220 AWS Interview Questions with Explanation
AWS is a cloud leader, and to be successful in its various interviews, it is important to understand both theoretical and practical scenarios. This compilation of interview questions is tailored to help you prepare for the nuances and specific challenges faced in distinct AWS job roles. We have considered the following roles:
- Cloud Practitioner: Basic understanding of AWS services and their use cases.
- Solutions Architect: Designing resilient, high-performing, secure, and cost-optimized architectures.
- AWS Developer: Developing and maintaining AWS-based applications, and using AWS SDKs to interact with AWS services.
- SysOps Administrator: Managing and operating systems on AWS.
- DevOps Engineer: Implementing and managing continuous delivery systems and methodologies on AWS.
- Security: Ensuring secure and compliant AWS environments.
- Data Analytics: Designing and building data analytics solutions using AWS services.
- Machine Learning: Building, training, and deploying machine learning models on AWS.
- Database Engineer: Designing, implementing, and managing AWS databases.
- Network Architect: Designs and implements scalable, secure, and reliable cloud networking solutions, optimizing connectivity, performance, and security within the AWS ecosystem.
- Network Specialist: Designs, implements, and manages cloud network architectures, ensuring secure, scalable, and high-performance connectivity between AWS services and external resources.
data:image/s3,"s3://crabby-images/932ae/932aed396c35dd28283e272042e52292a62b19fb" alt="descImg"
Q: What AWS service provides a fully managed service for container orchestration?
Ans: Amazon ECS (Elastic Container Service) or Amazon EKS (Elastic Kubernetes Service)
Q: Which AWS service would you use to create a private network connection between AWS and your data center?
Ans: AWS Direct Connect
Q: What is the AWS service that provides fast flexible data warehousing?
Ans: Amazon Redshift
Q: Which AWS service would you use to quickly deploy and scale applications on AWS?
Ans: AWS Elastic Beanstalk
Q: What AWS service provides a fully managed relational database service?
Ans: Amazon RDS (Relational Database Service)
Q: Which AWS service would you use to distribute incoming application traffic across multiple targets?
Ans: Elastic Load Balancing
Q: What is the AWS service that provides a virtual server in the cloud?
Ans: Amazon EC2 (Elastic Compute Cloud)
Q: Which AWS service would you use to run code without provisioning or managing servers?
Ans: AWS Lambda
Q: What AWS service provides a fully managed NoSQL database?
Ans: Amazon DynamoDB
Q: Which AWS service would you use to store and manage Docker containers?
Ans: Amazon ECR (Elastic Container Registry)
Q: What is the AWS service that provides scalable compute capacity in the cloud?
Ans: Amazon EC2 (Elastic Compute Cloud)
Q: Which AWS service would you use to create and manage AWS users and groups?
Ans: AWS IAM (Identity and Access Management)
Q: What AWS service provides a fully managed message queuing service?
Ans: Amazon SQS (Simple Queue Service)
Q: Which AWS service would you use to monitor your AWS resources and applications in real-time?
Ans: Amazon CloudWatch
Q: What is the AWS pricing model that allows you to pay a low upfront fee to reserve compute capacity and receive a significant discount on the hourly charge for an instance?
Ans: Reserved Instances
Q: Which AWS service provides a fully managed extract transform and load (ETL) service that makes it easy to prepare and load data for analytics?
Ans: AWS Glue
Q: What AWS service would you use to deploy and scale web applications?
Ans: AWS Elastic Beanstalk
Q: Which AWS service would you use to run a database that needs to scale automatically?
Ans: Amazon DynamoDB
Q: What is the AWS service that provides a virtual network dedicated to your AWS account?
Ans: Amazon VPC (Virtual Private Cloud)
Q: Which AWS service is designed for storing and retrieving any amount of data from anywhere on the web?
Ans: Amazon S3 (Simple Storage Service)
Q: What AWS service would you use for building and deploying forecasting models at scale?
Ans: Amazon Forecast
Q: Which AWS service provides a way to embed interactive analytics in applications?
Ans: Amazon QuickSight Q
Q: What AWS service would you use for processing and analyzing IoT device data?
Ans: AWS IoT Analytics
Q: Which AWS service provides a way to build and run analytics against operational databases?
Ans: Amazon Aurora with Amazon Aurora Machine Learning
Q: What AWS service would you use for data lake formation and management?
Ans: AWS Lake Formation
Q: Which AWS service provides a fully managed Apache Cassandra-compatible database?
Ans: Amazon Keyspaces
Q: What AWS service would you use for real-time analytics on streaming video?
Ans: Amazon Kinesis Video Streams
Q: Which AWS service provides a unified interface for data preparation and machine learning?
Ans: Amazon SageMaker Data Wrangler
Q: What AWS feature allows you to query data across different AWS data stores?
Ans: Amazon Redshift Spectrum
Q: Which AWS service would you use for a fully managed graph database?
Ans: Amazon Neptune
Q: What AWS service provides a fully managed time series database?
Ans: Amazon Timestream
Q: Which AWS service would you use for creating and sharing interactive data visualizations?
Ans: Amazon QuickSight
Q: What AWS service provides a fully managed extract, transform, and load (ETL) service?
Ans: AWS Glue
Q: Which AWS service would you use for building and operationalizing machine learning models?
Ans: Amazon SageMaker
Q: What AWS service provides a fully managed petabyte-scale data transfer service?
Ans: AWS Snow Family (Snowball
Q: Which AWS service would you use for a fully managed Apache Kafka-compatible event streaming platform?
Ans: Amazon Managed Streaming for Apache Kafka (MSK)
Q: What AWS service provides a fully managed Apache Spark environment?
Ans: Amazon EMR
Q: Which AWS service would you use for serverless, interactive analytics?
Ans: Amazon Athena
Q: What AWS service provides a fully managed data warehouse optimized for analytics?
Ans: Amazon Redshift
Q: Which AWS service would you use for real-time streaming data analytics?
Ans: Amazon Kinesis Data Analytics
Q: How can you ensure that your EC2 instances can access an S3 bucket without using access keys?
Ans: Use an IAM role
Q: A company wants to analyze their AWS costs and usage. Which service should they use?
Ans: AWS Cost Explorer
Q: Which service would you use to create a content delivery network?
Ans: Amazon CloudFront
Q: How can you improve the security of your VPC?
Ans: Implement Security Groups and Network Access Control Lists (NACLs)
Q: Which storage option would you recommend for an EC2 instance that requires high-performance
Ans: low-latency storage?
Q: A company needs to store sensitive data and manage the encryption keys. Which service should they use?
Ans: AWS Key Management Service (KMS)
Q: Which service would you use to monitor the CPU utilization of your EC2 instances?
Ans: Amazon CloudWatch
Q: How can you ensure that only authorized users can access specific S3 buckets?
Ans: Use S3 bucket policies and IAM policies
Q: Which service would you use to run a serverless web application?
Ans: AWS Lambda with Amazon API Gateway
Q: A company wants to reduce their RDS database costs. What would you recommend?
Ans: Use RDS Read Replicas
Q: Which service would you use to automatically distribute incoming application traffic across multiple EC2 instances?
Ans: Elastic Load Balancing (ELB)
Q: How can you improve the availability of an application running on EC2 instances?
Ans: Deploy the application across multiple Availability Zones using an Elastic Load Balancer
Q: A company needs to process a large amount of genomics data. Which EC2 instance family would you recommend?
Ans: EC2 High Performance Computing (HPC) instances
Q: Which service would you use to create a hybrid cloud architecture?
Ans: AWS Direct Connect
Q: How can you secure data in transit between an EC2 instance and an S3 bucket?
Ans: Use SSL/TLS encryption
Q: A company wants to migrate their on-premises MySQL database to AWS with minimal downtime. Which service should they use?
Ans: AWS Database Migration Service (DMS)
Q: Which AWS service would you use to run Docker containers without managing servers or clusters?
Ans: AWS Fargate
Q: A web application experiences high traffic during business hours and low traffic at night. How can you design the system to be cost-effective?
Ans: Use EC2 Auto Scaling with scheduled actions
Q: Which service would you recommend for analyzing log files from EC2 instances in near real-time?
Ans: Amazon Kinesis Data Firehose
Q: A company needs to store large video files that are accessed infrequently. Which S3 storage class should they use?
Ans: Amazon S3 Glacier Deep Archive
Q: How can you implement custom authentication for API Gateway?
Ans: Use Lambda authorizers
Q: Which service would you use to manage and rotate database credentials automatically?
Ans: AWS Secrets Manager
Q: How can you optimize the cost of your Lambda functions?
Ans: Adjust the memory allocation and optimize your code
Q: Which AWS service would you use to create and manage APIs for your applications?
Ans: Amazon API Gateway
Q: How can you grant temporary security credentials to users or AWS services?
Ans: Use IAM Roles
Q: Which service would you use to store and retrieve any amount of data from anywhere on the web?
Ans: Amazon S3
Q: How can you implement authentication for your web application?
Ans: Use Amazon Cognito
Q: Which AWS service would you use to run Docker containers?
Ans: Amazon Elastic Container Service (ECS) or Amazon Elastic Kubernetes Service (EKS)
Q: How can you implement server-side encryption for data stored in S3?
Ans: Use S3-Managed Keys (SSE-S3) or AWS KMS-Managed Keys (SSE-KMS)
Q: Which service would you use to host a static website?
Ans: Amazon S3
Q: How can you monitor the performance of your Lambda functions?
Ans: Use AWS X-Ray
Q: Which AWS service would you use to create a CI/CD pipeline for your application?
Ans: AWS CodePipeline
Q: How can you store session data for a web application that needs to scale horizontally?
Ans: Use Amazon ElastiCache
Q: Which service would you use to build and test your code automatically when changes are pushed to a repository?
Ans: AWS CodeBuild
Q: How can you deploy your application code to an EC2 instance automatically?
Ans: Use AWS CodeDeploy
Q: Which AWS service would you use to build a real-time data streaming application?
Ans: Amazon Kinesis
Q: How can you improve the performance of a DynamoDB query that's frequently accessing the same items?
Ans: Use DynamoDB Accelerator (DAX)
Q: Which service would you use to send push notifications to mobile devices?
Ans: Amazon Simple Notification Service (SNS)
Q: How can you store sensitive information like database credentials securely in AWS?
Ans: Use AWS Secrets Manager
Q: Which AWS service would you use to run code in response to HTTP requests?
Ans: AWS Lambda with Amazon API Gateway
Q: Which AWS service would you use to centrally manage and enforce compliance policies across multiple AWS accounts?
Ans: AWS Control Tower
Q: How can you ensure that your EC2 instances can access AWS services without using access keys?
Ans: Use IAM roles for EC2 instances
Q: Which service would you use to provide a virtual firewall for your VPC?
Ans: AWS Network Access Control List (NACL) and Security Groups
Q: How can you monitor and alert on AWS account root user activity?
Ans: Use CloudTrail with CloudWatch alarms
Q: Which service would you use to automatically discover and maintain an up-to-date inventory of your resources?
Ans: AWS Systems Manager Inventory
Q: How can you ensure that your EC2 instances have the latest security patches?
Ans: Use AWS Systems Manager Patch Manager
Q: Which service would you use to manage user access to AWS services and resources?
Ans: AWS Identity and Access Management (IAM)
Q: How can you securely store and manage encryption keys for your applications?
Ans: Use AWS Key Management Service (KMS)
Q: Which service would you use to manage and automate infrastructure deployments?
Ans: AWS CloudFormation
Q: How can you ensure that your RDS database is fault-tolerant?
Ans: Use Multi-AZ deployment
Q: Which AWS service would you use to run a single task on a schedule?
Ans: AWS Lambda with CloudWatch Events (EventBridge)
Q: How can you automatically recover an EC2 instance if it becomes impaired?
Ans: Enable detailed monitoring and use EC2 Auto Recovery
Q: Which service would you use to create a private connection between your VPC and on-premises data center?
Ans: AWS Direct Connect
Q: How can you ensure that your S3 buckets are not publicly accessible?
Ans: Use S3 Block Public Access feature
Q: Which AWS service would you use to centrally manage multiple AWS accounts?
Ans: AWS Organizations
Q: How can you optimize the cost of your EBS volumes?
Ans: Use Amazon EBS gp3 volumes and adjust IOPS and throughput as needed
Q: Which service would you use to track changes made to your AWS resources?
Ans: AWS Config
Q: How can you ensure that your EC2 instances are distributed across multiple Availability Zones?
Ans: Use an Auto Scaling group with multiple AZs selected
Q: Which AWS service would you use to automatically scale your EC2 instances based on demand?
Ans: AWS Auto Scaling
Q: How can you monitor the CPU utilization of an EC2 instance?
Ans: Use Amazon CloudWatch
Q: How can you implement immutable infrastructure deployments?
Ans: Use AWS CloudFormation with Auto Scaling groups
Q: Which AWS service would you use to implement chaos engineering practices?
Ans: AWS Fault Injection Simulator
Q: How can you ensure that your Lambda functions are tested before deployment?
Ans: Use AWS SAM with AWS CodeBuild
Q: Which service would you use to implement a GitOps workflow for your Kubernetes deployments?
Ans: AWS CodeCommit with AWS CodePipeline and Amazon EKS
Q: How can you implement automated rollbacks in your deployment process?
Ans: Use AWS CodeDeploy with automatic rollback configuration
Q: Which AWS service would you use to run and manage batch computing workloads?
Ans: AWS Batch
Q: How can you implement canary deployments for your applications?
Ans: Use AWS CodeDeploy with canary deployment configuration
Q: Which service would you use to create a continuous delivery workflow for serverless applications?
Ans: AWS SAM (Serverless Application Model) with CodePipeline
Q: How can you securely store and automatically rotate database credentials used in your applications?
Ans: Use AWS Secrets Manager
Q: Which AWS service would you use to centrally manage configuration and compliance across multiple AWS accounts?
Ans: AWS Config
Q: How can you implement infrastructure validation in your CI/CD pipeline?
Ans: Use AWS CloudFormation with custom resource types
Q: Which service would you use to monitor application performance and diagnose issues in distributed systems?
Ans: AWS X-Ray
Q: How can you ensure that your EC2 instances are always running the latest AMI?
Ans: Use AWS Systems Manager Automation with a maintenance window
Q: Which service would you use to create and manage Docker containers for your applications?
Ans: Amazon Elastic Container Service (ECS) or Amazon Elastic Kubernetes Service (EKS)
Q: How can you implement blue/green deployments for your applications?
Ans: Use AWS CodeDeploy with blue/green deployment configuration
Q: Which AWS service would you use to automatically deploy code to a fleet of EC2 instances?
Ans: AWS CodeDeploy
Q: How can you ensure that your CI/CD pipeline is triggered automatically when code is pushed to a specific branch?
Ans: Use AWS CodePipeline with CodeCommit as the source
Q: Which service would you use to centrally store and version control your infrastructure as code templates?
Ans: AWS CodeCommit
Q: How can you automate the deployment of infrastructure changes across multiple AWS accounts?
Ans: Use AWS CloudFormation StackSets
Q: Which AWS service would you use to automatically build and test code every time there's a code change?
Ans: AWS CodeBuild
Q: What AWS service would you use to detect and mitigate bias in machine learning model?
Ans: Amazon SageMaker Clarify
Q: Which AWS service is most appropriate for building and hosting a scalable search engine with machine learning capabilities?
Ans: Amazon Kendra
Q: What AWS service would you use to perform time series analysis on IoT device data?
Ans: Amazon SageMaker with DeepAR algorithm
Q: Which AWS service is best for creating a recommendation system that can handle millions of users and items?
Ans: Amazon Personalize
Q: What AWS service would you use to detect and blur faces in a large collection of images?
Ans: Amazon Rekognition
Q: Which AWS service is most suitable for building and deploying forecasting models at scale?
Ans: Amazon Forecast
Q: What AWS service would you use to automatically optimize hyperparameters for a machine learning model?
Ans: Amazon SageMaker Automatic Model Tuning
Q: Which AWS service is best for deploying machine learning models at the edge for low-latency inference?
Ans: AWS IoT Greengrass
Q: What AWS service would you use to store and version machine learning models and datasets?
Ans: Amazon S3 with versioning enabled
Q: Which AWS service is most appropriate for running distributed machine learning tasks on a Spark cluster?
Ans: Amazon EMR
Q: What AWS service would you use to deploy a machine learning model as a RESTful API?
Ans: Amazon API Gateway with AWS Lambda
Q: Which AWS service is best for creating a pipeline to preprocess, train, and deploy machine learning models?
Ans: AWS Step Functions for SageMaker
Q: What AWS service would you use to perform batch transform jobs on a large dataset using a trained model?
Ans: Amazon SageMaker Batch Transform
Q: Which AWS service is most suitable for building and training reinforcement learning models?
Ans: Amazon SageMaker RL
Q: What AWS service would you use to automatically label a large dataset of images for a machine learning project?
Ans: Amazon SageMaker Ground Truth
Q: Which AWS service is best for hosting a deep learning model that requires GPU acceleration?
Ans: Amazon EC2 P3 instances
Q: What AWS service would you use to extract text, entities, and key phrases from a large collection of documents?
Ans: Amazon Comprehend
Q: Which AWS service is most appropriate for building a chatbot with natural language understanding?
Ans: Amazon Lex
Q: What AWS service should you use to deploy a TensorFlow model for inference with automatic scaling?
Ans: Amazon SageMaker
Q: Which AWS service is best suited for real-time anomaly detection in IoT sensor data?
Ans: Amazon Kinesis Data Analytics
Q: Which AWS service would you use to create a private, high-bandwidth network connection between AWS and your data center, office, or colocation environment?
Ans: AWS Direct Connect
Q: What AWS feature allows you to connect your VPC to a remote network using an IPsec VPN tunnel?
Ans: AWS Client VPN
Q: Which AWS service provides a network border control as a managed service to protect your network?
Ans: AWS Network Firewall
Q: What AWS feature allows you to create a private namespace that can be accessed only through your VPC?
Ans: Amazon Route 53 Private Hosted Zones
Q: Which AWS service would you use to implement flexible network topologies that can change dynamically?
Ans: AWS Transit Gateway
Q: What AWS feature allows you to advertise your AWS IP address ranges to your on-premises network?
Ans: Direct Connect Gateway
Q: Which AWS service provides a fully managed service for deploying, operating, and scaling dedicated AWS endpoints?
Ans: AWS Global Accelerator
Q: What AWS feature allows you to create a private dedicated connection between your VPC and an AWS service in another account?
Ans: VPC Endpoint Services (AWS PrivateLink)
Q: Which AWS service would you use to monitor VPC network traffic?
Ans: VPC Flow Logs
Q: What AWS feature allows you to logically isolate EC2 instances within a subnet while maintaining network connectivity between them?
Ans: Network ACLs
Q: Which AWS service provides a scalable, pay-as-you-go Domain Name System (DNS) web service?
Ans: Amazon Route 53
Q: What AWS feature allows you to create a VPN connection between your VPC and your on-premises network?
Ans: AWS Site-to-Site VPN
Q: Which AWS service would you use to distribute incoming application traffic across multiple EC2 instances?
Ans: Elastic Load Balancing
Q: What AWS service provides a web application firewall to protect your web applications from common exploits?
Ans: AWS WAF
Q: Which AWS service would you use to create a private connection between a VPC and supported AWS services without using public IP addresses?
Ans: VPC Endpoints
Q: What AWS feature allows you to connect multiple VPCs together as if they were on the same network?
Ans: VPC Peering
Q: Which AWS service provides a fully managed NAT (Network Address Translation) service?
Ans: NAT Gateway
Q: What AWS service would you use to establish a dedicated network connection from your on-premises data center to AWS?
Ans: AWS Direct Connect
Q: Which VPC component allows you to control inbound and outbound traffic to AWS resources?
Ans: Security Groups
Q: What AWS service would you use to create a private network isolated from other networks within the AWS cloud?
Ans: Amazon VPC
Q: What AWS service would you use to provide secure, global content delivery?
Ans: Amazon CloudFront with AWS WAF
Q: Which AWS service provides security assessments for containers?
Ans: Amazon ECR image scanning
Q: What AWS feature allows you to analyze VPC network traffic?
Ans: VPC Flow Logs
Q: Which AWS service provides a simple way to create and manage encryption keys?
Ans: AWS Key Management Service (KMS)
Q: What AWS feature allows you to centrally manage firewall rules across multiple accounts and VPCs?
Ans: AWS Network Firewall
Q: Which AWS service provides a managed threat detection service?
Ans: Amazon GuardDuty
Q: What AWS service would you use to securely store and manage API keys?
Ans: AWS Secrets Manager
Q: Which AWS service provides automated reasoning to help identify security issues across your AWS infrastructure?
Ans: Amazon Detective
Q: What AWS feature allows you to control network access to EC2 instances?
Ans: Security Groups
Q: Which AWS service provides a secure and compliant data lake for analytics?
Ans: Amazon Macie
Q: What AWS service would you use to centrally manage and enforce compliance rules across multiple AWS accounts?
Ans: AWS Config
Q: Which AWS service provides a dedicated hardware security module (HSM) for regulatory compliance?
Ans: AWS CloudHSM
Q: What AWS service would you use to scan your applications for security vulnerabilities and deviations from best practices?
Ans: Amazon Inspector
Q: Which AWS service provides managed Distributed Denial of Service (DDoS) protection?
Ans: AWS Shield
Q: What AWS feature would you use to log API calls made to your AWS account?
Ans: AWS CloudTrail
Q: Which AWS service provides web application firewall capabilities?
Ans: AWS WAF
Q: What AWS service would you use to encrypt data at rest in Amazon S3?
Ans: Amazon S3 Server-Side Encryption
Q: Which AWS service provides temporary, limited-privilege credentials for EC2 instances?
Ans: IAM Roles
Q: What AWS service would you use to manage user access and permissions across AWS services?
Ans: AWS Identity and Access Management (IAM)
Q: Which AWS service provides centralized control of your AWS environment?
Ans: AWS Organizations
Q: What AWS feature allows you to replicate data across multiple regions for disaster recovery?
Ans: Amazon RDS Multi-AZ deployments with Cross-Region Read Replicas
Q: Which AWS service provides a central repository for storing and versioning data assets?
Ans: AWS Lake Formation
Q: What AWS service would you use for data integration and ETL in a serverless environment?
Ans: AWS Glue
Q: Which AWS service provides a fully managed MySQL and PostgreSQL-compatible relational database?
Ans: Amazon Aurora
Q: What AWS service would you use for a fully managed Apache Cassandra-compatible database?
Ans: Amazon Keyspaces
Q: Which AWS service provides a unified data preparation tool for machine learning?
Ans: Amazon SageMaker Data Wrangler
Q: What AWS service would you use for stream processing with SQL?
Ans: Amazon Kinesis Data Analytics
Q: Which AWS service provides a fully managed in-memory caching system?
Ans: Amazon ElastiCache
Q: What AWS feature allows you to query data across different AWS data stores?
Ans: AWS Lake Formation
Q: Which AWS service would you use for a fully managed document database?
Ans: Amazon DocumentDB
Q: What AWS service provides a fully managed graph database?
Ans: Amazon Neptune
Q: Which AWS service would you use for a fully managed time series database?
Ans: Amazon Timestream
Q: What AWS service provides a serverless query service to analyze data directly in S3?
Ans: Amazon Athena
Q: Which AWS service would you use for a fully managed Apache Spark environment?
Ans: Amazon EMR with Spark
Q: What AWS service provides a fully managed Apache Kafka-compatible event streaming platform?
Ans: Amazon MSK
Q: Which AWS service would you use for processing large datasets using the Hadoop framework?
Ans: Amazon EMR
Q: What AWS service provides a centralized metadata repository for data lakes?
Ans: AWS Glue Data Catalog
Q: Which AWS service would you use for a fully managed data warehouse?
Ans: Amazon Redshift
Q: What AWS service provides a fully managed extract, transform, and load (ETL) service?
Ans: AWS Glue
Q: Which AWS service would you use for real-time streaming data processing?
Ans: Amazon Kinesis Data Streams
Q: Which AWS feature allows you to securely access your private resources in a VPC from your on-premises network without a VPN?
Ans: AWS Direct Connect plus AWS PrivateLink
Q: What AWS service would you use to implement network segmentation and microsegmentation in a VPC?
Ans: AWS Network Firewall
Q: Which AWS feature allows you to advertise your AWS IP address ranges to your on-premises network?
Ans: AWS Direct Connect with BGP
Q: What AWS service provides a way to create and manage a global network of interconnected VPCs and on-premises networks?
Ans: AWS Cloud WAN
Q: Which AWS feature allows you to create a VPN connection between your VPC and your remote network using your own VPN customer gateway device?
Ans: AWS Site-to-Site VPN with a Customer Gateway
Q: What AWS service would you use to monitor VPC network traffic at the packet level?
Ans: VPC Traffic Mirroring
Q: Which AWS feature allows you to control inbound and outbound traffic to AWS resources at the subnet level?
Ans: Network Access Control Lists (NACLs)
Q: What AWS service would you use to create a private network connection between AWS and your data center, office, or colocation environment?
Ans: AWS Direct Connect
Q: Which AWS feature allows you to create a private namespace that can be accessed only through your VPC?
Ans: Amazon Route 53 Private Hosted Zones
Q: What AWS service provides a network-level protection against DDoS attacks?
Ans: AWS Shield
Q: Which AWS feature allows you to connect multiple VPCs across different AWS accounts and regions?
Ans: AWS Transit Gateway with inter-region peering
Q: What AWS service would you use to protect your web applications from common web exploits?
Ans: AWS WAF
Q: Which AWS feature allows you to create a logically isolated section of the AWS Cloud where you can launch AWS resources in a virtual network that you define?
Ans: Amazon Virtual Private Cloud (VPC)
Q: What AWS service provides a fully managed, highly available, and scalable Domain Name System (DNS) web service?
Ans: Amazon Route 53
Q: Which AWS feature allows you to extend your on-premises network to AWS using an IPsec VPN tunnel over the internet?
Ans: AWS Site-to-Site VPN
Q: What AWS service would you use to implement flexible network topologies that can change dynamically?
Ans: AWS Transit Gateway
Q: Which AWS feature allows you to create a private dedicated connection between your VPC and an AWS service in another account?
Ans: VPC Endpoint Services (AWS PrivateLink)
Q: What AWS service provides a way to intelligently route traffic globally for the best performance?
Ans: Amazon Global Accelerator
Q: Which AWS feature allows you to extend your on-premises network to the cloud with consistent network policies?
Ans: AWS Cloud WAN
Q: What AWS service would you use to create a private managed connection between VPCs across different AWS accounts?
Ans: AWS PrivateLink