Skip to main content
CloudCareerLabs Logo CloudCareerLabs
AWS Technical Screening Guides & Flashcard Preparation

Free AWS Interview Questions

Technical hiring standards for systems engineers demand quick problem-solving and conceptual clarity. This guide compiles the most common screening questions, complete with structural explanations and diagnostic walkthroughs. Prepare for your cloud engineering interview with our curated AWS interview questions guide. We cover essential questions on VPC configuration, IAM security policies, EC2 auto-scaling, S3 storage tiers, RDS replication, and serverless architectures using AWS Lambda. By utilizing standard patterns, engineers can build robust, highly automated platforms.

SM
Written by Sachin Mehta • Founder & Principal Cloud Architect Principal cloud architect and scalable container specialist.

Principles of a Well-Architected AWS Infrastructure

When building systems on Amazon Web Services, DevOps teams must align designs to the AWS Well-Architected Framework. This framework is built on six pillars: Operational Excellence, Security, Reliability, Performance Efficiency, Cost Optimization, and Sustainability.

Visualizing a Highly Available Multi-AZ Architecture

AWS Highly Available VPC Architecture

1. Amazon Route 53: Provides DNS routing, failover configurations, and health checks.

2. Application Load Balancer (ALB): Distributes incoming application traffic across target EC2 instances or ECS tasks in multiple Availability Zones.

3. NAT Gateway: Placed in public subnets to allow EC2 instances in private subnets outbound access to the internet for system updates, while rejecting unsolicited inbound connections.

4. Amazon Aurora: Offers MySQL/PostgreSQL-compatible relational databases with storage replicated across three Availability Zones.

---

Technical Q&As (AWS System Design)

Q1: What is the difference between a NAT Gateway and a VPC Endpoint? When would you use a VPC Gateway Endpoint instead of an Interface Endpoint?

Answer: Both components handle network routing, but they serve opposite directions:

  • NAT Gateway: Translates private IP addresses to public IPs, permitting private EC2 instances outbound access to the public internet. Traffic travels over the public internet gateway.
  • VPC Endpoint: A private connection powered by AWS PrivateLink. It allows resources in your VPC to communicate with AWS services (like S3, DynamoDB, or KMS) using private IP addresses. Traffic never leaves the Amazon network backbone.

AWS offers two types of VPC Endpoints:

1. Gateway Endpoints: Available only for Amazon S3 and DynamoDB. They are free of charge and operate by writing a route entry in your VPC route tables pointing to the service prefix list.

2. Interface Endpoints: Available for almost all other AWS services (EC2, Secrets Manager, etc.). They cost an hourly fee and charge for data processed. They place an ENI (Elastic Network Interface) with a private IP inside your subnet and register local DNS entries.

Q2: How do you protect against "Access Denied" errors when EC2 instances upload logs to an S3 bucket? Trace the role of IAM Instance Profiles.

Answer: Hardcoding AWS credentials (Access Key and Secret Key) inside configuration files or scripts is a severe security risk. To authorize EC2 instances, we use IAM Instance Profiles:

1. IAM Role: Create an IAM Role with a trust policy that allows the ec2.amazonaws.com service to assume the role.

2. Permissions Policy: Attach a policy to the role granting S3 permissions (e.g., s3:PutObject).

3. Instance Profile: Associate the IAM Role with the EC2 instance using an Instance Profile wrapper.

4. Credential Retrieval: Inside the instance, the AWS SDK automatically queries the IMDSv2 (Instance Metadata Service) to retrieve short-lived session credentials:

bash

# Querying IMDSv2 token first

TOKEN=$(curl -s -X PUT "http://169.254.169.254/latest/api/token" -H "X-aws-ec2-metadata-token-ttl-seconds: 21600")

# Retrieving temp credentials

curl -s -H "X-aws-ec2-metadata-token: $TOKEN" http://169.254.169.254/latest/meta-data/iam/security-credentials/

This secures credentials by generating new temporary tokens every few hours automatically.

Q3: What are the differences between Security Groups and Network Access Control Lists (NACLs)?

Answer: The differences represent two layers of firewall protection inside a VPC:

AttributeSecurity GroupNetwork Access Control List (NACL)
Operating LayerOperates at the Instance level (virtual interface).Operates at the Subnet boundary level.
StatefulnessStateful: Outbound response traffic is automatically allowed regardless of outbound rules.Stateless: Response packets must be explicitly allowed by rules in both directions.
Rules TypeSupports "Allow" rules only.Supports both "Allow" and "Deny" rules.
Execution OrderAll rules are evaluated simultaneously.Rules are processed sequentially in number order (lowest to highest).

---

AWS CLI Troubleshooting Snippets

Verifying VPC Route Table Configuration

To check if a subnet is properly routed to the internet gateway (IGW):

aws ec2 describe-route-tables --filters "Name=vpc-id,Values=vpc-0123456789abcdef0" --query "RouteTables[*].Routes"

Look for a route with DestinationCidrBlock: 0.0.0.0/0 and an GatewayId starting with igw-.

Creating a Gateway VPC Endpoint for S3

To set up private S3 connections for a VPC without NAT fees:

aws ec2 create-vpc-endpoint   --vpc-id vpc-0123456789abcdef0   --service-name com.amazonaws.us-east-1.s3   --route-table-ids rtb-0987654321fedcba0

AWS Infrastructure Technical Interview Challenge

Interactive Troubleshooting Lab

The interviewer asks you to debug a connection timeout issue: an EC2 instance in a public subnet cannot be reached via SSH. You need to outline your step-by-step process to locate the firewall block.

production_manifest.yaml
resource "aws_vpc" "main" {
  cidr_block           = "10.0.0.0/16"
  enable_dns_hostnames = true
  tags = { Name = "production-vpc" }
}

resource "aws_subnet" "private" {
  vpc_id            = aws_vpc.main.id
  cidr_block        = "10.1.1.0/24"
  availability_zone = "us-east-1a"
  tags = { Name = "private-subnet" }
}

resource "aws_vpc_endpoint" "s3" {
  vpc_id       = aws_vpc.main.id
  service_name = "com.amazonaws.us-east-1.s3"
  vpc_endpoint_type = "Gateway"
  route_table_ids   = [aws_vpc.main.main_route_table_id]
}

Diagnostic & Resolution Steps

Recommended remediation commands

To resolve this system outage, follow these step-by-step diagnostic and remediation instructions: 1. Check the instance status and public IP assignment. 2. Verify the VPC route table has a route for `0.0.0.0/0` pointing to an Internet Gateway (IGW). 3. Inspect the Security Group associated with the instance to ensure inbound traffic on port 22 is allowed from your IP address. 4. Check the Network Access Control List (NACL) for the subnet to confirm it doesn't block inbound port 22. Here is the clean, verified configuration file or script template demonstrating how to resolve this configuration drift or deploy the service correctly:

Interview Success Benchmarks for AWS

Core competencies & reference questions

To prepare effectively for the challenges of managing AWS, review the key domains and common test questions detailed below. These represent actual operational tasks expected of DevOps engineers in modern software environments.

Core Question: Describe the startup lifecycle of a service in this environment.

Explain how components verify network connections, synchronize states with configuration registries, and signal health back to the control plane.

Verification Checked

Scenario Question: How do you troubleshoot socket exhaustion or API latency issues?

Detail debugging steps including connection state counts, routing analysis, scaling policies, and file handle limits.

Verification Checked

Architecture Question: Explain how this technology guarantees idempotency.

Provide details on declarative configurations, state management comparisons, and how the target engine updates only modified parameters.

Verification Checked

Frequently Asked Questions

Technical reference answers

Q: What AWS concepts are most frequently tested in interviews?

Expect questions on VPC design (subnets, route tables, IGW vs NAT), IAM roles, S3 security, and High Availability/Disaster Recovery strategies.

Q: How do I explain AWS cost optimization in an interview?

Discuss right-sizing EC2 instances, utilizing S3 lifecycle policies, leveraging AWS Savings Plans/Reserved Instances, and monitoring with AWS Cost Explorer.

Q: Are scenario-based questions common in AWS interviews?

Yes, interviewers often present scenario questions, such as how to design a highly available, fault-tolerant web application under budget constraints.

Ready to test your skills in real-time?

Take the next step in your cloud career. Access our interactive simulators, test your command-line capabilities on live terminals, run script execution pipelines, and verify your configuration files instantly.

Practice Flashcards for AWS  →