8 of 8 cards free · no sign-in needed
A logically isolated virtual network you define in a Region. You control IP range (CIDR), subnets, route tables, and gateways.
A public subnet has a route to an internet gateway; a private subnet does not. Subnets live in a single AZ — spread them across AZs for resilience.
A horizontally-scaled, redundant VPC component that allows communication between the VPC and the internet. Required for public subnets.
Lets instances in a private subnet make outbound connections to the internet (e.g. updates) while preventing the internet from initiating connections to them. Lives in a public subnet.
A set of rules (routes) that determine where network traffic is directed. Each subnet associates with one route table; the local route enables intra-VPC traffic.
Security group = stateful, instance-level, allow-rules only. Network ACL = stateless, subnet-level, allow + deny rules evaluated in order.
A static, public IPv4 address you can allocate and remap between instances/NAT gateways to mask failures.
Sign in (free) to flip every card, mark what you know, and pick up exactly where you left off.
After sign-in: Space flip · ←→ navigate · K knew it · S skip