Virtual Private Clouds and the AWS Solutions Architect exam

A solid understanding of Virtual Private Cloud (VPC) architecture is central to just about everything connected to the Amazon Web Services universe. But if you’re thinking of taking the AWS Solutions Architect Associate level exam, it’s critical.

In this post, I will explain why I believe this to be true and specify which VPC elements will require your greatest focus if you’re serious about passing this exam.

Take a look at the AWS Solutions Architect exam blueprint. You will see a table breaking the exam material down into four areas:

Designing highly available, cost-efficient, fault tolerant, scalable systems. 60%
Implementation/Deployment. 10%
Data Security. 20%
Troubleshooting. 10%
TOTAL 100%

As you can see, 60% of the exam is specifically focused on Designing highly available, cost-efficient, fault tolerant, scalable systems. In my experience, what that really means is…understand the virtual private cloud.

So let’s outline the virtual private cloud elements I think are the most critical.

Critical Virtual Private Cloud Elements

1. Security Groups and Network ACLs

Amazon virtual private clouds come with two built-in security tools:

  • Security groups work at the instance level to control all traffic into and out of associated Amazon EC2 instances.
  • Network access control lists (ACLs) work at the subnet level to control all traffic into and out of associated subnets.

As a complete guide to VPC security is way beyond the scope of this post, be sure to read through the excellent Amazon documentation on the subject. A valid course to deep dive into AWS Networking is this Networking Fundamentals for AWS course in the Cloud Academy library. 

For now, here’s an excellent illustrative diagram from Amazon’s documentation:

Virtual Private Cloud networking with security groups, subnets, network ACL, routing table, VPG, and internet gateway.
An example of virtual private cloud networking with Security Groups, Subnets, Network ACL, Routing tables, VPG, and Internet Gateway

2. Public and Private IP Addresses

Make sure you understand the difference between public and private IP addresses. Simply put: private IP addresses are not accessible from the Internet but are used for communication between instances within your virtual private cloud. Public IP addresses, on the other hand, are accessible from the Internet and can be used for communication between your instances and the Internet, or with other AWS services that have public endpoints.

The Solutions Architect exam may contain some tricky IP-related questions. You might be expected to know how to connect a private IP to the internet or to understand how specific protocols can affect connectivity. You’ll also need to understand how public and private IP Addresses interact with Security Groups and Network ACLs.

Again, AWS documentation and the Cloud Academy’s Creating and Configuring Basics for Your EC2 Network course are your two best friends here.

3. NAT Instances

You are almost certain to see at least one Network Address Translation (NAT) question on the exam. How, for instance, can you connect an instance from a private subnet to the internet (to allow software updates)? You could create a special NAT instance in a public subnet in your virtual private cloud to provide controlled outbound connectivity to instances in the private subnet while restricting all inbound traffic.

If you’ve never set up a virtual private cloud on AWS, I suggest that you do it now. Play around with various VPC configuration profiles to see for yourself how your public and private networks interact between themselves and the outside world.

4. Virtual private cloud peering

A VPC peering connection is a networking connection between two virtual private clouds that enables you to route traffic between them using private IP addresses. This configuration scenario is important enough that you might face a related question on the exam. Again, the best option is to play around on the AWS console and try and set up 2 or more VPC’s and then play around with routing traffic between them using private IP addresses.

Conclusion and other virtual private cloud concepts

I cannot overstate the importance of fully understanding VPCs for passing the AWS Solutions Architect Associate exam. This article obviously doesn’t cover the whole topic. You’ll still need to work on other pieces of the puzzle like Network Interfaces, Route tables, and Internet gateways, and how they all interact with each other.

The AWS exam is well designed as a challenging test of your practical skills. As there are very few obvious or easy answers, you should definitely not take passing for granted, and perhaps more than any other topic, you should focus your preparations on VPC.

Avatar

Written by

Michael Sheehy

I have been UNIX/Linux System Administrator for the past 15 years and am slowly moving those skills into the AWS Cloud arena. I am passionate about AWS and Cloud Technologies and the exciting future that it promises to bring.


Related Posts

Joe Nemer
Joe Nemer
— April 3, 2020

Breaking News: All AWS Certification Exams Now Available Online

Remote proctoring for all AWS certifications Cloud Academy is an Advanced AWS Technology Partner, and we are happy to announce all AWS certification exams are available online!  What does this mean for you? You can stay focused on your certification goal. Or you can start a certifica...

Read more
  • AWS
  • AWS certification
  • AWS Certifications
Connie Benton
Connie Benton
— April 1, 2020

How To Build a Career with AWS Certifications

From Iaas and PaaS solutions to digital marketing, cloud computing reshapes the world of technology. As the influence of this technology grows, so does investment. Tens of billions of dollars are being spent on cloud computing-related services each year. This influx is continuing to inc...

Read more
  • AWS
  • Certifications
Vijayakumar Athithan
Vijayakumar Athithan
— March 27, 2020

What is Cognito in AWS?

Web applications usually allow a valid username and password combination for successful sign in to the application. Modern authentication flows incorporate more approaches to ensure user authentication. When using AWS, this is no exception, thanks to the abilities and features offered b...

Read more
  • AWS
  • AWS Cognito
  • Solutions Architect
Avatar
Andrew Larkin
— March 20, 2020

The 12 AWS Certifications: Which is Right for You and Your Team?

As companies increasingly shift workloads to the public cloud, cloud computing has moved from a nice-to-have to a core competency in the enterprise. This shift requires a new set of skills to design, deploy, and manage applications in cloud computing. As the market leader and most ma...

Read more
  • AWS
  • AWS Certifications
Alisha Reyes
Alisha Reyes
— March 17, 2020

Cloud Academy’s Blog Digest: How Do AWS Certifications Increase Your Employability, How to Become a Microsoft Certified Azure Data Engineer, and more

With everything going on right now, it's likely that the only thing you've been reading lately is related to the coronavirus pandemic. It's important to stay informed during these times, but it's also good to jump into something that can take your mind off of the current situation for j...

Read more
  • AWS
  • Azure
  • blog digest
  • Certifications
  • Cloud Academy
  • programming
  • Security
Avatar
Cloud Academy Team
— March 13, 2020

Which Certifications Should I Get?

As we mentioned in an earlier post, the old AWS slogan, “Cloud is the new normal” is indeed a reality today. Really, cloud has been the new normal for a while now and getting credentials has become an increasingly effective way to quickly showcase your abilities to recruiters and compan...

Read more
  • AWS
  • Azure
  • Certifications
  • Cloud Computing
  • Google Cloud Platform
Alisha Reyes
Alisha Reyes
— March 7, 2020

New on Cloud Academy: Intro to GitOps; AWS Courses; Java, Python, Amazon Linux 2, Ubuntu, & Docker Playgrounds; and much more

New Lab Playgrounds This month, our Content Team released six new "playground labs." Our playground labs provide a safe and secure sandbox environment for you to explore your own ideas, follow along with Cloud Academy courses, or answer your own questions — all without having to instal...

Read more
  • AWS
  • Azure
  • gitops
  • Google Cloud Platform
  • lab playground
  • programming
Alisha Reyes
Alisha Reyes
— March 6, 2020

New on Cloud Academy: Intro to GitOps; AWS Courses; Java, Python, Amazon Linux 2, Ubuntu, & Docker Playgrounds; and much more

New Lab Playgrounds This month, our Content Team released six new "playground labs." Our playground labs provide a safe and secure sandbox environment for you to explore your own ideas, follow along with Cloud Academy courses, or answer your own questions — all without having to instal...

Read more
  • AWS
  • Azure
  • gitops
  • Google Cloud Platform
  • lab playground
  • programming
Patrick Navarro
Patrick Navarro
— March 4, 2020

AWS Certifications: How Do They Increase Your Employability and Progress Your Career?

AWS certifications are no walk in the park. They’re designed to validate in-depth, specialist knowledge and comprehensive experience, often requiring months of dedicated studying to earn even for those already working with the cloud platform. But the rewards that AWS professionals ca...

Read more
  • AWS
  • AWS certification
  • certification
Avatar
Chandan Patra
— February 21, 2020

Elasticsearch vs. CloudSearch: AWS Cloud Search Choices

Elasticsearch vs. CloudSearch: What's the main difference? Let's compare AWS-based cloud tools: Elasticsearch vs. CloudSearch. While both services use proven technologies, Elasticsearch is more popular, open source, and has a flexible API to use for customization; in comparison, CloudS...

Read more
  • AWS
  • Azure
  • cloudsearch
  • elasticsearch
Avatar
Andrew Larkin
— February 13, 2020

Cloud Academy Content Roadmap Updates

Welcome to our Q1 2020 roadmap. This is the content we plan to build over the next three months, between February 1 - and April 30, 2020. Let's look at some of our roadmap highlights. Atlassian Bamboo for CI/CD We had a lot of requests for practical guides on how to apply DevOps tool...

Read more
  • Artificial Intelligence
  • AWS
  • Azure
  • Docker
  • Google Cloud Platform
  • Kubernetes
  • Machine Learning
Alisha Reyes
Alisha Reyes
— February 7, 2020

New on Cloud Academy: Git Labs, CKA and CKAD Lab Challenges, AWS and Azure Learning Paths, AGILE, and Much More

We just kicked off our first Free Weekend of 2020. This means we've unlocked our Training Library for just 72 hours. Until Sunday at 11:59 pm (PST), you can get unlimited access to our industry-leading learning paths, courses, certification prep exams, and our most popular hands-on labs...

Read more
  • agile
  • AWS
  • Azure
  • Google Cloud Platform
  • Linux
  • OWASP
  • programming
  • red hat
  • scrum