Skip to content

Chapter 3 of 7

Networking and Content Delivery

Inside a VPC, the choice of how instances reach the internet or AWS services affects both security and cost. A NAT Gateway lets private-subnet resources make outbound calls (for package updates, for example) while remaining unreachable from the internet. Gateway VPC Endpoints are free and route traffic privately to S3 and DynamoDB through the VPC routing table. Interface VPC Endpoints, powered by PrivateLink, provide private connectivity to most other AWS services for an hourly and per-GB price.

Connecting multiple VPCs and on-premises networks quickly grows complex. VPC peering is one-to-one with no transitive routing, so a hub-and-spoke pattern with many VPCs is better served by AWS Transit Gateway. AWS Network Firewall delivers managed stateful inspection inside a VPC, and AWS Firewall Manager centrally applies WAF and firewall rules across an organization. For hybrid DNS, Route 53 Resolver inbound and outbound endpoints let on-premises resolvers query private hosted zones and let VPC resources resolve on-premises names.

Load balancing and global traffic management are layered services. The Application Load Balancer (ALB) operates at layer 7 and supports path- and host-based routing, ideal for microservices and HTTP workloads, and its listener security policy is where you enforce TLS 1.2 or higher. The Network Load Balancer (NLB) operates at layer 4, preserves client source IPs, supports static IPs, and handles TCP and UDP. In front of regional ALBs, AWS Global Accelerator advertises anycast IPs from the AWS edge for cross-region failover and lower first-hop latency. Route 53 supports failover routing, where health-checked primary and secondary records automatically redirect traffic when the primary becomes unhealthy. CloudFront, the CDN, accelerates static and dynamic content at the edge; to force HTTPS you set the Viewer Protocol Policy to HTTPS Only or Redirect HTTP to HTTPS, PriceClass_100 limits costs to North America and Europe edges, and Origin Access Control keeps S3 origins private.

All chapters
  1. 1Object, Block, and File Storage
  2. 2Compute Foundations
  3. 3Networking and Content Delivery
  4. 4Databases, Caching, and Analytics
  5. 5Messaging, Streaming, and APIs
  6. 6Security, Identity, and Compliance
  7. 7Monitoring, Observability, and Disaster Recovery

Drill it

Reading is not remembering. These come from the AWS Saa C03 Exam Cheatsheet deck:

Q

Which AWS service is best for object storage with 11 9s durability?

Amazon S3 — durability 99.999999999%.

Q

Cheapest S3 class for rarely-accessed data with 12h retrieval?

S3 Glacier Deep Archive.

Q

S3 class for unknown/changing access patterns?

S3 Intelligent-Tiering — auto-moves objects, no retrieval fees.

Q

Feature that prevents accidental S3 object deletion?

S3 Versioning + MFA Delete.