🇮🇳 AWS Certified Solutions Architect – Associate · flashcards

AWS Certified Solutions Architect – Associate Networking & Content Delivery Flashcards

60 question-and-answer cards covering Networking & Content Delivery as it is examined in AWS Certified Solutions Architect – Associate. 24 of them are printed below, taken from across the deck — no signup, no paywall on the preview.

60Cards in deck
24Free preview
12Syllabus topics
~165Chars per answer
FreePrice

24 sample cards from the Networking & Content Delivery deck

Sampled from the end of the deck, so these are different cards from the ones shown on the syllabus page.

  1. What is the difference between a Gateway Endpoint and an Interface Endpoint?

    A Gateway Endpoint adds a route to your route table (target = the service) and is only for S3 and DynamoDB, with no charge. An Interface Endpoint (powered by AWS PrivateLink) creates an ENI with a private IP in your subnet, works for most AWS services, and incurs hourly + data charges.

  2. Which two AWS services use Gateway VPC Endpoints?

    Amazon S3 and Amazon DynamoDB.

  3. What technology powers Interface VPC Endpoints?

    AWS PrivateLink, which provisions an Elastic Network Interface (ENI) with a private IP address as the entry point to the service.

  4. What are the main options for hybrid connectivity between on-premises and AWS?

    AWS Site-to-Site VPN (IPsec over the internet) and AWS Direct Connect (dedicated private physical connection).

  5. Compare AWS Direct Connect vs Site-to-Site VPN.

    Direct Connect = dedicated private physical link, consistent low latency/high bandwidth, not encrypted by default, longer to provision. Site-to-Site VPN = encrypted IPsec tunnel over the public internet, quick to set up, lower cost, variable latency.

  6. How do you add encryption to a Direct Connect connection?

    Run a Site-to-Site VPN over the Direct Connect connection (combining private connectivity with IPsec encryption), or use MACsec on supported DX connections.

  7. How many tunnels does an AWS Site-to-Site VPN connection provide and why?

    Two tunnels, terminating in different AWS endpoints/AZs, to provide redundancy and high availability for the connection.

  8. What is the typical solution to keep a backup path if Direct Connect fails?

    Configure a Site-to-Site VPN as a backup/failover connection to maintain connectivity if the Direct Connect link goes down.

  9. What is AWS Client VPN?

    A managed, client-based VPN service that lets users securely access AWS resources and on-premises networks from any location using an OpenVPN-based client.

  10. What authentication methods does AWS Client VPN support?

    Active Directory authentication, mutual (certificate-based) authentication, and federated/SAML-based (SSO) authentication.

  11. How does Client VPN differ from Site-to-Site VPN?

    Client VPN connects individual remote users/devices to AWS (remote access VPN), while Site-to-Site VPN connects an entire network/data center to AWS (network-to-network).

  12. What is Amazon Route 53?

    A highly available and scalable DNS web service that also provides domain registration and health checking, with the '53' referring to DNS port 53.

  13. What is the difference between an A record, AAAA record, and CNAME in Route 53?

    A record maps a name to an IPv4 address; AAAA maps a name to an IPv6 address; CNAME maps a name to another domain name (cannot be used for the zone apex/root).

  14. What is a Route 53 Alias record and how does it differ from a CNAME?

    An Alias record maps a name to an AWS resource (ELB, CloudFront, S3 website, etc.). Unlike a CNAME, it works at the zone apex (root domain), is free for AWS resource queries, and resolves natively to the target.

  15. List the Route 53 routing policies.

    Simple, Weighted, Latency-based, Failover, Geolocation, Geoproximity, Multivalue answer, and IP-based routing.

  16. When would you use Route 53 Latency-based routing vs Geolocation routing?

    Latency-based routes users to the Region with the lowest network latency for best performance. Geolocation routes based on the user's physical location (for content localization, compliance, or licensing).

  17. What is Route 53 Failover routing combined with health checks used for?

    Active-passive disaster recovery: traffic goes to the primary resource while healthy and automatically fails over to a secondary resource when the health check on the primary fails.

  18. What is Amazon CloudFront?

    A global Content Delivery Network (CDN) that caches content at edge locations close to users to reduce latency and improve delivery of static and dynamic content.

  19. What is an Origin in CloudFront, and what types are supported?

    The source of the content CloudFront distributes. Origins include S3 buckets, MediaStore/MediaPackage, EC2/ALB or any custom HTTP origin (custom origin).

  20. What is Origin Access Control (OAC) in CloudFront?

    A feature that restricts direct access to an S3 origin so content is only reachable through CloudFront, replacing the older Origin Access Identity (OAI).

  21. What is the difference between CloudFront and Global Accelerator at the network layer?

    CloudFront caches and serves HTTP/HTTPS content at edge locations (Layer 7, content delivery). Global Accelerator routes TCP/UDP traffic over the AWS backbone using anycast static IPs (Layer 4, no caching), improving performance for non-cacheable/global apps.

  22. What is AWS Global Accelerator?

    A networking service that provides two static anycast IP addresses as a fixed entry point and routes user traffic over the AWS global backbone to the optimal application endpoint for improved performance and availability.

  23. What two static IP addresses does Global Accelerator provide and why are they useful?

    Two static anycast IPs that serve as a fixed front door to your application. They don't change, simplifying allow-listing and DNS, while traffic is routed to the nearest healthy endpoint.

  24. How does Global Accelerator improve availability during regional failure?

    It continuously health-checks endpoints and instantly reroutes traffic to the next-closest healthy endpoint/Region without requiring DNS changes (since the IPs are static).

What this deck covers

The Networking & Content Delivery deck follows the AWS Certified Solutions Architect – Associate Networking & Content Delivery syllabus — 3 chapters and 12 topics — so questions land on material that is genuinely examinable rather than trivia around it. That works out to roughly 20.0 cards per chapter.

Answers are written to be recallable, not just readable — averaging about 165 characters, which is long enough to carry the reasoning and short enough to say out loud.

A deck like this earns its keep on the second and third pass. Read the syllabus first so you know the shape of the subject, then use the cards to find the specific facts that have not stuck.

Networking & Content Delivery flashcards FAQ

How many Networking & Content Delivery flashcards are in this AWS Certified Solutions Architect – Associate deck?

60 cards. This page previews 24 of them, sampled evenly across the deck so you can judge the difficulty before installing anything.

Are these AWS Certified Solutions Architect – Associate flashcards free?

Yes. The preview here is free to read with no signup, and the full 60-card deck is free inside the Examius app.

What do the Networking & Content Delivery cards cover?

They follow the AWS Certified Solutions Architect – Associate Networking & Content Delivery syllabus — 3 chapters and 12 topics — so the questions track what is actually examinable.

How should I use these flashcards?

Read the syllabus first so you know the shape of the subject, then drill the deck. Examius schedules each card with spaced repetition, so cards you keep missing come back sooner and ones you know drift further apart.