[{"data":1,"prerenderedAt":781},["ShallowReactive",2],{"practiceExams":3,"practice-exam-questions-\u002Fpractice-exams\u002Faws-certified-advanced-networking-specialty-ans-c01\u002Fquestions":79},[4,15,23,32,42,51,61,70],{"id":5,"slug":6,"description":7,"questionCount":8,"isActive":9,"datePublicModified":10,"difficulty":11},9,"aws-certified-data-engineer-associate-dea-c01","Prepare for your AWS Certified Data Engineer - Associate exam with our practice exam simulator. Featuring real exam scenarios, detailed explanations, and instant feedback to boost your confidence and success rate.",3312,true,"2024-11-13T00:00:00.000Z",{"title":12,"subtitle":13,"slug":6,"coverImageUrl":14},"AWS Certified Data Engineer - Associate","DEA-C01","",{"id":16,"slug":17,"description":18,"questionCount":19,"isActive":9,"datePublicModified":10,"difficulty":20},10,"aws-certified-advanced-networking-specialty-ans-c01","The AWS Certified Advanced Networking - Specialty practice exam simulates the real test, offering scenario-based questions that assess your ability to design, implement, and troubleshoot complex AWS networking solutions. ",3531,{"title":21,"subtitle":22,"slug":17,"coverImageUrl":14},"AWS Certified Advanced Networking - Specialty","ANS-C01",{"id":24,"slug":25,"description":26,"questionCount":27,"isActive":9,"datePublicModified":28,"difficulty":29},8,"aws-certified-devops-engineer-professional-dop-c02","Boost your readiness for the AWS Certified DevOps Engineer - Professional (DOP-C02) exam with our practice exam simulator. Featuring realistic questions and detailed explanations, it helps you identify knowledge gaps and improve your skills.",2775,"2024-08-08T00:00:00.000Z",{"title":30,"subtitle":31,"slug":25,"coverImageUrl":14},"AWS Certified DevOps Engineer - Professional","DOP-C02",{"id":33,"slug":34,"description":35,"questionCount":36,"isActive":9,"datePublicModified":37,"difficulty":38},1,"aws-certified-solutions-architect-associate-saa-c03","Unlock your potential with the AWS Certified Solutions Architect - Associate Practice Exam Simulator. This comprehensive tool is designed to prepare you thoroughly and assess your readiness for the most sought-after AWS associate certification.",3813,"2024-06-13T00:00:00.000Z",{"title":39,"subtitle":40,"slug":34,"coverImageUrl":41},"AWS Certified Solutions Architect - Associate","SAA-C03","\u002Fimages\u002Fdifficulties\u002Faws-certified-solutions-architect-associatesaa-c03\u002Fcovers\u002Faws-SAA-C03.png",{"id":43,"slug":44,"description":45,"questionCount":46,"isActive":9,"datePublicModified":37,"difficulty":47},5,"aws-certified-cloud-practitioner-clf-c02","Master your AWS Certified Cloud Practitioner exam with our Practice Exam Simulator. Prepare effectively and assess your readiness with realistic practice exams designed to mirror the most popular official AWS exam.",4227,{"title":48,"subtitle":49,"slug":44,"coverImageUrl":50},"AWS Certified Cloud Practitioner","CLF-C02","\u002Fimages\u002Fdifficulties\u002Faws-certified-cloud-practitionerclf-c02\u002Fcovers\u002Faws-CLF-C02.png",{"id":52,"slug":53,"description":54,"questionCount":55,"isActive":9,"datePublicModified":56,"difficulty":57},6,"aws-certified-solutions-architect-professional-sap-c02","Elevate your career with the AWS Certified Solutions Architect - Professional Exam Simulator. Get ready to ace the most popular Professional AWS exam with our realistic practice exams. Assess your readiness, boost your confidence, and ensure your success.",8203,"2024-06-06T00:00:00.000Z",{"title":58,"subtitle":59,"slug":53,"coverImageUrl":60},"AWS Certified Solutions Architect - Professional","SAP-C02","\u002Fimages\u002Fdifficulties\u002Faws-certified-solutions-architect-professionalsap-c02\u002Fcovers\u002Faws-SAP-C02.png",{"id":62,"slug":63,"description":64,"questionCount":65,"isActive":9,"datePublicModified":56,"difficulty":66},7,"aws-certified-security-specialty-scs-c02","Advance your career in cloud cybersecurity with the AWS Certified Security - Specialty Exam Simulator! Tailored for professionals, this tool offers realistic practice exams to mirror the official exam.",5439,{"title":67,"subtitle":68,"slug":63,"coverImageUrl":69},"AWS Certified Security - Specialty","SCS-C02","\u002Fimages\u002Fdifficulties\u002Faws-certified-security-specialtyscs-c02\u002Fcovers\u002Faws_SCS_c02.png",{"id":71,"slug":72,"description":73,"questionCount":74,"isActive":9,"datePublicModified":56,"difficulty":75},4,"aws-certified-developer-associate-dva-c02","Unlock your potential as a software developer with the AWS Certified Developer - Associate Exam Simulator! Prepare thoroughly with realistic practice exams designed to mirror the official exam.",3787,{"title":76,"subtitle":77,"slug":72,"coverImageUrl":78},"AWS Certified Developer - Associate","DVA-C02","\u002Fimages\u002Fdifficulties\u002Faws-certified-developer-associatedva-c02\u002Fcovers\u002Faws-DVA-C02.png",{"id":16,"slug":17,"description":18,"content":80,"formalQuestionCount":81,"minQuestionCount":33,"maxQuestionCount":82,"formalTimeLimitCount":83,"minTimeLimitCount":33,"maxTimeLimitCount":84,"passingScore":82,"questionCount":19,"isActive":9,"dateCreated":85,"dateModified":86,"datePublicModified":10,"difficulty":87,"tags":780},"\u003Cp>\u003Cspan class=\"text-big\">The AWS Certified Advanced Networking - Specialty (ANS-C01) certification is a highly specialized credential aimed at professionals with advanced networking skills and extensive experience in designing and implementing AWS and hybrid IT network architectures at scale. The exam tests a deep understanding of a broad range of AWS networking services and concepts, along with the ability to design, develop, and deploy complex cloud-based solutions using the Amazon Web Services platform.\u003C\u002Fspan>\u003C\u002Fp>\u003Cp>&nbsp;\u003C\u002Fp>\u003Cp>\u003Cspan class=\"text-big\">A significant portion of the exam focuses on networking fundamentals and concepts, requiring candidates to have a strong grasp of the OSI model and how various networking protocols map to it. Understanding IP addressing, particularly in IPv4 and IPv6, is crucial, including subnetting, CIDR (Classless Inter-Domain Routing), and the differences between these IP versions. Additionally, knowledge of routing and switching is vital, with an emphasis on static and dynamic routing protocols such as RIP, OSPF, and BGP, as well as concepts like route tables, network address translation (NAT), and switching mechanisms.\u003C\u002Fspan>\u003C\u002Fp>\u003Cp>&nbsp;\u003C\u002Fp>\u003Cp>\u003Cspan class=\"text-big\">The exam extensively covers AWS networking services, beginning with Amazon VPC (Virtual Private Cloud), a core service that allows the creation of isolated networks within AWS. Candidates are expected to understand VPC components, including subnets, route tables, security groups, and Network ACLs (NACLs). Additionally, the exam delves into more advanced VPC features like VPC Peering, Transit Gateway, and VPC endpoints. AWS Direct Connect is another critical service, providing a dedicated network connection from an on-premises environment to AWS, and the exam assesses knowledge of its setup, configuration, and use cases.\u003C\u002Fspan>\u003C\u002Fp>\u003Cp>&nbsp;\u003C\u002Fp>\u003Cp>\u003Cspan class=\"text-big\">AWS VPN is also a key service, with the exam focusing on both Site-to-Site VPN and Client VPN, including setup, encryption standards, and integration with VPCs and on-premises networks. Elastic Load Balancing (ELB) is another important topic, where candidates must have detailed knowledge of application, network, and gateway load balancers, including their use cases and configuration. The exam also evaluates understanding of AWS Global Accelerator, which is used to improve global application performance by leveraging AWS’s global network infrastructure.\u003C\u002Fspan>\u003C\u002Fp>\u003Cp>&nbsp;\u003C\u002Fp>\u003Cp>\u003Cspan class=\"text-big\">Amazon Route 53, AWS’s DNS service, plays a significant role in the exam, with candidates needing to demonstrate knowledge of routing policies such as latency-based, geolocation, and failover, as well as domain registration and health checks. AWS Transit Gateway, which allows the interconnection of VPCs and on-premises networks via a central hub, is another critical topic, including concepts like route propagation, attachments, and segmentation. Amazon CloudFront, a content delivery network (CDN) service, is also covered, with a focus on edge locations, distribution types, and caching strategies.\u003C\u002Fspan>\u003C\u002Fp>\u003Cp>&nbsp;\u003C\u002Fp>\u003Cp>\u003Cspan class=\"text-big\">Security is a major theme in the exam, with an emphasis on securing AWS networking components using security groups, NACLs, AWS Web Application Firewall (WAF), and Shield (DDoS protection). Candidates must also understand encryption, both in-transit and at-rest, as well as AWS compliance frameworks like PCI DSS, HIPAA, and GDPR, and how they impact network design. Disaster recovery and high availability strategies are also tested, including Multi-AZ and Multi-Region architectures, failover mechanisms, and data replication to ensure network resilience and data redundancy.\u003C\u002Fspan>\u003C\u002Fp>\u003Cp>&nbsp;\u003C\u002Fp>\u003Cp>\u003Cspan class=\"text-big\">The exam also tests knowledge of network automation and monitoring. Candidates need to be proficient in using AWS CloudFormation, AWS CLI, and SDKs for automating network deployments, as well as third-party automation tools like Terraform. Monitoring and troubleshooting are equally important, with expertise in using Amazon CloudWatch, VPC Flow Logs, AWS Config, and AWS CloudTrail to monitor, troubleshoot, and audit network activity. The exam may present scenarios requiring the identification and resolution of network performance issues.\u003C\u002Fspan>\u003C\u002Fp>\u003Cp>&nbsp;\u003C\u002Fp>\u003Cp>\u003Cspan class=\"text-big\">Hybrid networking and multi-account environments are also key areas of focus. Candidates must understand hybrid cloud architectures, including connecting on-premises networks with AWS using services like AWS Direct Connect and VPN. The exam also includes scenarios involving multiple AWS accounts, VPC peering, and shared services, and requires knowledge of AWS Organizations and best practices for managing networking across multiple AWS accounts, including the use of centralized logging and monitoring, shared VPCs, and resource access management.\u003C\u002Fspan>\u003C\u002Fp>\u003Cp>&nbsp;\u003C\u002Fp>\u003Cp>\u003Cspan class=\"text-big\">The \u003Cstrong>AWS Certified Advanced Networking - Specialty (ANS-C01)\u003C\u002Fstrong> exam is known for its difficulty. It requires a deep understanding of AWS networking services and the ability to apply this knowledge to complex, real-world scenarios. The depth of knowledge required is significant, with the exam testing advanced networking concepts that go beyond basic AWS networking. The questions are often scenario-based, requiring candidates to design or troubleshoot a network architecture, which tests both knowledge and problem-solving skills. The breadth of services covered is also extensive, requiring candidates to understand how different AWS services integrate with each other, adding to the challenge. Additionally, the time pressure of the exam, with its detailed and time-consuming questions, makes effective time management crucial.\u003C\u002Fspan>\u003C\u002Fp>\u003Cp>&nbsp;\u003C\u002Fp>\u003Cp>\u003Cspan class=\"text-big\">Overall, the AWS Certified Advanced Networking - Specialty (ANS-C01) certification is an excellent credential for professionals seeking to demonstrate their expertise in AWS networking. It validates a candidate’s ability to design, deploy, and maintain complex network architectures on AWS, making it a valuable certification for network engineers, architects, and systems administrators. However, due to its difficulty, it requires thorough preparation and substantial practical experience with AWS networking services.\u003C\u002Fspan>\u003C\u002Fp>",65,75,170,200,"2024-08-28T09:20:54.226Z","2024-11-13T11:21:18.000Z",{"id":24,"title":21,"subtitle":22,"rating":43,"slug":17,"guideUrl":88,"categories":89,"services":534},null,[90,254,364,449],{"id":91,"title":92,"subtitle":93,"description":94,"content":88,"coverImageUrl":14,"weight":95,"subcategories":96},33,"Network Design","Domain 1","This domain focuses on designing complex network architectures that incorporate edge services, DNS solutions, load balancing, logging, monitoring, and routing strategies to optimize performance and connectivity for AWS and hybrid environments.",30,[97,124,150,176,202,228],{"id":98,"title":99,"subtitle":100,"description":88,"questions":101},134,"Design a solution that incorporates edge network services to optimize user performance and traffic management for global architectures","Task 1.1",[102],{"id":103,"subcategoryId":98,"content":104,"hint":105,"isPublic":9,"answers":106},35058,"Your company is expanding its customer base globally and needs to ensure that users from different regions have optimal performance when accessing your web application. You currently use Elastic Load Balancing (ELB) to distribute traffic among your application servers. To further improve performance and traffic management, you are considering integrating additional AWS services. Which solution would best suit this requirement?","Consider a service that works well with ELB to improve global performance and simplify traffic management.",[107,112,116,120],{"id":108,"questionId":103,"content":109,"hint":110,"isCorrect":111},159134,"Deploy additional Application Load Balancers in each region.","While deploying additional ALBs in each region can help distribute the traffic more efficiently, it requires more complex management and does not leverage global edge networks for caching content.",false,{"id":113,"questionId":103,"content":114,"hint":115,"isCorrect":111},159135,"Use an Auto Scaling group with spot instances.","Auto Scaling with spot instances can help with cost management and scaling based on load but does not directly help with optimizing content delivery for a global audience.",{"id":117,"questionId":103,"content":118,"hint":119,"isCorrect":9},159136,"Use Amazon CloudFront with your Elastic Load Balancer.","Amazon CloudFront is a Content Delivery Network (CDN) that works seamlessly with ELB to cache content close to the users and reduces latency, improving performance for a global audience.",{"id":121,"questionId":103,"content":122,"hint":123,"isCorrect":111},159137,"Use Amazon Route 53 with latency-based routing.","While Amazon Route 53 with latency-based routing can route users to the closest region, it does not cache content like CloudFront, so it doesn't optimize performance in the same way.",{"id":125,"title":126,"subtitle":127,"description":88,"questions":128},135,"Design DNS solutions that meet public, private, and hybrid requirements","Task 1.2",[129],{"id":130,"subcategoryId":125,"content":131,"hint":132,"isPublic":9,"answers":133},35167,"You are working as a network architect for a company that has recently migrated its web applications to AWS. They are aiming to improve the performance and security of their global web traffic. The company has registered its domain through Amazon Route 53 and is using Amazon CloudFront as a Content Delivery Network (CDN) to cache and serve their web content closer to end-users across the globe. They want to make sure that the DNS records are optimally configured to integrate with CloudFront, ensuring both availability and security. Which DNS configuration should you choose in Route 53 to best meet these requirements?","Consider how Amazon CloudFront interacts with DNS records and the importance of correct aliasing for optimal performance and security.",[134,138,142,146],{"id":135,"questionId":130,"content":136,"hint":137,"isCorrect":111},159570,"Configure a 'TXT' record with the CloudFront distribution domain name.","TXT records are typically used for arbitrary text data, such as verification information for domain ownership or email sender policies. They do not play any role in routing web traffic to a CloudFront distribution.",{"id":139,"questionId":130,"content":140,"hint":141,"isCorrect":111},159571,"Use an 'MX' record that points to the CloudFront distribution domain name.","An MX record is used for directing mail servers and is irrelevant to web traffic and CDN integration. Using an MX record here would not help in routing web requests to CloudFront.",{"id":143,"questionId":130,"content":144,"hint":145,"isCorrect":9},159572,"Use an 'A' record with a CloudFront distribution domain name as an alias target.","Using an 'A' record with an alias to the CloudFront distribution domain provides the benefit of an edge-optimized service, reducing latency and improving load times while also maintaining Route 53's DNS failover and health check features.",{"id":147,"questionId":130,"content":148,"hint":149,"isCorrect":111},159573,"Use a 'CNAME' record pointing to the CloudFront distribution domain name.","While a CNAME record could technically work, it is not as efficient as an 'A' record with aliasing in Route 53. A CNAME cannot be used at the root domain level and lacks some of the advanced features provided by Route 53 when A records are used, such as DNS failover and health checks.",{"id":151,"title":152,"subtitle":153,"description":88,"questions":154},136,"Design solutions that integrate load balancing to meet high availability, scalability, and security requirements","Task 1.3",[155],{"id":156,"subcategoryId":151,"content":157,"hint":158,"isPublic":9,"answers":159},35287,"Your company has an e-commerce application hosted on a fleet of EC2 instances in a multi-AZ architecture. It has been reported that the application occasionally experiences high latency during peak traffic times. To address this issue, your manager asks you to design a solution that ensures high availability and scalability. You decide to integrate an AWS Network Load Balancer (NLB) into the architecture. Considering the need for high availability, scalability, and security, which of the following configurations is the most appropriate?\n\n1. Associate the NLB with a target group that contains the existing EC2 instances.\n2. Enable cross-zone load balancing in the NLB settings.\n3. Ensure that health checks are configured to monitor the application endpoints.\n4. Use an Auto Scaling Group to dynamically adjust the number of EC2 instances based on traffic.\n\nWhich of the following steps should NOT be included in your design?","Consider the primary functionalities and capabilities provided by a Network Load Balancer (NLB) and how it balances traffic across instances in multiple Availability Zones.",[160,164,168,172],{"id":161,"questionId":156,"content":162,"hint":163,"isCorrect":111},160050,"Ensure that health checks are configured to monitor the application endpoints.","Configuring health checks is essential for ensuring that traffic is only routed to healthy instances, thus maintaining high availability.",{"id":165,"questionId":156,"content":166,"hint":167,"isCorrect":111},160051,"Use an Auto Scaling Group to dynamically adjust the number of EC2 instances based on traffic.","An Auto Scaling Group is crucial for automatically adjusting the number of instances in response to traffic demand, ensuring scalability and availability.",{"id":169,"questionId":156,"content":170,"hint":171,"isCorrect":9},160052,"Enable cross-zone load balancing in the NLB settings.","Network Load Balancers do not support cross-zone load balancing natively. Enabling cross-zone load balancing is more relevant for Application Load Balancers (ALBs). For NLB, traffic is distributed per Availability Zone.",{"id":173,"questionId":156,"content":174,"hint":175,"isCorrect":111},160053,"Associate the NLB with a target group that contains the existing EC2 instances.","Associating the NLB with a target group containing the existing EC2 instances is necessary to ensure that traffic is properly distributed among the instances.",{"id":177,"title":178,"subtitle":179,"description":88,"questions":180},137,"Define logging and monitoring requirements across AWS and hybrid networks","Task 1.4",[181],{"id":182,"subcategoryId":177,"content":183,"hint":184,"isPublic":9,"answers":185},35364,"You have been tasked with designing a network monitoring and logging solution for a hybrid cloud architecture that spans both AWS and on-premises resources. Your organization is keen to capture baseline network performance metrics for their AWS resources and requires real-time insights to identify potential bottlenecks. Which AWS service would you use to achieve this, and how would you implement it considering the need to monitor both AWS and hybrid networks?","Focus on services that can provide monitoring and logging capabilities not only for AWS components but also for on-premises resources.",[186,190,194,198],{"id":187,"questionId":182,"content":188,"hint":189,"isCorrect":111},160358,"Use AWS X-Ray to monitor network performance and capture logs from both AWS and on-premises resources.","AWS X-Ray is used for distributed tracing of requests across microservices and is primarily focused on application-level monitoring rather than network performance metrics. It does not provide the comprehensive network monitoring and logging required for capturing baseline network performance.",{"id":191,"questionId":182,"content":192,"hint":193,"isCorrect":9},160359,"Use Amazon CloudWatch to capture network performance metrics and set up CloudWatch Logs to collect logs from both AWS and on-premises resources.","Amazon CloudWatch is designed to monitor AWS resources and applications and can be extended to include on-premises resources using the CloudWatch Agent. It provides robust performance metrics, dashboards, and the ability to set alarms and visualize data, which is essential for capturing baseline network performance.",{"id":195,"questionId":182,"content":196,"hint":197,"isCorrect":111},160360,"Deploy Amazon Inspector to capture and monitor network performance metrics for AWS and on-premises resources.","Amazon Inspector is a security assessment service that inspects AWS resources for vulnerabilities and deviations from best practices. It is not designed for ongoing performance monitoring or logging of network metrics.",{"id":199,"questionId":182,"content":200,"hint":201,"isCorrect":111},160361,"Use AWS CloudTrail to monitor and capture network performance metrics.","AWS CloudTrail is primarily used for auditing API calls and user activity rather than capturing network performance metrics. It records AWS API requests and does not provide performance monitoring or logging functionality.",{"id":203,"title":204,"subtitle":205,"description":88,"questions":206},138,"Design a routing strategy and connectivity architecture between on-premises networks and the AWS Cloud","Task 1.5",[207],{"id":208,"subcategoryId":203,"content":209,"hint":210,"isPublic":9,"answers":211},35455,"A large enterprise is looking to expand its network infrastructure to the AWS Cloud using a software-defined wide area network (SD-WAN) approach. They currently have an on-premises data center with several branch offices connected through an MPLS network. They want to leverage AWS services to provide reliable, secure, and scalable connectivity between their on-premises network and their VPCs in AWS. They are considering using AWS Transit Gateway and AWS VPN in combination with their SD-WAN for optimal performance. Given these requirements, which architecture should they implement?","Consider the role of AWS Transit Gateway and how it can be leveraged with existing SD-WAN infrastructure along with AWS VPN for secure connections.",[212,216,220,224],{"id":213,"questionId":208,"content":214,"hint":215,"isCorrect":111},160722,"Directly connect all branch offices to VPCs using separate VPN connections for each.","While technically possible, this solution is not scalable or efficient for a large enterprise with numerous branch offices. Managing multiple VPN connections directly to VPCs can become complex and cumbersome.",{"id":217,"questionId":208,"content":218,"hint":219,"isCorrect":111},160723,"Use AWS Site-to-Site VPN to connect the on-premises data center and retransmit traffic to branch offices through the MPLS network.","While feasible, this solution does not leverage the benefits of SD-WAN integration and reduces the overall efficiency and flexibility in managing traffic between branch offices and AWS. It would also place additional load on the on-premises data center.",{"id":221,"questionId":208,"content":222,"hint":223,"isCorrect":111},160724,"Set up Direct Connect for each branch office to connect them directly to AWS.","AWS Direct Connect is generally more suitable for high-bandwidth and low-latency requirements but would be cost-prohibitive and complex to manage for numerous branch offices distributed geographically.",{"id":225,"questionId":208,"content":226,"hint":227,"isCorrect":9},160725,"Use AWS Transit Gateway with Transit Gateway Connect, integrate SD-WAN appliances at the branch offices with the Transit Gateway using VPN attachments, and route traffic through the Transit Gateway to VPCs.","This approach leverages the AWS Transit Gateway with Transit Gateway Connect, providing a scalable and reliable way to integrate SD-WAN connections with the AWS environment. The use of VPN attachments ensures secure connectivity from the branch offices to the Transit Gateway, facilitating optimal routing to VPCs.",{"id":229,"title":230,"subtitle":231,"description":88,"questions":232},139,"Design a routing strategy and connectivity architecture that include multiple AWS accounts, AWS Regions, and VPCs to support different connectivity patterns","Task 1.6",[233],{"id":234,"subcategoryId":229,"content":235,"hint":236,"isPublic":9,"answers":237},35514,"As a senior network architect for a growing company, you've been tasked with designing a routing strategy and connectivity architecture that connects multiple AWS accounts, AWS regions, and VPCs. During the planning phase, you realize that there are IP address overlaps between different VPCs in different AWS accounts. You need to ensure seamless connectivity across these VPCs without conflicts. Which service and setup would be the most appropriate to manage these IP overlaps effectively?","Consider the AWS services that allow routing to handle IP address overlaps effectively while providing the necessary connectivity across multiple AWS accounts and regions.",[238,242,246,250],{"id":239,"questionId":234,"content":240,"hint":241,"isCorrect":111},160958,"Use AWS Direct Connect for direct private connections between overlapping VPCs in different AWS accounts.","AWS Direct Connect provides dedicated network connections to AWS but does not inherently resolve IP address overlaps between VPCs. It's primarily for establishing high-bandwidth, low-latency connectivity rather than addressing overlapping IP concerns.",{"id":243,"questionId":234,"content":244,"hint":245,"isCorrect":111},160959,"Enable VPC Peering between all VPCs in different AWS accounts and route traffic through a central VPC.","While VPC Peering allows routing between VPCs, it does not handle IP address overlaps. Peering does not provide NAT capabilities to manage overlapping CIDR blocks, leading to potential IP address conflicts.",{"id":247,"questionId":234,"content":248,"hint":249,"isCorrect":9},160960,"Use AWS Transit Gateway with Network Address Translation (NAT) for handling overlapping IP spaces within your interconnected VPCs.","AWS Transit Gateway can act as a central hub for interconnecting multiple VPCs across accounts and regions. By using NAT with the Transit Gateway, you can translate IP addresses and resolve conflicts arising from IP overlaps.",{"id":251,"questionId":234,"content":252,"hint":253,"isCorrect":111},160961,"Utilize AWS PrivateLink to expose services across overlapping VPCs in different accounts.","AWS PrivateLink enables access to services through private IP addresses within VPCs but does not facilitate general routing and NAT for managing IP overlaps. It is more suited for exposing services privately rather than managing complex VPC-to-VPC connectivity with overlapping IPs.",{"id":255,"title":256,"subtitle":257,"description":88,"content":88,"coverImageUrl":14,"weight":258,"subcategories":259},34,"Network Implementation","Domain 2",26,[260,286,312,338],{"id":261,"title":262,"subtitle":263,"description":88,"questions":264},140,"Implement routing and connectivity between on-premises networks and the AWS Cloud","Task 2.1",[265],{"id":266,"subcategoryId":261,"content":267,"hint":268,"isPublic":9,"answers":269},35701,"Your company, ABC Corp, has recently deployed an AWS Direct Connect connection between its on-premises data center and its VPC in AWS. As part of the implementation phase, you need to test and validate the connectivity between these environments. However, you realize that the on-premises network cannot reach your resources in the VPC. Which of the following steps should you take to identify and resolve the connectivity issue?","Consider the common troubleshooting steps you would take in networking, such as verifying BGP session status, route propagation, and security setups.",[270,274,278,282],{"id":271,"questionId":266,"content":272,"hint":273,"isCorrect":111},161706,"Verify that the IAM roles are correctly configured for the AWS Direct Connect link.","IAM roles are not involved in the establishment or management of the AWS Direct Connect link. This option does not address the core issues of network routing or connectivity.",{"id":275,"questionId":266,"content":276,"hint":277,"isCorrect":111},161707,"Ensure that SSL certificates are installed on both on-premises and VPC resources.","SSL certificates are used for secure communication but are not related to establishing basic connectivity or routing between the on-premises network and the VPC.",{"id":279,"questionId":266,"content":280,"hint":281,"isCorrect":9},161708,"Check if the BGP session is established and the routes are correctly advertised.","If the BGP (Border Gateway Protocol) session is not established or routes are not correctly advertised, the on-premises environment will not be able to reach resources in the VPC. Ensuring the BGP session is up and routes are correct is crucial for connectivity.",{"id":283,"questionId":266,"content":284,"hint":285,"isCorrect":111},161709,"Check if the AWS Direct Connect usage quota is exceeded in your account.","While quotas can limit network capacity, exceeding a quota typically affects throughput rather than completely blocking connectivity. The issue described is more likely related to routing or session establishment rather than quota limits.",{"id":287,"title":288,"subtitle":289,"description":88,"questions":290},141,"Implement routing and connectivity across multiple AWS accounts, Regions, and VPCs to support different connectivity patterns","Task 2.2",[291],{"id":292,"subcategoryId":287,"content":293,"hint":294,"isPublic":9,"answers":295},35844,"You are a network engineer for a multinational company that has a complex AWS environment with multiple AWS accounts, Regions, and Virtual Private Clouds (VPCs). Your company is using AWS Transit Gateway to facilitate the network connectivity among different VPCs. Recently, the security team has requested enhanced network monitoring and logging to ensure compliance with regulatory requirements and to identify any potential security threats. Which of the following solutions should you implement to achieve robust network monitoring and logging for your AWS Transit Gateway setup?","Think about AWS services that provide monitoring and logging capabilities specifically for network traffic and consider how they can be integrated with AWS Transit Gateway.",[296,300,304,308],{"id":297,"questionId":292,"content":298,"hint":299,"isCorrect":111},162278,"Enable AWS CloudTrail for the Transit Gateway and set up Amazon SNS notifications for API calls.","AWS CloudTrail is primarily used for logging API calls made in your AWS account but it does not log network traffic directly. Setting up SNS notifications for API calls won't provide the required network monitoring and logging capabilities.",{"id":301,"questionId":292,"content":302,"hint":303,"isCorrect":111},162279,"Setup AWS Direct Connect with AWS Transit Gateway to monitor and log all traffic.","While AWS Direct Connect can provide a dedicated connection from your premises to AWS, it does not inherently provide network monitoring and logging capabilities. You would still need a solution like VPC Flow Logs for detailed network traffic monitoring.",{"id":305,"questionId":292,"content":306,"hint":307,"isCorrect":9},162280,"Enable VPC Flow Logs for each VPC connected to the Transit Gateway and use Amazon CloudWatch Logs to analyze network traffic.","Enabling VPC Flow Logs for each VPC connected to the Transit Gateway allows you to capture detailed information about the IP traffic going to and from network interfaces in your VPCs. Integrating these logs with Amazon CloudWatch Logs enables robust monitoring and the ability to perform traffic analysis.",{"id":309,"questionId":292,"content":310,"hint":311,"isCorrect":111},162281,"Use AWS Config to track changes to the Transit Gateway and store configurations in an S3 bucket.","AWS Config tracks configuration changes to AWS resources but it does not provide detailed network traffic monitoring and logging. It’s useful for auditing AWS configurations but not for analyzing network traffic.",{"id":313,"title":314,"subtitle":315,"description":88,"questions":316},142,"Implement complex hybrid and multi-account DNS architectures","Task 2.3",[317],{"id":318,"subcategoryId":313,"content":319,"hint":320,"isPublic":9,"answers":321},35983,"You are managing a multi-account AWS environment and need to configure DNS monitoring and logging for a hybrid architecture involving Amazon Route 53 and Amazon VPCs. Your architecture includes a primary on-premises data center connected to your AWS environment via Direct Connect. You aim to log all DNS queries that originate from both the on-premises and AWS VPC environments for security and troubleshooting purposes. What is the BEST approach to achieve comprehensive DNS query logging in this scenario?","Consider solutions that can capture DNS activity from both AWS and on-premises environments and can integrate with AWS monitoring and logging services.",[322,326,330,334],{"id":323,"questionId":318,"content":324,"hint":325,"isCorrect":111},162834,"Install and configure an EC2 instance as a DNS logging server within your VPC.","While this approach may capture DNS logs within the VPC, it would not automatically cover DNS queries originating from the on-premises data center or between VPCs without additional complex routing and logging configurations.",{"id":327,"questionId":318,"content":328,"hint":329,"isCorrect":9},162835,"Enable Route 53 Resolver query logging and configure VPC Flow Logs for the respective VPCs.","Enabling Route 53 Resolver query logging will capture DNS queries that pass through Route 53, including those from on-premises via Direct Connect. VPC Flow Logs can log network traffic, including DNS queries within the VPCs.",{"id":331,"questionId":318,"content":332,"hint":333,"isCorrect":111},162836,"Enable AWS Config to monitor configurations and changes in Route 53.","AWS Config is used to track configuration changes and compliance but does not have the capability to log individual DNS queries.",{"id":335,"questionId":318,"content":336,"hint":337,"isCorrect":111},162837,"Use AWS CloudTrail to log and monitor all DNS queries.","AWS CloudTrail primarily logs API calls and is not designed for logging DNS queries. It can provide some information on DNS-related API activities but not the DNS queries themselves.",{"id":339,"title":340,"subtitle":341,"description":88,"questions":342},143,"Automate and configure network infrastructure","Task 2.4",[343],{"id":344,"subcategoryId":339,"content":345,"hint":346,"isPublic":9,"answers":347},36063,"John, a network engineer at a growing tech company, is tasked with optimizing the cloud network resources using Infrastructure as Code (IaC). He needs to automate the configuration of AWS networking components such as VPC, subnets, and security groups. John decides to use Terraform for this purpose. How should John proceed with automating the creation and management of these AWS resources using Terraform?","Consider the key functionalities of Terraform in managing and automating AWS network resources and configurations.",[348,352,356,360],{"id":349,"questionId":344,"content":350,"hint":351,"isCorrect":111},163154,"John should use AWS CloudFormation to write and execute templates instead of Terraform.","AWS CloudFormation is another IaC service but it's not the one John decided to use. The question explicitly states John is using Terraform.",{"id":353,"questionId":344,"content":354,"hint":355,"isCorrect":9},163155,"John should create and execute Terraform configuration files that define the desired AWS network resources, and use the 'terraform apply' command to provision these resources.","Terraform configuration files (written in HashiCorp Configuration Language - HCL) allow you to define infrastructure resources declaratively. The 'terraform apply' command will then execute these configurations, creating and managing the specified AWS resources as defined.",{"id":357,"questionId":344,"content":358,"hint":359,"isCorrect":111},163156,"John should manually create AWS resources in the Console and then export the configurations to Terraform.","This approach is not in line with the idea of automating the resource management process with IaC. Terraform is used to automate the deployment, not just to manage existing manually created resources.",{"id":361,"questionId":344,"content":362,"hint":363,"isCorrect":111},163157,"John should write Terraform configurations but use the 'terraform import' command exclusively to manage existing AWS resources.","'terraform import' is used to import existing resources into Terraform management, not to automate new resource creation. For a new infrastructure setup, the 'terraform apply' command should be used to create resources based on configuration files.",{"id":365,"title":366,"subtitle":367,"description":368,"content":88,"coverImageUrl":14,"weight":369,"subcategories":370},35,"Network Management and Operation","Domain 3","This domain emphasizes the ongoing management, optimization, and troubleshooting of AWS and hybrid networks. It includes maintaining routing, monitoring traffic, optimizing network performance, and ensuring cost-effective and reliable connectivity.",20,[371,397,423],{"id":372,"title":373,"subtitle":374,"description":88,"questions":375},144,"Maintain routing and connectivity on AWS and hybrid networks","Task 3.1",[376],{"id":377,"subcategoryId":372,"content":378,"hint":379,"isPublic":9,"answers":380},36163,"Your company has a hybrid network infrastructure onboard AWS leveraging a Transit Gateway to interconnect multiple VPCs and on-premises data centers. You're tasked with optimizing the routing configurations to enhance network performance. Currently, different static and dynamic routing protocols are used throughout the network setup. However, the internal networking team has noticed overlapping CIDR blocks affecting existing route summarizations.\n\nWhat should you do to optimize the routing in your AWS environment while handling the CIDR overlap?","Consider ways to effectively manage CIDR overlaps and ensure efficient route summarization within AWS.",[381,385,389,393],{"id":382,"questionId":377,"content":383,"hint":384,"isCorrect":111},163554,"Disable the static routing protocols and rely entirely on Transit Gateway's default routes.","Disabling static routing protocols and relying entirely on default routes ignores the complexity and specifics of route management and does not address the CIDR overlap issue.",{"id":386,"questionId":377,"content":387,"hint":388,"isCorrect":9},163555,"Consolidate the overlapping CIDR blocks and reconfigure the Transit Gateway route table to avoid conflicts.","Consolidating overlapping CIDR blocks and reconfiguring the Transit Gateway route table helps to resolve conflicts and allows for proper route summarization, improving the overall routing efficiency in your hybrid network.",{"id":390,"questionId":377,"content":391,"hint":392,"isCorrect":111},163556,"Use only dynamic routing protocols like BGP to handle the overlaps automatically.","Dynamic routing protocols like BGP can handle some aspects of route changes but will not resolve CIDR overlap issues by themselves. Configuration adjustments at the route table level are also necessary.",{"id":394,"questionId":377,"content":395,"hint":396,"isCorrect":111},163557,"Add more specific routes to the Transit Gateway route table to avoid the CIDR overlap.","Adding more specific routes without correcting the CIDR conflicts can lead to more complexity and potential routing issues rather than optimizing the routing and solving the overlap problem.",{"id":398,"title":399,"subtitle":400,"description":88,"questions":401},145,"Monitor and analyze network traffic to troubleshoot and optimize connectivity patterns","Task 3.2",[402],{"id":403,"subcategoryId":398,"content":404,"hint":405,"isPublic":9,"answers":406},36271,"You are a network engineer responsible for managing an Amazon VPC that supports a critical application. Your application is experiencing intermittent connectivity issues when communicating with an on-premises data center over a VPN. You suspect there might be a problem with packet size mismatches. How would you identify and resolve this issue to restore network connectivity?","Think about tools and configurations within AWS that can help you analyze and adjust packet sizes between VPC and on-premises data center.",[407,411,415,419],{"id":408,"questionId":403,"content":409,"hint":410,"isCorrect":111},163986,"Adjust the security group settings to allow all traffic types.","Security group settings manage access and permissions but do not resolve packet size mismatch problems.",{"id":412,"questionId":403,"content":413,"hint":414,"isCorrect":111},163987,"Use AWS CloudFormation to redeploy the VPC resources.","Redeploying the VPC resources does not address the specific issue of packet size mismatches.",{"id":416,"questionId":403,"content":417,"hint":418,"isCorrect":9},163988,"Use VPC Flow Logs to capture and analyze the traffic, and adjust the Maximum Transmission Unit (MTU) settings on the VPN connection.","VPC Flow Logs will help you identify any dropped packets or issues related to packet sizes. Adjusting the MTU settings can ensure compatibility between the VPC and the on-premises network.",{"id":420,"questionId":403,"content":421,"hint":422,"isCorrect":111},163989,"Enable AWS Direct Connect for more stable connectivity.","While AWS Direct Connect can offer more stable and consistent connectivity than a VPN, it does not directly address packet size mismatch issues.",{"id":424,"title":425,"subtitle":426,"description":88,"questions":427},146,"Optimize AWS networks for performance, reliability, and cost- effectiveness","Task 3.3",[428],{"id":429,"subcategoryId":424,"content":430,"hint":431,"isPublic":9,"answers":432},36464,"You are a network engineer for a global media streaming company that aims to optimize its content delivery network (CDN) to enhance performance and availability. Your company currently uses AWS Direct Connect for a dedicated network connection from your on-premises data center to AWS. However, users in different regions report varying network performance. To improve the latency and availability of your streaming services, you decide to implement AWS Global Accelerator. What combination of AWS services and configurations would best optimize network connectivity for your users?","Think about how the combination of AWS Direct Connect and Global Accelerator can work together to improve latency and availability for global users.",[433,437,441,445],{"id":434,"questionId":429,"content":435,"hint":436,"isCorrect":111},164758,"Use AWS Global Accelerator in combination with a VPN over the internet for cost-saving, as opposed to AWS Direct Connect.","While using a VPN could reduce costs, it would not provide the dedicated bandwidth and low latency of AWS Direct Connect, leading to potential performance issues, especially for a high-demand service like media streaming.",{"id":438,"questionId":429,"content":439,"hint":440,"isCorrect":9},164759,"Use AWS Global Accelerator to provide static IP addresses for your endpoints across AWS regions, and route traffic through AWS Direct Connect to reduce latency.","AWS Global Accelerator uses static IP addresses and optimizes routing to the closest edge location, reducing latency and improving availability. Combining this with AWS Direct Connect ensures dedicated, low-latency connections, providing an overall optimized network performance.",{"id":442,"questionId":429,"content":443,"hint":444,"isCorrect":111},164760,"Implement AWS Global Accelerator for intra-region traffic only and rely on AWS Direct Connect for inter-region traffic.","AWS Global Accelerator is designed to improve internet traffic across global regions. Using it only for intra-region traffic limits its potential, as combining it with AWS Direct Connect for both intra and inter-region traffic optimizes performance and availability most effectively.",{"id":446,"questionId":429,"content":447,"hint":448,"isCorrect":111},164761,"Discontinue using AWS Direct Connect and solely rely on AWS Global Accelerator for improved performance and availability.","While AWS Global Accelerator significantly improves availability and optimizes routing, discontinuing AWS Direct Connect would remove the low-latency, dedicated connection to AWS, which could negatively impact performance.",{"id":450,"title":451,"subtitle":452,"description":453,"content":88,"coverImageUrl":14,"weight":454,"subcategories":455},36,"Network Security, Compliance, and Governance","Domain 4","This domain addresses the implementation and maintenance of network security features, compliance needs, and data confidentiality. It also includes validating security through monitoring, logging, and auditing in AWS environments.",24,[456,482,508],{"id":457,"title":458,"subtitle":459,"description":88,"questions":460},147,"Implement and maintain network features to meet security and compliance needs and requirements","Task 4.1",[461],{"id":462,"subcategoryId":457,"content":463,"hint":464,"isPublic":9,"answers":465},36573,"Jane is a DevOps engineer at a FinTech company. Recently, her team has been tasked with improving the security incident reporting and alerting mechanisms to ensure they meet strict compliance requirements for financial services. They want to ensure any configuration changes in their network environment that could impact security are automatically detected and reported. They decide to use AWS Config for this purpose. Which of the following steps should Jane take to achieve this goal?","Think about how AWS Config can be used in conjunction with other AWS services to create comprehensive security incident reporting and alerting.",[466,470,474,478],{"id":467,"questionId":462,"content":468,"hint":469,"isCorrect":111},165194,"Use AWS WAF to monitor and block suspicious network traffic and integrate it with AWS Config for real-time incident reporting.","AWS WAF is designed to monitor and block web application threats but does not cover comprehensive network configuration monitoring. Its integration with AWS Config wouldn't provide a holistic approach to security incident reporting and alerting for configuration changes.",{"id":471,"questionId":462,"content":472,"hint":473,"isCorrect":9},165195,"Set up AWS Config rules to monitor critical AWS resource configurations and configure Amazon SNS to alert the security team when a rule is violated.","AWS Config rules allow you to monitor AWS resource configurations according to your security compliance policies. Amazon SNS can be used to send notifications and alerts when these rules are breached, ensuring that the security team is immediately informed of any issues.",{"id":475,"questionId":462,"content":476,"hint":477,"isCorrect":111},165196,"Deploy AWS Shield Advanced to protect against DDoS attacks and configure AWS Config to periodically generate compliance snapshots.","AWS Shield Advanced is specifically for DDoS protection and doesn't address configuration monitoring. Moreover, compliance snapshots do not provide real-time alerting, which is crucial for immediate incident response.",{"id":479,"questionId":462,"content":480,"hint":481,"isCorrect":111},165197,"Use AWS CloudTrail to monitor network configuration changes and manually create weekly reports to share with the security team.","While AWS CloudTrail logs can be used to track changes, manually creating reports does not provide real-time alerting and lacks automation, which is essential for rapid incident response.",{"id":483,"title":484,"subtitle":485,"description":88,"questions":486},148,"Validate and audit security by using network monitoring and logging services","Task 4.2",[487],{"id":488,"subcategoryId":483,"content":489,"hint":490,"isPublic":9,"answers":491},36690,"You have recently taken on the role of Network Architect at a mid-sized company utilizing AWS. The company has several AWS accounts and wants to implement a network audit strategy to validate and audit security group configurations. During an audit, it was discovered that some instances have overly permissive security group rules that allow inbound traffic from any IP address. Your task is to ensure that all security groups are as restrictive as possible while still allowing necessary traffic. Which of the following AWS tools or approaches would best help you automate the process of identifying and remediating overly permissive security group rules across multiple accounts and VPCs?","Consider AWS services designed for security auditing and compliance, especially those that can manage settings across multiple AWS accounts and environments.",[492,496,500,504],{"id":493,"questionId":488,"content":494,"hint":495,"isCorrect":9},165662,"AWS Firewall Manager","AWS Firewall Manager is a security management tool that can be used to centrally configure and manage firewall rules across multiple accounts and VPCs. It enables you to enforce a single set of security policies across your organization.",{"id":497,"questionId":488,"content":498,"hint":499,"isCorrect":111},165663,"AWS CloudTrail","AWS CloudTrail captures API calls and activity on your account but is not primarily designed to manage or automate the remediation of security group rules.",{"id":501,"questionId":488,"content":502,"hint":503,"isCorrect":111},165664,"AWS Trusted Advisor","AWS Trusted Advisor offers recommendations to optimize your AWS environment, including security settings. However, it does not provide automation for correcting overly permissive security groups across multiple accounts.",{"id":505,"questionId":488,"content":506,"hint":507,"isCorrect":111},165665,"AWS Config","AWS Config can monitor and provide compliance reports regarding your security groups. However, it does not natively provide automated remediation capabilities across multiple accounts.",{"id":509,"title":510,"subtitle":511,"description":88,"questions":512},149,"Implement and maintain confidentiality of data and communications of the network","Task 4.3",[513],{"id":514,"subcategoryId":509,"content":515,"hint":516,"isPublic":9,"answers":517},36784,"You are an AWS Certified Advanced Networking Specialist tasked with enhancing the security of a client's web application. Your client has expressed concerns about the privacy and integrity of DNS queries generated by their application. They are also worried about potential web exploits and malicious traffic targeting their service. You decide to implement secure DNS communications alongside other security measures. Which configuration steps should you take to achieve these objectives using AWS WAF and DNS security protocols?","Consider both DNS communication security measures and web application security measures offered by AWS services.",[518,522,526,530],{"id":519,"questionId":514,"content":520,"hint":521,"isCorrect":111},166038,"Implement DNSSEC to secure DNS queries and deploy AWS Shield to protect against DDoS attacks.","DNSSEC secures DNS queries by preventing DNS spoofing but does not encrypt DNS traffic. AWS Shield provides DDoS protection but does not filter HTTP\u002FHTTPS requests or protect against web application vulnerabilities.",{"id":523,"questionId":514,"content":524,"hint":525,"isCorrect":111},166039,"Use CloudFront with AWS WAF, but do not configure any specific DNS security measures.","While CloudFront and AWS WAF together provide comprehensive protection at the application layer and edge locations, they do not specifically address the privacy and integrity of DNS queries.",{"id":527,"questionId":514,"content":528,"hint":529,"isCorrect":9},166040,"Implement DNS over HTTPS (DoH) or DNS over TLS (DoT) for securing DNS queries and deploy AWS WAF to filter and monitor HTTP\u002FHTTPS requests to your web application.","Combining DNS over HTTPS (DoH) or DNS over TLS (DoT) for securing DNS queries ensures privacy and integrity of DNS traffic. AWS WAF provides protection against common web exploits and malicious traffic, safeguarding the web application.",{"id":531,"questionId":514,"content":532,"hint":533,"isCorrect":111},166041,"Only deploy AWS WAF to monitor and filter HTTP\u002FHTTPS requests to your web application.","While AWS WAF is essential for protection against application layer threats, it does not address the confidentiality and integrity of DNS communications.",[535,541,547,552,557,562,567,573,579,585,591,597,603,608,614,620,625,631,637,643,649,654,660,666,672,678,684,690,696,702,707,712,717,721,726,732,738,744,750,756,762,768,774],{"id":536,"title":537,"description":538,"slug":539,"coverImageUrl":540},21,"Amazon EventBridge","Amazon EventBridge is a serverless event bus service provided by AWS that enables applications to communicate with each other using events, facilitating the building of event-driven architectures.","amazon-eventbridge","\u002Fimages\u002Fprovider-services\u002Famazon-eventbridge\u002Fcovers\u002FArch_Amazon-EventBridge_64.png",{"id":542,"title":543,"description":544,"slug":545,"coverImageUrl":546},23,"Amazon Simple Notification Service (Amazon SNS)","Amazon Simple Notification Service (Amazon SNS) is a fully managed messaging service for both application-to-application (A2A) and application-to-person (A2P) communication, enabling the delivery of messages or notifications to subscribers or other applications.","amazon-simple-notification-service-(amazon-sns)","\u002Fimages\u002Fprovider-services\u002Famazon-simple-notification-service-(amazon-sns)\u002Fcovers\u002FArch_Amazon-Simple-Notification-Service_64.png",{"id":454,"title":548,"description":549,"slug":550,"coverImageUrl":551},"Amazon Simple Queue Service (Amazon SQS)","Amazon Simple Queue Service (Amazon SQS) is a scalable, fully managed message queuing service that enables the decoupling and scaling of microservices, distributed systems, and serverless applications.","amazon-simple-queue-service-(amazon-sqs)","\u002Fimages\u002Fprovider-services\u002Famazon-simple-queue-service-(amazon-sqs)\u002Fcovers\u002FArch_Amazon-Simple-Queue-Service_64.png",{"id":95,"title":553,"description":554,"slug":555,"coverImageUrl":556},"AWS Cost Explorer","AWS Cost Explorer is a web service that allows users to visualize, understand, and manage their Amazon Web Services (AWS) costs and usage over time through detailed reports and analytics.","aws-cost-explorer","\u002Fimages\u002Fprovider-services\u002Faws-cost-explorer\u002Fcovers\u002FArch_AWS-Cost-Explorer_64.png",{"id":255,"title":558,"description":559,"slug":560,"coverImageUrl":561},"Amazon EC2","Amazon EC2 (Elastic Compute Cloud) is a web service that provides resizable compute capacity in the cloud, allowing users to run and manage virtual servers.","amazon-ec2","\u002Fimages\u002Fprovider-services\u002Famazon-ec2\u002Fcovers\u002FArch_Amazon-EC2_64.png",{"id":450,"title":563,"description":564,"slug":565,"coverImageUrl":566},"Amazon EC2 Auto Scaling","Amazon EC2 Auto Scaling is a service that automatically adjusts the number of Amazon EC2 instances in your deployment to maintain performance and minimize costs based on defined conditions such as traffic or resource utilization.","amazon-ec2-auto-scaling","\u002Fimages\u002Fprovider-services\u002Famazon-ec2-auto-scaling\u002Fcovers\u002FArch_Amazon-EC2-Auto-Scaling_64.png",{"id":568,"title":569,"description":570,"slug":571,"coverImageUrl":572},48,"Amazon Elastic Container Registry (Amazon ECR)","Amazon Elastic Container Registry (Amazon ECR) is a fully managed Docker container registry that makes it easy for developers to store, manage, and deploy Docker container images.","amazon-elastic-container-registry-(amazon-ecr)","\u002Fimages\u002Fprovider-services\u002Famazon-elastic-container-registry-(amazon-ecr)\u002Fcovers\u002FArch_Amazon-Elastic-Container-Registry_64.png",{"id":574,"title":575,"description":576,"slug":577,"coverImageUrl":578},54,"Amazon Elastic Container Service (Amazon ECS)","Amazon Elastic Container Service (Amazon ECS) is a fully managed container orchestration service that allows you to run and scale containerized applications on AWS.","amazon-elastic-container-service-(amazon-ecs)","\u002Fimages\u002Fprovider-services\u002Famazon-elastic-container-service-(amazon-ecs)\u002Fcovers\u002FArch_Amazon-Elastic-Container-Service_64.png",{"id":580,"title":581,"description":582,"slug":583,"coverImageUrl":584},55,"Amazon Elastic Kubernetes Service (Amazon EKS)","Amazon Elastic Kubernetes Service (Amazon EKS) is a managed service that makes it easy to deploy, manage, and scale containerized applications using Kubernetes on AWS.","amazon-elastic-kubernetes-service-(amazon-eks)","\u002Fimages\u002Fprovider-services\u002Famazon-elastic-kubernetes-service-(amazon-eks)\u002Fcovers\u002FArch_Amazon-Elastic-Kubernetes-Service_64.png",{"id":586,"title":587,"description":588,"slug":589,"coverImageUrl":590},73,"Amazon API Gateway","Amazon API Gateway is a fully managed service that makes it easy for developers to create, publish, maintain, monitor, and secure APIs at any scale, providing a way to facilitate communication between software applications through web services.","amazon-api-gateway","\u002Fimages\u002Fprovider-services\u002Famazon-api-gateway\u002Fcovers\u002FArch_Amazon-API-Gateway_64.png",{"id":592,"title":593,"description":594,"slug":595,"coverImageUrl":596},88,"AWS Auto Scaling","AWS Auto Scaling is a service provided by Amazon Web Services that automatically adjusts the number of computing resources in response to demand, ensuring that your application maintains consistent performance at the lowest possible cost.","aws-auto-scaling","\u002Fimages\u002Fprovider-services\u002Faws-auto-scaling\u002Fcovers\u002FArch_AWS-Auto-Scaling_64.png",{"id":598,"title":599,"description":600,"slug":601,"coverImageUrl":602},92,"AWS CloudFormation","AWS CloudFormation is a service that enables users to model, provision, and manage AWS and third-party application resources in a safe, repeatable, and efficient manner using templates.","aws-cloudformation","\u002Fimages\u002Fprovider-services\u002Faws-cloudformation\u002Fcovers\u002FArch_AWS-CloudFormation_64.png",{"id":604,"title":498,"description":605,"slug":606,"coverImageUrl":607},93,"AWS CloudTrail is a service that provides a comprehensive log of user activity and API usage across the AWS infrastructure, enabling security monitoring, compliance auditing, and operational troubleshooting.","aws-cloudtrail","\u002Fimages\u002Fprovider-services\u002Faws-cloudtrail\u002Fcovers\u002FArch_AWS-CloudTrail_64.png",{"id":609,"title":610,"description":611,"slug":612,"coverImageUrl":613},95,"Amazon CloudWatch","Amazon CloudWatch is a monitoring and observability service offered by Amazon Web Services (AWS) that provides data and actionable insights to monitor applications, respond to system-wide performance changes, optimize resource utilization, and get a unified view of operational health.","amazon-cloudwatch","\u002Fimages\u002Fprovider-services\u002Famazon-cloudwatch\u002Fcovers\u002FArch_Amazon-CloudWatch_64.png",{"id":615,"title":616,"description":617,"slug":618,"coverImageUrl":619},96,"AWS Command Line Interface (AWS CLI)","The AWS Command Line Interface (AWS CLI) is a unified tool that allows you to manage and automate AWS services directly from the terminal or command prompt.","aws-command-line-interface-(aws-cli)","\u002Fimages\u002Fprovider-services\u002Faws-command-line-interface-(aws-cli)\u002Fcovers\u002FArch_AWS-Command-Line-Interface_64.png",{"id":621,"title":506,"description":622,"slug":623,"coverImageUrl":624},98,"AWS Config is a service that enables you to assess, audit, and evaluate the configurations of your AWS resources, providing a detailed view of their compliance with the configurations specified by your internal guidelines and regulatory standards.","aws-config","\u002Fimages\u002Fprovider-services\u002Faws-config\u002Fcovers\u002FArch_AWS-Config_64.png",{"id":626,"title":627,"description":628,"slug":629,"coverImageUrl":630},99,"AWS Control Tower","AWS Control Tower is a cloud service that automatically sets up and governs a secure, multi-account AWS environment based on best practices established through AWSâs experience working with thousands of enterprises.","aws-control-tower","\u002Fimages\u002Fprovider-services\u002Faws-control-tower\u002Fcovers\u002FArch_AWS-Control-Tower_64.png",{"id":632,"title":633,"description":634,"slug":635,"coverImageUrl":636},100,"AWS Health Dashboard","The AWS Health Dashboard is a service provided by Amazon Web Services that shows the current status of AWS services and alerts to any operational issues or scheduled maintenance events affecting the user's resources.","aws-health-dashboard","\u002Fimages\u002Fprovider-services\u002Faws-health-dashboard\u002Fcovers\u002FArch_AWS-Health-Dashboard_64.png",{"id":638,"title":639,"description":640,"slug":641,"coverImageUrl":642},107,"AWS Management Console","The AWS Management Console is a web-based interface that allows users to access and manage Amazon Web Services (AWS) and its resources, offering an intuitive and easy-to-navigate user experience for configuring AWS services, monitoring their performance, and managing billing and security.","aws-management-console","\u002Fimages\u002Fprovider-services\u002Faws-management-console\u002Fcovers\u002FArch_AWS-Management-Console_64.png",{"id":644,"title":645,"description":646,"slug":647,"coverImageUrl":648},108,"AWS Organizations","AWS Organizations is a cloud service from Amazon Web Services that allows you to centrally manage and govern your environment as you scale your AWS resources across multiple accounts.","aws-organizations","\u002Fimages\u002Fprovider-services\u002Faws-organizations\u002Fcovers\u002FArch_AWS-Organizations_64.png",{"id":650,"title":502,"description":651,"slug":652,"coverImageUrl":653},113,"AWS Trusted Advisor is an online tool that provides real-time guidance to help users optimize their Amazon Web Services (AWS) infrastructure for cost, performance, security, and fault tolerance by scanning their environment and offering recommendations based on best practices.","aws-trusted-advisor","\u002Fimages\u002Fprovider-services\u002Faws-trusted-advisor\u002Fcovers\u002FArch_AWS-Trusted-Advisor_64.png",{"id":655,"title":656,"description":657,"slug":658,"coverImageUrl":659},114,"AWS Well-Architected Tool","The AWS Well-Architected Tool is a cloud service provided by Amazon Web Services that offers a set of questions across five pillars: operational excellence, security, reliability, performance efficiency, and cost optimizations to help users review the state of their workloads and compare them against AWS architectural best practices.","aws-well-architected-tool","\u002Fimages\u002Fprovider-services\u002Faws-well-architected-tool\u002Fcovers\u002FArch_AWS-Well-Architected-Tool_64.png",{"id":661,"title":662,"description":663,"slug":664,"coverImageUrl":665},127,"AWS Client VPN","AWS Client VPN is a managed client-based VPN service that enables secure access to AWS resources and on-premises networks from any location.","aws-client-vpn","\u002Fimages\u002Fprovider-services\u002Faws-client-vpn\u002Fcovers\u002FArch_AWS-Client-VPN_64.png",{"id":667,"title":668,"description":669,"slug":670,"coverImageUrl":671},128,"Amazon CloudFront","Amazon CloudFront is a fast content delivery network (CDN) service that securely delivers data, videos, applications, and APIs to customers globally with low latency, high transfer speeds, all within a developer-friendly environment.","amazon-cloudfront","\u002Fimages\u002Fprovider-services\u002Famazon-cloudfront\u002Fcovers\u002FArch_Amazon-CloudFront_64.png",{"id":673,"title":674,"description":675,"slug":676,"coverImageUrl":677},129,"AWS Direct Connect","AWS Direct Connect is a cloud service from Amazon Web Services that provides a dedicated network connection from an on-premises network to AWS infrastructure, allowing for reduced network costs, increased bandwidth throughput, and a more consistent network experience compared to internet-based connections.","aws-direct-connect","\u002Fimages\u002Fprovider-services\u002Faws-direct-connect\u002Fcovers\u002FArch_AWS-Direct-Connect_64.png",{"id":679,"title":680,"description":681,"slug":682,"coverImageUrl":683},130,"Elastic Load Balancing (ELB)","Elastic Load Balancing (ELB) is a service provided by Amazon Web Services (AWS) that automatically distributes incoming application traffic across multiple targets, such as EC2 instances, containers, and IP addresses, to ensure fault tolerance and scalability.","elastic-load-balancing-(elb)","\u002Fimages\u002Fprovider-services\u002Felastic-load-balancing-(elb)\u002Fcovers\u002FArch_Elastic-Load-Balancing_64.png",{"id":685,"title":686,"description":687,"slug":688,"coverImageUrl":689},131,"AWS Global Accelerator","AWS Global Accelerator is a networking service that improves an application's availability and performance by directing traffic to optimal endpoints over the AWS global network.","aws-global-accelerator","\u002Fimages\u002Fprovider-services\u002Faws-global-accelerator\u002Fcovers\u002FArch_AWS-Global-Accelerator_64.png",{"id":691,"title":692,"description":693,"slug":694,"coverImageUrl":695},132,"AWS PrivateLink","AWS PrivateLink is a networking service that allows AWS customers to securely access services across the Amazon Web Services (AWS) network in a private manner, without using public IPs or requiring the traffic to traverse the public internet.","aws-privatelink","\u002Fimages\u002Fprovider-services\u002Faws-privatelink\u002Fcovers\u002FArch_AWS-PrivateLink_64.png",{"id":697,"title":698,"description":699,"slug":700,"coverImageUrl":701},133,"Amazon Route 53","Amazon Route 53 is a scalable cloud Domain Name System (DNS) web service designed to give developers and businesses a reliable way to route end users to Internet applications by translating names like www.example.com into the numeric IP addresses like 192.0.2.1 that computers use to connect to each other.","amazon-route-53","\u002Fimages\u002Fprovider-services\u002Famazon-route-53\u002Fcovers\u002FArch_Amazon-Route-53_64.png",{"id":98,"title":703,"description":704,"slug":705,"coverImageUrl":706},"AWS Site-to-Site VPN","AWS Site-to-Site VPN is a service that allows you to establish a secure and private connection between your on-premises network and your Amazon Virtual Private Cloud (VPC), enabling secure data transfer and remote access to your AWS resources.","aws-site-to-site-vpn","\u002Fimages\u002Fprovider-services\u002Faws-site-to-site-vpn\u002Fcovers\u002FArch_AWS-Site-to-Site-VPN_64.png",{"id":125,"title":708,"description":709,"slug":710,"coverImageUrl":711},"AWS Transit Gateway","AWS Transit Gateway is a service that enables customers to connect their Amazon Virtual Private Clouds (VPCs) and their on-premises networks to a single gateway, simplifying their network architecture and enabling scalable, efficient routing among thousands of VPCs, AWS accounts, and on-premises environments.","aws-transit-gateway","\u002Fimages\u002Fprovider-services\u002Faws-transit-gateway\u002Fcovers\u002FArch_AWS-Transit-Gateway_64.png",{"id":151,"title":713,"description":714,"slug":715,"coverImageUrl":716},"Amazon VPC","Amazon VPC (Virtual Private Cloud) is a service that allows users to launch AWS resources in a logically isolated virtual network that they can define and control, including IP address ranges, subnets, route tables, and gateways.","amazon-vpc","\u002Fimages\u002Fprovider-services\u002Famazon-vpc\u002Fcovers\u002FVirtual-private-cloud-VPC_32.png",{"id":424,"title":494,"description":718,"slug":719,"coverImageUrl":720},"AWS Firewall Manager is a security management service that allows you to centrally configure and manage firewall rules across your Amazon Web Services (AWS) accounts and applications, simplifying your AWS network firewall administration.","aws-firewall-manager","\u002Fimages\u002Fprovider-services\u002Faws-firewall-manager\u002Fcovers\u002FArch_AWS-Firewall-Manager_64.png",{"id":483,"title":722,"description":723,"slug":724,"coverImageUrl":725},"AWS IAM Identity Center (AWS Single Sign-On)","AWS IAM Identity Center (formerly AWS Single Sign-On) is a cloud service that enables secure and unified authentication for users to access AWS accounts and business applications with a single set of credentials.","aws-iam-identity-center-(aws-single-sign-on)","\u002Fimages\u002Fprovider-services\u002Faws-iam-identity-center-(aws-single-sign-on)\u002Fcovers\u002FArch_AWS-IAM-Identity-Center_64.png",{"id":727,"title":728,"description":729,"slug":730,"coverImageUrl":731},153,"AWS Network Firewall","AWS Network Firewall is a managed service provided by Amazon Web Services that enables users to deploy essential network protections such as stateful firewall rules, intrusion detection and prevention, and web filtering within their Virtual Private Cloud (VPC) environments.","aws-network-firewall","\u002Fimages\u002Fprovider-services\u002Faws-network-firewall\u002Fcovers\u002FArch_AWS-Firewall-Manager_64.png",{"id":733,"title":734,"description":735,"slug":736,"coverImageUrl":737},154,"AWS Resource Access Manager (AWS RAM)","AWS Resource Access Manager (AWS RAM) is a service that enables you to easily and securely share AWS resources with any AWS account or within your AWS Organization.","aws-resource-access-manager-(aws-ram)","\u002Fimages\u002Fprovider-services\u002Faws-resource-access-manager-(aws-ram)\u002Fcovers\u002FArch_AWS-Resource-Access-Manager_64.png",{"id":739,"title":740,"description":741,"slug":742,"coverImageUrl":743},157,"AWS Shield","AWS Shield is a managed Distributed Denial of Service (DDoS) protection service that safeguards applications running on AWS against DDoS attacks.","aws-shield","\u002Fimages\u002Fprovider-services\u002Faws-shield\u002Fcovers\u002FArch_AWS-Shield_64.png",{"id":745,"title":746,"description":747,"slug":748,"coverImageUrl":749},158,"AWS WAF","AWS WAF (Web Application Firewall) is a web application firewall service that helps protect web applications and APIs from common web exploits and bots that may affect availability, compromise security, or consume excessive resources.","aws-waf","\u002Fimages\u002Fprovider-services\u002Faws-waf\u002Fcovers\u002FArch_AWS-WAF_64.png",{"id":751,"title":752,"description":753,"slug":754,"coverImageUrl":755},166,"AWS Fargate","AWS Fargate is a serverless compute engine for containers that allows you to run containers without having to manage servers or clusters.","aws-fargate","\u002Fimages\u002Fprovider-services\u002Faws-fargate\u002Fcovers\u002FArch_AWS-Fargate_64.png",{"id":757,"title":758,"description":759,"slug":760,"coverImageUrl":761},168,"AWS Lambda","AWS Lambda is a serverless computing service provided by Amazon Web Services that allows developers to run code in response to events without provisioning or managing servers.","aws-lambda","\u002Fimages\u002Fprovider-services\u002Faws-lambda\u002Fcovers\u002FArch_AWS-Lambda_64.png",{"id":763,"title":764,"description":765,"slug":766,"coverImageUrl":767},173,"Amazon S3","Amazon S3 (Simple Storage Service) is a scalable cloud storage service offered by Amazon Web Services (AWS) that allows users to store and retrieve any amount of data from anywhere on the web.","amazon-s3","\u002Fimages\u002Fprovider-services\u002Famazon-s3\u002Fcovers\u002FArch_Amazon-Simple-Storage-Service_64.png",{"id":769,"title":770,"description":771,"slug":772,"coverImageUrl":773},240,"AWS App Mesh","AWS App Mesh is a service mesh that provides application-level networking to standardize how your microservices communicate, offering end-to-end visibility and control for managing traffic and ensuring high availability across your applications.","aws-app-mesh","\u002Fimages\u002Fprovider-services\u002Faws-app-mesh\u002Fcovers\u002FArch_AWS-App-Mesh_64.png",{"id":775,"title":776,"description":777,"slug":778,"coverImageUrl":779},241,"AWS Cloud Map","AWS Cloud Map is a cloud resource discovery service that allows developers to define custom names for their application resources, and it keeps track of the changing locations of these dynamically changing resources, making it easier to discover and connect to them in a cloud environment.","aws-cloud-map","\u002Fimages\u002Fprovider-services\u002Faws-cloud-map\u002Fcovers\u002FArch_AWS-Cloud-Map_64.png",[],1790430980644]