?	* EC2 instance\n* IP addresses\n* Application Load Balancer\n\nRemember: ALB = Layer 7 (HTTP/HTTPS, path/host routing). NLB = Layer 4 (TCP/UDP, ultra-low latency). CLB = legacy, avoid for new deployments.	projects/knowledge/interview/aws/190-what-are-the-supported-target-groups-for-network-l.txt
aws-networking/fe9b621a574a	aws-networking	easy	aws, security-group	What is the advantage of referencing security groups from a given security group?	Imagine you have an instance referencing two security groups, allowing to get inbound traffic from them. \nNow imagine you have two instances, each using one of the security groups referenced in the instance we've just mentioned. This means you can get traffic from these two instances because they use security groups which referenced in the instance mentioned at the beginning. No need to use IPs.\n\nGotcha: always test networking changes in a non-production VPC first. A misconfigured route table or NACL can instantly isolate your entire application.	projects/knowledge/interview/aws/071-what-is-the-advantage-of-referencing-security-grou.txt

<!-- wiki:related:start -->
---

## Wiki Navigation

### Related Content

- [AWS Networking](../../../../library/topics/aws-networking/index.md) (Topic Pack, L1) — AWS Networking

<!-- wiki:related:end -->
