Master VPC architectures, Security Groups/NACLs, storage systems, IAM permissions, serverless platforms, and cloud cost management.
SM
Written by Sachin Mehta • Founder & Principal Cloud ArchitectPrincipal cloud infrastructure specialist and systems architect. CKA & CKS certified.
Interactive Flashcards
# 1
Unreviewed
Consider a VPC with only one subnet. There are no route tables, no security groups, no configurations — it’s completely empty. Do you think it is a private subnet or a public subnet?
Answer Guide
It is a private subnet by default. In AWS VPC, a subnet is only considered public if it is associated with a route table that has a route pointing to an Internet Gateway (0.0.0.0/0 -> igw-xxxx) and has public IP assignment enabled. Without these configurations, there is no route to or from the internet, rendering it completely private.
Key Concepts Checklist
Evaluate difficulty:
# 2
Unreviewed
What is EBS and EFS? Explain the key differences clearly.
Answer Guide
EBS (Elastic Block Store) is a block-level storage volume designed for a single EC2 instance (supports Multi-Attach for specific SSDs in the same AZ). It operates at the block level and is ideal for databases or OS drives. EFS (Elastic File System) is a serverless, shared file system that supports NFSv4. It can be mounted concurrently by thousands of EC2 instances/containers across multiple AZs, adjusting capacity automatically.
Key Concepts Checklist
Evaluate difficulty:
# 3
Unreviewed
How do you set up a highly available application in AWS?
Answer Guide
Deploy the application across multiple Availability Zones (AZs) using an Auto Scaling Group (ASG) behind an Application Load Balancer (ALB). Place instances in private subnets, run databases in multi-AZ configurations (like RDS Multi-AZ or Aurora), store shared assets in EFS or S3, and manage DNS routing using Route 53 with active health checks and failover routing policies.
Key Concepts Checklist
Evaluate difficulty:
# 4
Unreviewed
How do you configure AWS IAM credentials in Jenkins for multi-account deployment?
Answer Guide
Instead of storing long-lived IAM Access Keys in Jenkins credentials, use IAM Roles. In a master/agent architecture, assign an IAM instance profile or service account (EKS IRSA) to the Jenkins agent. For multi-account access, configure the Jenkins agent role to assume target account IAM execution roles using "sts:AssumeRole" via temporary credentials.
Key Concepts Checklist
Evaluate difficulty:
# 5
Unreviewed
If you are not able to access an EC2 instance via SSH/session manager, what might be the issues?
Answer Guide
1. Security Group does not allow inbound SSH (Port 22) from your IP. 2. NACL blocks inbound/outbound SSH port or ephemeral ports. 3. Route table lacks an Internet Gateway route (for public instances) or NAT/VPC Endpoint route (for private). 4. Instance doesn't have a public IP (if public access is expected). 5. The private key (.pem) is wrong or has wrong permissions (must be chmod 400). 6. For SSM Session Manager, the SSM Agent is not running, or the instance lacks the "AmazonSSMManagedInstanceCore" IAM policy.
Key Concepts Checklist
Evaluate difficulty:
# 6
Unreviewed
What are S3 Storage Classes, and what are their use cases?
Answer Guide
S3 Standard (frequently accessed data), S3 Intelligent-Tiering (unknown/changing access patterns), S3 Standard-IA & One Zone-IA (infrequently accessed but immediate access needed), S3 Glacier Instant Retrieval, Flexible Retrieval & Deep Archive (archival data with retrieval times ranging from minutes to 12 hours).
Key Concepts Checklist
Evaluate difficulty:
# 7
Unreviewed
What are Security Groups and NACLs, and what are the key differences between them?
Answer Guide
Security Groups are stateful firewalls operating at the instance/ENI level, where return traffic is automatically allowed, and they support "allow" rules only. Network Access Control Lists (NACLs) are stateless firewalls operating at the subnet level, requiring explicit rules for inbound and outbound traffic (including ephemeral ports), and they support both "allow" and "deny" rules evaluated in numbered order.
Key Concepts Checklist
Evaluate difficulty:
# 8
Unreviewed
How do you reduce AWS costs in your DevOps project?
Answer Guide
1. Set up AWS Budgets and Cost Anomaly Detection. 2. Clean up unused resources (idle EBS volumes, unassociated Elastic IPs, old S3 versions/multipart uploads). 3. Right-size EC2, RDS, and EBS volumes using AWS Compute Optimizer. 4. Implement S3 Lifecycle policies to transition data to cheaper storage classes (e.g. Glacier). 5. Purchase Savings Plans or Reserved Instances for predictable workloads. 6. Automatically stop development environments during off-hours using AWS Instance Scheduler.
Key Concepts Checklist
Evaluate difficulty:
# 9
Unreviewed
What is the difference between VPC Peering and Transit Gateway, and when should you use each?
Answer Guide
VPC Peering is a one-to-one network connection between two VPCs. It is non-transitive and becomes complex to manage at scale (hub-and-spoke grid). Transit Gateway (TGW) acts as a centralized cloud router, allowing you to connect thousands of VPCs and on-premises networks transitively, simplifying management and network scaling.
Key Concepts Checklist
Evaluate difficulty:
# 10
Unreviewed
What is AWS Lambda, and in which scenarios would you prefer Lambda over EC2?
Answer Guide
AWS Lambda is a serverless, event-driven compute service that runs code in response to events and automatically manages compute resources. You prefer Lambda over EC2 for short-running tasks (under 15 mins), sporadic or unpredictable traffic, file processing on S3, microservices, cron jobs, and glue code where you want zero administration overhead and pay-per-use execution pricing.
Key Concepts Checklist
Evaluate difficulty:
# 11
Unreviewed
What is a NAT Gateway, how does it work, and what is its pricing implication?
Answer Guide
A NAT Gateway allows resources in private subnets to connect outbound to the internet (for updates/downloads) while preventing inbound connections from the internet. It must be placed in a public subnet with an Elastic IP and route. In terms of cost, AWS charges an hourly rate for the NAT Gateway plus a per-gigabyte data processing fee, which can be optimized by using VPC endpoints for AWS services.
Key Concepts Checklist
Evaluate difficulty:
Scenario Challenges
Select a scenario below to test your troubleshooting workflow.
Topic: Load Balancer Selection
You need to design a load balancing tier. System receives millions of requests per second of raw TCP traffic with low latency, and also needs to route HTTP traffic based on path rules. Arrange the architecture steps.
Map high-throughput raw TCP traffic to a Layer 4 Network Load Balancer (NLB) to handle peak traffic.Click to select
Configure a Layer 7 Application Load Balancer (ALB) to process path-based HTTP routing rules.Click to select
Chain the ALB behind the NLB to gain both static IP routing (NLB) and HTTP header evaluation (ALB).Click to select
Selected Sequence
No steps selected yet. Click options above in sequence.
Topic: Isolated Database Tier
Design a multi-tier network where the database has zero internet access but can be reached by the application tier. Arrange the networking rules.
Place the ALB in public subnets, EC2 app in private subnets, and RDS in isolated subnets without IGW routes.Click to select
Configure the DB subnet route tables to exclude 0.0.0.0/0 route mapping to NAT or Internet gateways.Click to select
Restrict the RDS Security Group to only permit inbound traffic on port 3306 from the EC2 application security group.Click to select
Selected Sequence
No steps selected yet. Click options above in sequence.
Topic: EBS Volume Expansion
An EC2 instance running a database reports that its 50GB EBS volume is 98% full. Expand it to 100GB without downtime.
Modify the EBS volume size directly to 100GB in the AWS console, CLI, or via Terraform.Click to select
Monitor the volume state until the optimization status changes from modifying to optimizing/complete.Click to select
Log in via SSH and run growpart followed by resize2fs (or xfs_growfs) to expand the partition and filesystem.Click to select
Selected Sequence
No steps selected yet. Click options above in sequence.
Topic: SSH Access Debugging
A developer cannot SSH into a newly launched EC2 instance. Determine the correct troubleshooting sequence.
Check if the EC2 Security Group allows inbound SSH traffic on port 22 from the developer's public IP address.Click to select
Verify that the subnet route table contains a route pointing to the Internet Gateway for public instances.Click to select
Confirm that the instance has a public IP address assigned and the developer's private SSH key (.pem) has correct file permissions (0400).Click to select
Selected Sequence
No steps selected yet. Click options above in sequence.
Topic: Storage Cost Optimization
Your S3 costs have spiked due to accumulated non-current object versions and incomplete multipart uploads. Resolve the cost leak.
Configure an S3 Lifecycle policy with a rule to abort incomplete multipart uploads after 7 days.Click to select
Add a rule to transition non-current object versions to S3 Glacier Deep Archive or permanently delete them after 30 days.Click to select
Activate S3 Storage Lens to audit empty buckets and identify duplicate datasets across accounts.Click to select
Selected Sequence
No steps selected yet. Click options above in sequence.
We value your privacy
We use cookies to analyze site traffic, personalize content, and support our free educational platforms. By clicking "Accept All", you consent to our use of cookies.