Wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

AWS Solutions Architect Associate - Networking and VPC

Total questions: 23

Worksheet time: 12mins

Name
Class
Date
1.

What does the CIDR 10.0.4.0/28 correspond to?

a)

10.0.4.0 to 10.0.4.15

b)

10.0.4.0 to 10.0.32.0

c)

10.0.4.0 to 10.0.4.28

d)

10.0.0.0 to 10.0.16.0

2.

You have a corporate network of size 10.0.0.0/8 and a satellite office of size 192.168.0.0/16. Which CIDR is acceptable for your AWS VPC if you plan on connecting your networks later on?

a)

172.16.0.0/12

b)

172.16.0.0/16

c)

10.0.16.0/16

d)

192.168.4.0/18

3.

You plan on creating a subnet and want it to have at least capacity for 28 EC2 instances. What's the minimum size you need to have for your subnet?

a)

/28

b)

/27

c)

/26

d)

/25

4.

Security Groups operate at the ________ level while NACLs operate at the ________ level.

a)

EC2 instance, Subnet

b)

Subnet, EC2 instance

5.

You have attached an Internet Gateway to your VPC, but your EC2 instances still don't have access to the Internet. What is NOT a possible issue?

a)

Route Tables are missing entries

b)

The EC2 instances don't have public IPs

c)

The Security Group does not allow traffic in

d)

The NACL does not allow traffic out

6.

You would like to provide Internet access to your EC2 instances in private subnets with IPv4 while making sure this solution requires the least amount of administration and scales seamlessly. What should you use?

a)

NAT Instances with Source/Destination Check flag off

b)

Egress Only Internet Gateway

c)

NAT Gateway

7.

VPC Peering has been enabled between VPC A and VPC B, and the route tables have been updated for VPC A. But, the EC2 instances cannot communicate. What is the likely issue?

a)

Check the NACL

b)

Check the Route Tables in VPC B

c)

Check the EC2 instance attached Security Groups

d)

Check if DNS Resolution is enabled

8.

You have set up a Direct Connect connection between your corporate data center and your VPC A in your AWS account. You also need to access VPC B in another AWS region from your corporate datacenter. What should you do?

a)

Enable VPC Peering

b)

Use a Customer Gateway

c)

Use a Direct Connect Gateway

d)

Set up a NAT Gateway

9.

When using VPC Endpoints, what are the only two AWS services that have a Gateway Endpoint available?

a)

Amazon S3 & Amazon SQS

b)

Amazon SQS & DynamoDB

c)

Amazon S3 & DynamoDB

10.

AWS reserves 5 IP addresses each time you create a new subnet in a VPC. When you create a subnet with CIDR 10.0.0.0/24, the following IP addresses are reserved, EXCEPT:

a)

10.0.0.1

b)

10.0.0.2

c)

10.0.0.3

d)

10.0.0.4

11.

You have 3 VPCs A, B, and C. You want to establish a VPC Peering connection between all the 3 VPCs. What should you do?

a)

VPC Peering supports Transitive Peering, so you need to establish 2 VPC Peering connections (A-B, B-C)

b)

Establish 3 VPC Peering connections (A-B, A-C, B-C)

12.

How can you capture information about IP traffic inside your VPCs?

a)

Enable VPC Flow Logs

b)

Enable VPC Traffic Mirroring

c)

Enable CloudWatch Traffic Logs

13.

If you want a 500 Mb/s Direct Connect connection between your corporate data center and AWS, you would choose a ________ connection.

a)

Dedicated

b)

Hosted

14.

When you set up an AWS Site-to-Site VPN connection between your corporate on-premises datacenter and VPCs in AWS Cloud, what are the two major components you want to configure for this connection?

a)

Customer Gateway and NAT Gateway

b)

Internet Gateway and Customer Gateway

c)

Virtual Private Gateway and Internet Gateway

d)

Virtual Private Gateway and Customer Gateway

15.

Your company has several on-premises sites across the USA. These sites are currently linked using private connections, but your private connections provider has been recently quite unstable, making your IT architecture partially offline. You would like to create a backup connection that will use the public Internet to link your on-premises sites, that you can failover in case of issues with your provider. What do you recommend?

a)

VPC Peering

b)

AWS VPN CloudHub

c)

Direct Connect

d)

AWS PrivateLink

16.

You need to set up a dedicated connection between your on-premises corporate datacenter and AWS Cloud. This connection must be private, consistent, and traffic must not travel through the Internet. Which AWS service should you use?

a)

Site-to-Site VPN

b)

AWS PrivateLink

c)

AWS Direct Connect

d)

Amazon EventBridge

17.

Using a Direct Connect connection, you can access both public and private AWS resources.

a)

True

b)

False

18.

You want to scale up an AWS Site-to-Site VPN connection throughput, established between your on-premises data and AWS Cloud, beyond a single IPsec tunnel's maximum limit of 1.25 Gbps. What should you do?

a)

Use 2 Virtual Private Gateways

b)

Use Direct Connect Gateway

c)

Use Transit Gateway

19.

You have a VPC in your AWS account that runs in a dual-stack mode. You are continuously trying to launch an EC2 instance, but it fails. After further investigation, you have found that you are no longer have IPv4 addresses available. What should you do?

a)

Modify your VPC to run in IPv6 mode only

b)

Modify your VPC to run in IPv4 mode only

c)

Add an additional IPv4 CIDR to your VPC

20.

A web application backend is hosted on EC2 instances in private subnets fronted by an Application Load Balancer in public subnets. There is a requirement to give some of the developers access to the backend EC2 instances but without exposing the backend EC2 instances to the Internet. You have created a bastion host EC2 instance in the public subnet and configured the backend EC2 instances Security Group to allow traffic from the bastion host. Which of the following is the best configuration for bastion host Security Group to make it secure?

a)

Allow traffic only on port 80 from the company's public CIDR

b)

Allow traffic only on port 22 from the company's public CIDR

c)

Allow traffic only on port 22 from the company's private CIDR

d)

Allow traffic only on port 80 from the company's private CIDR

21.

A company has set up a Direct Connect connection between their corporate data center to AWS. There is a requirement to prepare a cost-effective secure backup connection in case there are issues with this Direct Connect connection. What is the most cost effective and secure solution you recommend?

a)

Setup another Direct Connect connection to the same AWS region

b)

Setup another Direct Connect connection to a different AWS region

c)

Setup a Site-to-Site VPN connection as a backup

22.

Which AWS service allows you to protect and control traffic in your VPC from layer 3 to layer 7?

a)

AWS Network Firewall

b)

Amazon GuardDuty

c)

Amazon Inspector

d)

Amazon Shield

23.

A web application hosted on a fleet of EC2 instances managed by an Auto Scaling Group. You are exposing this application through an Application Load Balancer. Both the EC2 instances and the ALB are deployed on a VPC with the following CIDR 192.168.0.0/18. How do you configure the EC2 instances' security group to ensure only the ALB can access them on port 80?

a)

Add an Inbound Rule with port 80 and 0.0.0.0/0 as the source

b)

Add an Inbound Rule with port 80 and 192.168.0.0/18 as the source

c)

Add an Inbound Rule with port 80 and the ALB's Security Group as the source

d)

Load an SSL certificate on the ALB