SaveMyCert
Log in
5 of 5 free questions left today·for 30 a day
SOA-C03 · Domain 5

Networking and Content Delivery practice questions

Networking and Content Delivery is worth 18% of the SOA-C03 exam — the 4th-heaviest of the 5 domains. VPC networking and private connectivity, DNS and content delivery, and troubleshooting with flow logs and network monitoring. 6 fully worked examples are further down this page, answers included.

Exam weight
18%
the 4th-heaviest of the 5 domains
Questions
60
across 3 topics
Free, no account
5/day
sign up free to remove the cap
Explanations
Every option
right and wrong

Build a practice session

5 free questions left today.

Domains

How many?

Mode

Ready when you are

10 fresh questions drawn across 1 of 5 domains, in Learn mode.

Focused review

Every question you answer incorrectly, and every question you flag while practising, is saved here automatically. Finish a session and you can come back to re-drill just those.

6 sample Networking and Content Delivery questions, fully explained

Questions from the SOA-C03 bank mapped to domain 5, with the answer key and the reasoning behind every option. None of them repeat the examples on the main SOA-C03 practice page.

Question 1Networking and Content Delivery

An operations team runs IPv6-enabled EC2 instances in private subnets that must download packages from internet repositories over IPv6. The security policy requires that no connection can be initiated from the internet to these instances. What should the team configure?

Choose one.

  • a
    Create an egress-only internet gateway and route ::/0 to it Correct

    An egress-only internet gateway is stateful and allows outbound-initiated IPv6 connections and their replies while blocking all inbound-initiated traffic — exactly the outbound-only IPv6 requirement.

  • b
    Route ::/0 to a NAT gateway in a public subnet

    NAT gateways perform network address translation for IPv4; there is no IPv6 NAT because VPC IPv6 addresses are globally unique and publicly routable.

  • c
    Route ::/0 to the VPC's internet gateway

    An internet gateway allows inbound-initiated connections to the instances' publicly routable IPv6 addresses, violating the policy.

  • d
    Create a gateway VPC endpoint for the package repositories

    Gateway endpoints support only Amazon S3 and DynamoDB; they cannot provide general outbound access to internet repositories.

The concept

VPC IPv6 addresses are globally unique and publicly routable, so IPv6 has no NAT. The egress-only internet gateway is the IPv6 construct for outbound-only access: instances can initiate connections out, and all inbound-initiated traffic is blocked.

Why that’s the answer

Routing ::/0 to an egress-only internet gateway gives the instances outbound IPv6 access while its stateful behavior blocks anything the internet initiates. A NAT gateway is wrong because it handles IPv4 only; a standard internet gateway is wrong because it exposes the publicly routable IPv6 addresses to inbound connections; and a gateway endpoint only reaches S3 and DynamoDB, not internet repositories.

How to reason it out
  1. Create an egress-only internet gateway and attach it to the VPC.
  2. In the private subnets' route tables, add a route sending ::/0 to the egress-only internet gateway.
  3. Verify security groups and NACLs permit the outbound traffic and (for NACLs) the ephemeral-port return traffic.
  4. Confirm instances can reach the repositories while inbound IPv6 connection attempts fail.

Exam tip: "IPv6, outbound only" always maps to an egress-only internet gateway — there is no IPv6 NAT.

VPC Networking and Private Connectivity for SOA-C03 — the lesson that teaches this.

Question 2Networking and Content Delivery

EC2 instances in private subnets upload hundreds of gigabytes of objects to Amazon S3 every day through a NAT gateway. The company wants this traffic to stay off the public internet at no additional data-processing cost. What should a CloudOps engineer do?

Choose one.

  • a
    Create an interface VPC endpoint for Amazon S3

    An interface endpoint keeps the traffic private but bills per hour per AZ plus per GB — it fails the no-additional-cost requirement that the gateway endpoint meets.

  • b
    Create a gateway VPC endpoint for Amazon S3 and associate it with the private subnets' route tables Correct

    Gateway endpoints for S3 have no hourly or data-processing charge, and the managed prefix-list route diverts S3 traffic away from the NAT gateway so it never touches the internet.

  • c
    Add a second NAT gateway in the same Availability Zone to share the load

    This adds another hourly charge and every byte still pays NAT data-processing rates while traversing the internet path to S3.

  • d
    Enable S3 Transfer Acceleration for the destination buckets

    Transfer Acceleration speeds uploads over the CloudFront edge network for an extra per-GB fee — it uses public endpoints and increases cost rather than eliminating it.

The concept

Gateway VPC endpoints support exactly two services — Amazon S3 and DynamoDB — and are free: no hourly fee and no data-processing fee. They work by inserting a managed prefix-list route into the route tables you select, steering service traffic through the endpoint instead of the internet path.

Why that’s the answer

A gateway endpoint satisfies both constraints at once: the traffic stays on the AWS network and the endpoint costs nothing, eliminating the NAT data-processing charges for S3 traffic. An interface endpoint is private but billed hourly plus per GB, a second NAT gateway compounds the cost problem, and Transfer Acceleration is a paid performance feature that still uses public endpoints.

How to reason it out
  1. Create a gateway VPC endpoint for the S3 service in the VPC.
  2. Select the private subnets' route tables during creation so AWS inserts the prefix-list route.
  3. Optionally attach an endpoint policy restricting access to approved buckets.
  4. Verify S3 traffic flows through the endpoint and NAT data-processing charges for it disappear.

Exam tip: "Private S3 access at no additional cost" is always a gateway VPC endpoint — the classic fix for NAT data-processing spend.

VPC Networking and Private Connectivity for SOA-C03 — the lesson that teaches this.

Question 3Networking and Content Delivery

During a network protection audit, a manager asks a CloudOps engineer what defense the company's public-facing AWS resources already have against common layer 3 and layer 4 DDoS attacks such as SYN floods, and what that protection costs. What should the engineer report?

Choose one.

  • a
    AWS Shield Advanced is enabled by default on all accounts

    Shield Advanced is the paid subscription tier with enhanced detection, cost protection, and the Shield Response Team — it must be explicitly subscribed to.

  • b
    There is no protection until a WAF web ACL is associated with each resource

    AWS WAF is a layer 7 web application firewall for requests like SQL injection; layer 3 and 4 flood protection comes from Shield Standard without any configuration.

  • c
    DDoS protection requires deploying AWS Network Firewall endpoints in every VPC

    Network Firewall is a managed stateful firewall for inspecting VPC traffic you route through it — it is not the automatic edge DDoS absorption layer.

  • d
    AWS Shield Standard already protects the resources automatically at no charge Correct

    Shield Standard is enabled automatically and free for every AWS customer, absorbing common layer 3 and 4 DDoS attacks such as SYN floods and UDP reflection at the edge.

The concept

AWS Shield Standard is automatic and free for every AWS customer, absorbing common layer 3 and 4 DDoS attacks at the edge with nothing to configure. Shield Advanced is the optional paid tier that adds enhanced detection, cost protection against DDoS-driven scaling charges, and access to the Shield Response Team.

Why that’s the answer

The accurate audit answer is that Shield Standard already covers common network-layer floods at no cost. Shield Advanced is never on by default, WAF operates at layer 7 and does not absorb SYN floods, and Network Firewall inspects routed VPC traffic rather than providing automatic edge DDoS defense.

How to reason it out
  1. Identify the attack layer in the question: SYN floods and UDP reflection are layer 3/4 events.
  2. Map layer 3/4 DDoS absorption to AWS Shield — Standard is automatic and free.
  3. Reserve Shield Advanced for requirements like cost protection or the Shield Response Team.
  4. Keep WAF (layer 7 web requests) and Network Firewall (routed VPC inspection) in their own lanes.

Exam tip: Shield Standard is automatic and free for layer 3/4 DDoS; Shield Advanced is a paid, opt-in upgrade.

VPC Networking and Private Connectivity for SOA-C03 — the lesson that teaches this.

Question 4Networking and Content Delivery

A CloudOps engineer creates a custom route table containing a route that sends 0.0.0.0/0 to the VPC's internet gateway, then launches EC2 instances with public IPv4 addresses into a newly created subnet. The instances are unreachable from the internet, and the VPC's main route table contains only the local route. What is the MOST likely cause?

Choose one.

  • a
    The custom route table is missing its local route

    Every route table automatically carries an unremovable local route for the VPC CIDR — it cannot be missing.

  • b
    The internet gateway must be placed inside the new subnet

    An internet gateway attaches to the VPC as a whole; it is never deployed into a subnet.

  • c
    The subnet was never associated with the custom route table, so it still uses the main route table Correct

    A subnet with no explicit route table association falls back to the main table — which here has only the local route and therefore no internet path.

  • d
    The instances also need a route for ::/0 to an egress-only internet gateway

    An egress-only internet gateway is for outbound-only IPv6; it is irrelevant to inbound IPv4 reachability.

The concept

Every VPC has one main route table, and each subnet uses exactly one route table. Subnets with no explicit association fall back to the main table. Creating a custom route table does nothing for a subnet until you associate the subnet with it.

Why that’s the answer

The instances have public IPs and the custom table has the IGW route, so the missing piece is the association: the new subnet is defaulting to the main table, which has no IGW route. The local route cannot be missing (it is automatic and unremovable), internet gateways attach to the VPC rather than living in subnets, and IPv6 egress has nothing to do with inbound IPv4 access.

How to reason it out
  1. Check which route table the subnet actually uses — an unassociated subnet shows the main table.
  2. Associate the subnet explicitly with the custom route table containing the 0.0.0.0/0 route to the IGW.
  3. Confirm the instances hold public IPv4 or Elastic IP addresses.
  4. Retest reachability, then review security groups and NACLs if it still fails.

Exam tip: A custom route table does nothing until the subnet is associated with it — unassociated subnets silently use the main route table.

VPC Networking and Private Connectivity for SOA-C03 — the lesson that teaches this.

Question 5Networking and Content Delivery

A private subnet's route table in a VPC with CIDR 10.0.0.0/16 contains three routes: the local route for 10.0.0.0/16, a route sending 0.0.0.0/0 to a NAT gateway, and a route sending 172.16.0.0/16 to a VPC peering connection. An instance in the subnet sends a packet to 172.16.40.9. Where does the VPC router deliver it?

Choose one.

  • a
    To the NAT gateway, because 0.0.0.0/0 matches every destination

    The default route does match, but route selection uses the most specific matching prefix, and /16 is more specific than /0.

  • b
    The packet is dropped because the routes conflict

    Overlapping routes are not an error; the router resolves them deterministically by choosing the most specific prefix.

  • c
    To the VPC peering connection, because the /16 route is the most specific match Correct

    172.16.40.9 falls inside 172.16.0.0/16, and when routes overlap the longest (most specific) prefix wins, so the peering route beats the default route.

  • d
    Through the local route, because peered VPC traffic is treated as intra-VPC

    The local route covers only the VPC's own CIDR (10.0.0.0/16); 172.16.40.9 lies outside it and belongs to the peered network.

The concept

When multiple routes in a table match a destination, the VPC router uses the most specific (longest) prefix: a /32 beats a /16, which beats 0.0.0.0/0. The unremovable local route always handles intra-VPC traffic for the VPC's own CIDR.

Why that’s the answer

172.16.40.9 matches both 0.0.0.0/0 and 172.16.0.0/16, and the /16 is more specific, so traffic goes to the peering connection. The default-route answer ignores longest-prefix matching, "dropped" wrongly treats overlap as a conflict, and the local route only covers 10.0.0.0/16.

How to reason it out
  1. List every route whose prefix contains the destination address.
  2. Compare prefix lengths — the longest prefix (largest number after the slash) wins.
  3. Here 172.16.0.0/16 beats 0.0.0.0/0, so the peering connection carries the packet.
  4. Remember the same logic explains why a gateway-endpoint prefix route diverts S3 traffic away from a NAT default route.

Exam tip: VPC routing always picks the most specific matching prefix — the default route only carries what nothing narrower claims.

VPC Networking and Private Connectivity for SOA-C03 — the lesson that teaches this.

Question 6Networking and Content Delivery

A production VPC spans three Availability Zones. Private subnets in all three AZs currently route 0.0.0.0/0 to a single NAT gateway in AZ A. The operations team must ensure that the failure of any one Availability Zone cannot remove outbound internet access for workloads in the surviving AZs. What should the team do?

Choose one.

  • a
    Enable multi-AZ mode on the existing NAT gateway

    There is no multi-AZ mode — a NAT gateway is a zonal resource that exists in exactly one Availability Zone.

  • b
    Add a second NAT gateway in another public subnet in AZ A

    Both gateways would share AZ A's failure domain, so an AZ A outage still strands every private subnet.

  • c
    Deploy a NAT gateway in a public subnet in each AZ and point each private subnet's route table at the NAT gateway in its own AZ Correct

    NAT gateways are zonal; a per-AZ NAT with AZ-local routing means an AZ failure only affects that AZ's own egress, and it also eliminates cross-AZ data charges.

  • d
    Move the NAT gateway into a private subnet in AZ B

    A NAT gateway must live in a public subnet with an internet gateway route, and a single gateway anywhere is still a single-AZ failure point.

The concept

A NAT gateway is an AZ-resident appliance. The resilient production pattern is one NAT gateway per AZ, with each private subnet routing to the NAT in its own AZ, so no AZ depends on another AZ's gateway.

Why that’s the answer

Per-AZ NAT gateways with AZ-local routes are the only listed option that removes the cross-AZ dependency: losing AZ A then affects only AZ A. "Multi-AZ mode" does not exist for NAT gateways, a second gateway in the same AZ shares the same failure domain, and a NAT gateway in a private subnet has no path to the internet at all.

How to reason it out
  1. Create a public subnet (if needed) and a NAT gateway with an Elastic IP in each AZ.
  2. Give each AZ's private subnets their own route table.
  3. In each route table, send 0.0.0.0/0 to the NAT gateway in the same AZ.
  4. Verify egress per AZ, and note the trade-off: three hourly charges instead of one, in exchange for AZ independence and no cross-AZ data fees.

Exam tip: NAT gateways are zonal — high availability means one per AZ, each serving only its own AZ's subnets.

VPC Networking and Private Connectivity for SOA-C03 — the lesson that teaches this.

What SOA-C03 domain 5 tests, topic by topic

The official exam guide breaks Networking and Content Delivery into 3 topics. The question bank follows the same split, so a weak topic shows up as a cluster of misses you can go back and read.

Published SOA-C03 practice questions per topic in Networking and Content Delivery
TopicWhat it coversQuestions
Implement and optimize networking features and connectivityExam guide task 5.1. Configuring a VPC — subnets, route tables, network ACLs, security groups, NAT gateways, internet gateway, egress-only internet gateway; private networking connectivity (VPC endpoints, AWS PrivateLink, VPC peering); auditing network protection services (Route 53 Resolver DNS Firewall, WAF, Shield, Network Firewall) in a single account; optimizing network architecture cost.20
Configure domains, DNS services, and content deliveryExam guide task 5.2. Configuring DNS with Route 53 Resolver; Route 53 routing policies, configurations, and query logging; content and service distribution with CloudFront and Global Accelerator.20
Troubleshoot network connectivity issuesExam guide task 5.3. Troubleshooting VPC configurations (subnets, route tables, network ACLs, security groups, transit gateways, NAT gateways); interpreting networking logs (VPC flow logs, ELB access logs, WAF web ACL logs, CloudFront logs, container logs); remediating CloudFront caching issues; troubleshooting hybrid and private connectivity; configuring and analyzing CloudWatch network monitoring.20
Total60

Revise Networking and Content Delivery before you drill it

Other SOA-C03 domains

Networking and Content Delivery: your questions

Networking and Content Delivery is domain 5 of the SOA-C03 exam guide and carries 18% of the scored content — the 4th-heaviest of the 5 domains. On a 65-question paper that works out to roughly 12 questions, though AWS does not publish an exact per-domain count and individual exam forms vary.

Source

The domain weight and topic list on this page come from the official SOA-C03 exam guide.