Domain 3: Cloud Technology and Services

AWS Networking Services (Task 3.5)

Amazon VPC Subnets Route Tables Internet Gateway NAT Gateway Amazon Route 53 Amazon CloudFront AWS Global Accelerator AWS VPN AWS Direct Connect
Exam Tip
VPC = your private network (pick a CIDR, divide into subnets). Public subnet = has route to Internet Gateway; private subnet = no direct internet (NAT for outbound). Route 53 = DNS (registration + routing policies). CloudFront = CDN caching. Global Accelerator = anycast IP routing, NOT a cache. VPN = encrypted over internet; Direct Connect = private dedicated line.

AWS Networking Services

Source: https://docs.aws.amazon.com/whitepapers/latest/aws-overview/networking-services.html

Networking questions are routing questions: what path may traffic take, and who may initiate it? Seniors design subnets by WHO NEEDS TO REACH WHAT — public for internet-facing tiers, private for compute, isolated for data.

Amazon VPC — Your Virtual Network

Brief: A logically isolated network you define inside a Region: you choose a CIDR block (e.g., 10.0.0.0/16), divide it into subnets (each living entirely in ONE AZ), and control paths with route tables.

How it works: The VPC router moves traffic per route table rules — the most important line in any table is the default route: if 0.0.0.0/0 points at an Internet Gateway (IGW), the subnet is PUBLIC; if it points at a NAT Gateway, the subnet is PRIVATE (outbound-only internet); if there is no default route at all, the subnet is ISOLATED (data tiers). A NAT Gateway lives IN a public subnet, holds an Elastic IP, and translates private instances' outbound connections — they can download patches but cannot be reached inbound. Bigger structures: Virtual Private Gateway (VPN endpoint), Transit Gateway (hub-and-spoke for many VPCs).

Example: a database in a subnet whose route table has NO 0.0.0.0/0 route: it cannot be reached from the internet AND cannot reach out — patches arrive via VPC endpoints (S3/DynamoDB) or a controlled proxy.

Real use-case: The standard three-tier VPC: per AZ, a public subnet (ALB + NAT GW), a private subnet (EC2 ASG, route to NAT), and an isolated subnet (RDS — local routes only). A pen test finds zero inbound paths to the database from outside the VPC — by construction, not by firewall rules someone might forget.

Gotchas & interview notes: "public subnet" is not a checkbox — it is purely the route to an IGW. AWS reserves 5 IPs per subnet (.0 network, .1 router, .2 DNS, .3 future, .255 broadcast) — a /28 subnet has only 11 usable IPs. NAT Gateway costs ~$32/month + data processing — one per AZ for HA, but right-size for dev accounts. VPC CIDRs must not overlap with anything you will ever peer or connect to — plan address space FIRST.

Amazon Route 53 — DNS

Brief: AWS's highly available DNS service: registers domains and answers lookups according to routing policies.

Policy Behavior
Simple Standard answer
Weighted Split traffic by percentage (canary testing)
Latency Answer with the lowest-latency Region for the user
Failover Primary healthy? Answer primary : secondary (DR)
Geolocation Answer based on user location (EU users → EU site)
Multi-value answer Return several healthy records (simple client-side failover)


How it works: Policies combine with health checks — Route 53 probes endpoints (or CloudWatch alarms) and routes away from unhealthy ones. Weighted supports canary deploys (95/5 splits); latency uses measured network distance (not geography — a Delhi user may route to Singapore if that path is faster).

Real use-case: DR for a website — Route 53 health-checks the primary ALB; on failure it fails over DNS to the standby Region's ALB. Note: DNS TTLs mean clients cache answers; aggressive failover uses low TTLs (30–60s) in advance.

Gotchas & interview notes: Route 53 is 100% SLA-available DNS — but it is NOT a load balancer (multi-value is "poor man's failover," not health-checked balancing). Geolocation answers WHERE the user IS; latency answers which endpoint is FASTEST — the exam swaps these deliberately.

Edge / Content Delivery: CloudFront vs Global Accelerator

  • Amazon CloudFront (CDN): caches content at 400+ edge locations — static assets, video streams, API acceleration; integrates WAF/Shield, signed URLs/cookies for private content, and origin failover.
  • AWS Global Accelerator: static anycast IPs; user traffic enters the AWS backbone at the nearest edge and routes to your healthy Regional endpoints. It routes; it does not cache.
  • AWS Site-to-Site VPN: IPsec tunnels (two, for redundancy) over the internet; minutes to set up; encrypted but internet-latency.
  • AWS Direct Connect: private dedicated circuit (1/10/100 Gbps) from your data center to AWS; consistent latency; no internet exposure; takes weeks to provision.
  • Common pairing: "needs private connectivity AND a backup path" → Direct Connect primary + VPN failover (BGP handles the switch).
Real use-case: A global API needs consistent latency and instant regional failover (no cacheable responses) → Global Accelerator over the ALBs in two Regions. The same company's marketing site (cacheable HTML/images) rides CloudFront — different problems, different edges.

Gotchas & interview notes: CloudFront = cache + TLS + WAF at the edge; Global Accelerator = anycast routing over the backbone. "Improve availability for non-HTTP traffic" or "static IPs" → Global Accelerator. CloudFront signed URLs are the answer for "restrict private S3 content through the CDN."

Connectivity Options

  • Amazon CloudFront (CDN): caches content at 400+ edge locations — static assets, video streams, API acceleration; integrates WAF/Shield, signed URLs/cookies for private content, and origin failover.
  • AWS Global Accelerator: static anycast IPs; user traffic enters the AWS backbone at the nearest edge and routes to your healthy Regional endpoints. It routes; it does not cache.
  • AWS Site-to-Site VPN: IPsec tunnels (two, for redundancy) over the internet; minutes to set up; encrypted but internet-latency.
  • AWS Direct Connect: private dedicated circuit (1/10/100 Gbps) from your data center to AWS; consistent latency; no internet exposure; takes weeks to provision.
  • Common pairing: "needs private connectivity AND a backup path" → Direct Connect primary + VPN failover (BGP handles the switch).
Gotchas & interview notes: VPN now (instant) vs DX later (weeks) when a scenario needs immediate connectivity. DX is private but not encrypted by default — add MACsec or IPsec-over-DX for regulated traffic.

Worked Example: Standard Three-Tier VPC

VPC 10.0.0.0/16 in us-east-1, 3 AZs. Per AZ: public subnet (ALB, NAT Gateway) with route → IGW; private subnet (EC2 ASG) with route → NAT (outbound only); isolated subnet (RDS — local routes only). Route 53 latency-routing sends users to the nearest Region's CloudFront distribution, which fronts the ALB. Office admins reach the VPC over a Site-to-Site VPN. Every element answers "who may initiate contact with whom" — the entire security posture is visible in the route tables.