Topic module

VPC Connectivity, Routing and Endpoints

Networking questions test VPCs, subnets, route tables, security groups, network ACLs, endpoints, NAT, peering, Transit Gateway, and hybrid paths.

Long-form learning
Concept to Risk to Memory to Check-up

How to study for AWS CloudOps Engineer Associate

Treat each question as an operations scenario: identify the signal, failing component, recovery target, access boundary, and repeatable automation before choosing an answer.

Core concepts

Concept 1

VPC Connectivity, Routing and Endpoints questions test operational choices for monitoring, reliability, automation, security, and networking on AWS.

Exam cue: Identify the failing resource, operational signal, recovery target, access boundary, and automation surface.

Concept 2

The strongest answer maps the incident or operating requirement to a managed AWS control with measurable recovery or prevention value.

Exam cue: Match the AWS service to the control needed: detect, analyze, remediate, provision, secure, connect, or recover.

Concept 3

Eliminate answers that rely on manual fixes, public exposure, missing alarms, single points of failure, or untracked infrastructure changes.

Exam cue: Prefer observable, repeatable, least-privilege, multi-AZ, and infrastructure-as-code approaches when the scenario calls for them.

Risk pitfalls and guardrails

Fixing symptoms without adding metrics, logs, alarms, automation, or durable prevention.

Guardrail: Avoid answers that rely on manual console edits, broad access, public paths, missing alarms, untested backups, or single-AZ dependencies.

Choosing manual console changes when repeatable provisioning or Systems Manager automation is expected.

Guardrail: Avoid answers that rely on manual console edits, broad access, public paths, missing alarms, untested backups, or single-AZ dependencies.

Opening broad network or identity access to solve an operations issue quickly.

Guardrail: Avoid answers that rely on manual console edits, broad access, public paths, missing alarms, untested backups, or single-AZ dependencies.

Memory anchors

Route Table

A route table controls where subnet or gateway traffic is directed.

Security Group

A security group is a stateful virtual firewall attached to supported resources.

Network ACL

A network ACL is a stateless subnet-level traffic filter.

NAT Gateway

A NAT gateway lets private subnet resources initiate outbound IPv4 internet access.

VPC Endpoint

A VPC endpoint provides private connectivity to supported AWS services without public internet paths.

PrivateLink

AWS PrivateLink exposes services privately through interface endpoints.

VPC Peering

VPC peering connects two VPCs with non-overlapping CIDR ranges and no transitive routing.

Transit Gateway

AWS Transit Gateway connects multiple VPCs and on-premises networks through a central hub.

VPN

AWS Site-to-Site VPN provides encrypted connectivity between AWS and an on-premises network.

Direct Connect

AWS Direct Connect provides dedicated private connectivity from on-premises locations to AWS.

Checkpoint rule

Do the check-up only after you can summarize each concept in one sentence and identify one dangerous pitfall from memory.

Knowledge Check (after reading)

Short check-up to confirm understanding of this module.

Check-up Questions

1-2 question checkpoint

A private subnet routes `0.0.0.0/0` to a NAT gateway, but the NAT gateway is in a private subnet with no internet-gateway route. Why does egress fail?

A private IPv6 workload needs outbound internet access without unsolicited inbound connections. Which gateway is appropriate?

Answer all questions to submit.

Next step personalized recommendations

What is Pass Harbor?

Completely free exam prep for 317 U.S. exams.

  • Practice questions
  • Flashcards
  • Study guides
  • Mock exams
  • No registration
  • No paywall
  • Start instantly
No more expensive exam prep. Quality study tools should be accessible to everyone.