6 of 6 cards free · no sign-in needed
Public: has a route to an Internet Gateway → resources can receive internet traffic (e.g. load balancers). Private: no direct internet route → resources inaccessible from internet (e.g. databases). Use NAT Gateway for outbound-only access.
Security Groups: stateful, instance-level firewall — return traffic automatically allowed. Network ACLs: stateless, subnet-level firewall — must explicitly allow inbound AND outbound. Both provide defence-in-depth.
Scalable DNS service that routes internet traffic to AWS resources. Supports routing policies: simple, weighted, latency, failover, geolocation, multivalue. Can register domain names.
Dedicated private network link between on-premises and AWS. Bypasses the public internet for consistent throughput, lower latency, and potentially reduced data transfer costs. Not encrypted by default — combine with VPN for encryption.
Content Delivery Network (CDN) that caches content at 400+ edge locations globally. Reduces latency for static assets, videos, APIs. Integrates with WAF, Shield, and S3. Origin can be S3, ALB, EC2, or custom HTTP server.
Sign in (free) to flip every card, mark what you know, and pick up exactly where you left off.
After sign-in: Space flip · ←→ navigate · K knew it · S skip