[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"lesson-aws-certified-cloudops-engineer-associate-networking-content-delivery-en":3,"cheat-sheet---en":3,"topic-info----en":3,"prev-aws-certified-cloudops-engineer-associate-networking-content-delivery-en":3,"next-aws-certified-cloudops-engineer-associate-networking-content-delivery-en":3,"domain-info-aws-certified-cloudops-engineer-associate-networking-content-delivery-en":4},null,{"meta":5,"body":8},{"title":6,"description":7},"Networking and Content Delivery","Move traffic where it should go and find out why it is not going there: VPC design, private and hybrid connectivity, Route 53 DNS, CloudFront and Global Accelerator, network protection services, network cost optimization, and systematic troubleshooting with flow logs and Reachability Analyzer.",{"type":9,"value":10,"toc":61},"minimark",[11,15,18,23,51,55,58],[12,13,14],"p",{},"An instance in a private subnet times out when it calls S3. The application did not change and the IAM role is fine, so the request is dying somewhere in the path: a missing route, a NAT gateway in the wrong subnet, a security group with no outbound rule, or an endpoint policy nobody remembers writing. This domain teaches you to build that path deliberately and to walk it in order when it breaks.",[12,16,17],{},"Networking carries 18% of SOA-C03, but its share of real incidents is higher. Failures from other domains surface here first: a target group that reports unhealthy, a Lambda function that cannot reach its database, a stack that hangs on a resource with no route out.",[19,20,22],"h2",{"id":21},"what-this-domain-covers","What This Domain Covers",[24,25,26,30,33,36,39,42,45,48],"ul",{},[27,28,29],"li",{},"VPC building blocks: CIDR planning, public and private subnets, and which route table sends traffic where",[27,31,32],{},"Internet gateways, NAT gateways, and egress-only gateways, including the IPv6 case and the cost NAT adds",[27,34,35],{},"Security groups against network ACLs: stateful versus stateless, and which one a scenario is describing",[27,37,38],{},"Private access with gateway and interface VPC endpoints, plus PrivateLink for services you or a partner expose",[27,40,41],{},"Connecting networks with VPC peering, Transit Gateway, Site-to-Site VPN, and Client VPN",[27,43,44],{},"Route 53 hosted zones, Resolver for hybrid name resolution, and the routing policies (weighted, latency, failover, geolocation)",[27,46,47],{},"CloudFront distributions and caching behavior, and where Global Accelerator fits instead",[27,49,50],{},"Auditing network protection services, cutting data transfer and NAT spend, and troubleshooting with VPC Flow Logs, Reachability Analyzer, and CloudWatch network metrics",[19,52,54],{"id":53},"why-it-matters","Why It Matters",[12,56,57],{},"Exam questions here hand you a connection that fails and four plausible reasons for it. What you need is an ordered method: route table, then gateway, then network ACL, then security group, then the policy on the endpoint or the service. The same order works whether the destination is S3, an on-premises data center, or another VPC.",[12,59,60],{},"The boundaries carry most of the marks. Security group against network ACL, gateway endpoint against interface endpoint, peering against Transit Gateway, CloudFront against Global Accelerator: each pair looks interchangeable until one constraint in the scenario separates them.",{"title":62,"searchDepth":63,"depth":63,"links":64},"",3,[65,67],{"id":21,"depth":66,"text":22},2,{"id":53,"depth":66,"text":54}]