Showing posts with label transit. Show all posts
Showing posts with label transit. Show all posts

November 14, 2022

Top 20 AWS Outposts Interview Questions and Answers

 

 

Ques. 1): Why not use the AWS Outposts rack instead of operating in an AWS Region?

Answer:

The Outposts rack can accommodate applications that need low latency or local data processing. These programmes could need to interact with other local programmes, control local hardware, or reply to user requests extremely immediately. Real-time patient diagnostics or medical imaging workloads, multimedia and video streaming, and automated industrial operations are a few examples. To securely store and process client data that requires be on-site or in countries without an AWS Region, a rack can be utilised. You can run data intensive workloads on Outposts rack and process data locally when transmitting data to AWS Regions is expensive and wasteful and for better control on data analysis, backup and restore.

 

AWS(Amazon Web Services) Interview Questions and Answers

AWS Cloud Interview Questions and Answers

 

Ques. 2): Can I use Outposts rack when it is not connected to the AWS Region or in a disconnected environment?

Answer:

An Outpost must be connected to its parent AWS Region. For circumstances with little to no connection or for disconnected operations, Outposts Rack is not designed. Our advice is that customers have highly accessible networking links back to their AWS Region. If you're interested in utilising AWS services in disconnected environments like cruise ships or remote mining areas, find out more about AWS services like Snowball Edge, which are optimised to operate in circumstances with little to no connection.

 

AWS AppSync Interview Questions and Answers

AWS Cloud9 Interview Questions and Answers

 

Ques. 3): Which S3 use cases are most suited for Outposts?

Answer:

Customers in regulated industries or those who need to store and process client data securely on-site or in locations outside an AWS region should utilise S3 on Outposts. Customers may now perform data-intensive processes for local data processing and on-premises storage using S3 on Outposts. S3 on Outposts will also be beneficial if your applications need to communicate with other on-premises systems or control equipment that is located on-site, such as in a factory, hospital, or research institution.


Amazon Athena Interview Questions and Answers

AWS RedShift Interview Questions and Answers

 

Ques. 4): Can I add my own hardware to my Outposts rack as a component?

Answer:

In order to give the greatest AWS experience possible, the AWS Outposts rack offers fully integrated AWS-designed configurations with integrated top-of-rack switches and redundant power supplies. You can order as much compute and storage infrastructure as you need by selecting from the variety of Outposts rack options, or you can work with us to create a unique combination using Amazon Elastic Compute Cloud (EC2), Amazon Elastic Block Store (EBS), and Amazon Simple Storage Service that has the capacity you want (S3). You don't need to do any further setup because they have already been verified and tested, so you can start using them straight away.


AWS Cloud Practitioner Essentials Questions and Answers

AWS EC2 Interview Questions and Answers

 

Ques. 5): Is resource sharing supported by the AWS Outposts rack?

Answer:

Yes. Using the AWS Resource Access Manager (RAM) tool, you may share your AWS resources with any other AWS account or with other people who are a part of your AWS Organization. With RAM support, the Outpost owner may centrally create, manage, and distribute Outpost resources including EC2 instances, EBS volumes, subnets, and local gateways (LGWs) among several AWS accounts inside the same AWS organisation. Others may now launch and run instances, build up VPCs, and create EBS volumes using the shared Outpost.


AWS Lambda Interview Questions and Answers

AWS Cloud Security Interview Questions and Answers

 

Ques. 6): Who is responsible for the physical security of the Outposts rack in my datacenter?

Answer:

AWS provides services that provide data encryption both while usage and during transport, in addition to other highly technical security features and auditing methods. Additionally, a Nitro Security Key is physically attached to customer data. When the device is destroyed, the data is also destroyed. As part of the shared responsibility approach, customers are required to confirm that the Outpost is physically secure, that access restrictions are in place, and that it complies with all stated environmental criteria for facility, networking, and electricity. Before returning the Outposts rack hardware, the Nitro Security Key will be removed to make sure that all client data has been cryptographically erased.


AWS Simple Storage Service (S3) Interview Questions and Answers

AWS Fargate Interview Questions and Answers

 

Ques. 7): What kind of control plane data is returned to the primary AWS Region?

Answer:

Examples include relaying information about instance health, activity (started, stopped), and the underlying hypervisor system to the parent AWS Region. This information may be used by AWS to inform customers of the capacity and condition of their instances, as well as to maintain and improve the Outpost. Your team does not need to develop its own tooling in order to maintain these components and actively issue security updates and patches for your Outpost. For administrative and reporting purposes, certain metrics and bucket names from S3 on Outposts data management and telemetry may be kept in the AWS Region. When the link is lost, this data cannot be sent back to the parent Region.


AWS SageMaker Interview Questions and Answers

AWS DynamoDB Interview Questions and Answers

 

Ques. 8): Can I order an Outpost from a country or territory where the Outposts rack has not yet debuted and attach it back to a supported Region?

Answer:

No, we are only able to transport and install Outposts rack in countries and territories that permit its shipping and support.


AWS Cloudwatch interview Questions and Answers

AWS Elastic Block Store (EBS) Interview Questions and Answers

 

Ques. 9): EBS snapshots are kept where?

Answer:

Amazon S3 in the Region is the default destination for storing EBS snapshots of EBS Volumes on Outposts rack. If Amazon S3 is enabled on Outposts, you have the option of storing your snapshots locally on your Outpost. Since EBS snapshots are incremental, they only save the blocks on your Outpost that have changed since your most recent snapshot. The recorded snapshots may always be used to restore (hydrate) the EBS Volume on Outposts.


AWS Amplify Interview Questions and Answers

AWS Secrets Manager Interview Questions and Answers

 

Ques. 10): Is AWS Outposts Rack GxP compliant?

Answer:

Yes, the AWS Outposts rack adheres to GxP. AWS Outposts expand AWS services to AWS-managed equipment that is situated physically at a client site. Outposts rack capacity may be accessed locally utilising a local gateway that is routed to the customer's local network in addition to having a connection channel back to the AWS Region. The planning and verification of GxP compliance is the responsibility of life sciences companies using AWS services that are subject to GxP standards.


AWS Django Interview Questions and Answers

AWS Cloud Support Engineer Interview Question and Answers

 

Ques. 11): Can Outposts rack handle real-time applications with low-latency requirements?

Answer:

Yes, you may use Amazon RDS on Outposts to host managed Microsoft SQL Server, MySQL, and PostgreSQL databases locally for low latency workloads that need to be close to locally stored data and applications. You can manage RDS databases both locally and in the cloud using the same AWS Management Console, APIs, and CLI. Real-time applications for extremely low-latency workloads, such as workloads operating on factory floors for automated manufacturing processes, real-time medical diagnostics, and media streaming, are made possible by ElastiCache on Outposts, which enables sub-millisecond responses.


AWS Solution Architect Interview Questions and Answers

AWS Glue Interview Questions and Answers

 

Ques. 12): Do the same compliance certifications for Outposts Rack services as for AWS Services now apply?

Answer:

In addition to being HIPAA, PCI, SOC, ISMAP, IRAP, and FINMA compliant, the AWS Outposts rack is also ISO, CSA STAR, and HITRUST certified. In the following months, we plan to add more compliance certifications. You may examine the most recent certification status for AWS Services on Outposts rack on our Services in Scope page. Due to their achievement of certifications like PCI, RDS and Elasticache Redis, two AWS Services on Outposts rack, are recognised as certified on Outposts rack. Because AWS Outpost racks are housed inside the customer's data centre, the customer is in charge of the physical security and access controls around the Outpost for compliance certification under the AWS Shared Responsibility model.


AWS Cloud Interview Questions and Answers

AWS VPC Interview Questions and Answers         

 

Ques. 13): Exist any prerequisites before I can set up my Outposts 42U racks?

Answer:

Your site must satisfy the basic power, networking, and space requirements in order to host an Outpost. An Outposts rack can support uplink rates of 1-10-40-100 Gbps, consumes 5-15 kVA, and has space for a 42U rack (80" x 24" x 48"). Outposts rack needs consistent network connections to the AWS Region, therefore be prepared for a public internet connection. Enterprise Service or Enterprise On-Ramp Help, which provides 24/7 remote support within 15 or 30 minutes depending on the Support package selected, is what customers require.


AWS DevOps Cloud Interview Questions and Answers

AWS Aurora Interview Questions and Answers

 

Ques. 14): Will the servers I have now function in an Outpost?

Answer:

No, the AWS Outposts rack depends on AWS infrastructure, and it is only supported on AWS hardware, which is designed for reliable, secure, and safe operations.


AWS Database Interview Questions and Answers

AWS ActiveMQ Interview Questions and Answers

 

Ques. 15): What is the status of AWS Outposts' FedRAMP authorization?

Answer:

FedRAMP has given AWS Outposts permission, but not for the service's hardware components. Customers are in charge of keeping up the physical and environmental security measures required to keep AWS Outposts secure while they are on their property. Depending on their level of risk tolerance, customers and agencies can choose to use AWS Outposts or can execute a Type Accreditation to check the hardware components of AWS Outposts before utilising them to run FedRAMP applications. Access to earlier evaluation results from the AWS Third Party Assessment Organization is made available by CapLinked.

 

AWS CloudFormation Interview Questions and Answers

AWS GuardDuty Questions and Answers

 

Ques. 16): How can AWS assist in expanding the capacity of current Outposts?

Answer:

You may expand the computation and storage capacity of your AWS Outposts rack using two different methods. By first installing more Outposts racks from the Outposts rack catalogue, you may enhance capacity. Second, you can go from a "small" to a "medium" or "large" configuration, or from a "medium" to a "large" configuration, if your current Outposts racks have available power and places inside the rack. The highest amount of compute and storage capacity that can be added to a rack that can handle 10KVA to 15KVA power consumption is double that amount. Note: The 42U Outposts form factor cannot accommodate the installation of the 1U and 2U Outposts servers.

 

AWS Control Tower Interview Questions and Answers

AWS Lake Formation Interview Questions and Answers

 

Ques. 17): How is the AWS Outposts rack infrastructure maintained?

Answer:

AWS will monitor your Outpost as a part of the public Region once it has been installed and is accessible in the AWS Management Console. AWS will also carry out software updates and patches automatically.

If physical maintenance is required, AWS will get in touch to arrange a visit to your facility. AWS may swap out a specific module if necessary, but it won't service customers' hosts or network switches there.

 

AWS Data Pipeline Interview Questions and Answers

Amazon CloudSearch Interview Questions and Answers 

 

Ques. 18): Using EBS Local Snapshots on Outposts, how do I ensure data residency on the Outposts rack?

Answer:

To ensure data residency, you may establish resource-level IAM policies and permissions on your Outpost for EBS Local Snapshots on Outposts and AMI images. A data residency enforcement policy may be put up by each account (or IAM user or role) for one or more Outposts. This will prevent both API/CLI requests made beyond the defined Outposts rack ARN as well as the creation or copying of local snapshots and images. You can track that local snapshots are present at your location since all create, update, and copy actions are recorded in CloudTrail audit logs.

 

AWS Transit Gateway Interview Questions and Answers

Amazon Detective Interview Questions and Answers

 

Ques. 19): Can Outposts Rack satisfy the criteria for data residency?

Answer:

Yes. Using Amazon Elastic Block Store (EBS) and Amazon Simple Storage Service (S3) on Outposts, in the client's on-premises site or a designated co-location facility, customer data may be set to remain on the rack. The data residency needs that we hear from our clients the most frequently are addressed by well-architected apps that use Outposts Rack and AWS services and capabilities. You may manage access to AWS resources using AWS Identity and Access Management (IAM). You may determine which kinds of data must stay on Outposts rack and cannot be duplicated to the AWS Region using IAM and granular data control rules. By default, S3 on Outposts keeps data on your Outpost, and depending on your particular residency needs, you may decide to duplicate all or a portion of your data to other AWS Regions. You may safely process client data locally on the Outposts rack using ElastiCache on Outposts. There will be a small amount of restricted meta-data that flows back to the AWS Region, such as instance IDs, monitoring metrics, metering records, tags, bucket names, etc.

We advise you to confirm and coordinate closely with your compliance and security teams to make sure your particular data residency needs are satisfied.

 

Amazon EMR Interview Questions and Answers

Amazon OpenSearch Interview Questions and Answers

 

Ques. 20): On the Outposts rack, which EC2 instances are available?

Answer:

AWS Outposts rack supports EC2 instances built on the AWS Nitro System for general purpose, compute, memory, storage, and GPU optimization with Intel Xeon Scalable processors, and Graviton processors based EC2 instances are on the way.

 

 

More on AWS:

 

AWS FinSpace Interview Questions and Answers

AWS MSK Interview Questions and Answers

AWS EventBridge Interview Questions and Answers

AWS Simple Notification Service (SNS) Interview Questions and Answers

AWS QuickSight Interview Questions and Answers

AWS SQS Interview Questions and Answers

AWS AppFlow Interview Questions and Answers

AWS QLDB Interview Questions and Answers

AWS STEP Functions Interview Questions and Answers

Amazon Managed Blockchain Questions and Answers

AWS Message Queue(MQ) Interview Questions and Answers

AWS Serverless Application Model(SAM) Interview Questions and Answers

AWS X-Ray Interview Questions and Answers

AWS Wavelength Interview Questions and Answers



June 03, 2022

Top 20 AWS Transit Gateway Interview Questions and Answers

 

AWS Transit Gateway is a central hub that links your Amazon Virtual Private Clouds (VPCs) and on-premises networks. This streamlines your network and eliminates complicated peering arrangements. It functions as a cloud router, establishing new connections only once.


AWS(Amazon Web Services) Interview Questions and Answers


Ques. 1): How do I decide which Amazon Virtual Private Clouds (VPCs) are allowed to speak with one another?

Answer:

Create numerous route tables in an AWS Transit Gateway and attach Amazon VPCs and VPNs to them to partition your network. This allows you to construct isolated networks within an AWS Transit Gateway, similar to how VRFs are used in traditional networks. There will be a default route table for the AWS Transit Gateway. Multiple route tables can be used if desired.


AWS Cloud Interview Questions and Answers


Ques. 2): What is the definition of a global network?

Answer:

In the AWS Transit Gateway Network Manager service, a 'Global Network' object represents your private global network in AWS. Your AWS Transit Gateway hubs, attachments, AWS partner SD-WAN network virtual appliances, and on-premises devices, sites, linkages, and connections are all included.


AWS AppSync Interview Questions and Answers


Ques. 3): In the same multicast domain, can I have both IGMP and static members?

Answer:

Yes, in the same multicast domain, you may have both IGMP and static members. By delivering IGMPv2 messages, IGMP-capable participants can dynamically join or exit a multicast group. Using the terminal, CLI, or SDK, you may add or delete static members from a multicast group.


AWS Cloud9 Interview Questions and Answers


Ques. 4): How does AWS Transit Gateway's routing work?

Answer:

Between connected Amazon VPCs and VPNs, AWS Transit Gateway provides both dynamic and static routing. The default route table is associated with Amazon VPCs, VPNs, Direct Connect gateways, Transit Gateway Connect, and peered Transit Gateways by default. You may associate Amazon VPCs, Direct Connect gateways, VPNs, Transit Gateway Connect, and peered Transit Gateways with extra route tables.

Depending on the packet's destination IP address, the routes determine the next hop. Routes can be configured to point to an Amazon VPC, a VPN connection, a Direct Connect gateway, a Transit Gateway Connect, or a peered Transit Gateway.


Amazon Athena Interview Questions and Answers


Ques. 5): What is AWS Transit Gateway Network Manager, and how does it work?

Answer:

The Network Manager function of AWS Transit Gateway is a feature of AWS Transit Gateway. It centralises networking resource administration and monitoring, as well as connectivity to remote branch sites.

 

AWS RedShift Interview Questions and Answers


Ques. 6): Is it possible to link Amazon VPCs with the same CIDRs?

Answer:

Routing across Amazon VPCs with identical CIDRs is not supported by AWS Transit Gateway. If you create a new Amazon VPC with a CIDR that is the same as an existing Amazon VPC, AWS Transit Gateway will not add the new Amazon VPC route to the AWS Transit Gateway route database.

 

AWS Cloud Practitioner Essentials Questions and Answers


Ques. 7): For the GRE tunnel and BGP addresses, can I use various address families?

Answer:

Yes, the GRE tunnel and BGP addresses can be in the same or distinct address families. You can, for example, set the GRE tunnel to use IPv4 addresses and the BGP addresses to use IPv6 addresses, and vice versa.


AWS EC2 Interview Questions and Answers


Ques. 8): What is AWS Transit Gateway Connect, and how does it work?

Answer:

A feature of AWS Transit Gateway is AWS Transit Gateway Connect. The native integration of SD-WAN (Software-Defined Wide Area Network) network virtual appliances into AWS Transit Gateway facilitates branch connectivity. Connect attachment is a new logical attachment type provided by AWS Transit Gateway Connect that uses Amazon VPC or AWS Direct Connect attachments as the underlying network transport. Over the Connect attachment, it supports common protocols including Generic Routing Encapsulation (GRE) and Border Gateway Protocol (BGP).


AWS Lambda Interview Questions and Answers


Ques. 9): Is it possible to share a multicast Transit Gateway?

Answer:

Yes, you may share a transit gateway multicast domain for VPC subnet associations between accounts or throughout your company in AWS Organizations using AWS Resource Access Manager (RAM).


AWS Cloud Security Interview Questions and Answers


Ques. 10): Can I link my AWS Transit Gateway to another account's Direct Connect gateway?

Answer:

Yes, you can link your AWS Transit Gateway to a separate AWS account's AWS Direct Connect gateway. An affiliation to a Direct Connect gateway can only be created by the owner of the AWS Transit Gateway. You can't link your AWS Transit Gateway to your Direct Connect gateway with Resource Access Manager.


AWS Simple Storage Service (S3) Interview Questions and Answers


Ques. 11): Is it possible to link a route table to a Connect attachment?

Answer:

Yes, you may associate a route table with the Connect attachment, just like you can with any other Transit Gateway attachment. This route table might be the same as or different from the route table associated with the VPC or AWS Direct Connect (underlying transport mechanism) attachment.


AWS Fargate Interview Questions and Answers


12) Which Amazon VPC functionalities aren't available in the first release?

Answer:

At this time, Amazon VPC does not enable Security Group Referencing. Security groups in other spokes linked to the same AWS Transit Gateway cannot be referenced by spoke Amazon VPCs.


AWS SageMaker Interview Questions and Answers


Ques. 13): What is the process for propagating routes into the AWS Transit Gateway?

Answer:

In the AWS Transit Gateway, routes are propagated in two ways:

Propagation of routes to/from on-premises networks: Routes will propagate between the AWS Transit Gateway and your on-premises router utilising Border Gateway Protocol when you connect VPN or Direct Connect Gateway (BGP).

Routes to/from Amazon VPCs: When you attach or resize an Amazon VPC to an AWS Transit Gateway, the Amazon VPC Classless Inter-Domain Routing (CIDR) will propagate into the AWS Transit Gateway route table utilising internal APIs (not BGP). CIDR is a technique of allocating IP addresses and IP routing that helps to reduce the expansion of routing tables on routers throughout the Internet and the quick expiration of IPv4 addresses. The Amazon VPC's route table will not receive routes from the AWS Transit Gateway route table. To transmit traffic to the AWS Transit Gateway, the VPC owner must construct a static route.

Route propagation is not supported via peering links between Transit Gateways. To send traffic on peering attachments, you must construct static routes in the Transit gateway route tables.


AWS DynamoDB Interview Questions and Answers


Ques. 14): AWS Transit Gateway complies with which compliance programmes?

Answer:

AWS Transit Gateway inherits Amazon VPC compliance and fulfils PCI DSS Level 1, ISO 9001, ISO 27001, ISO 27017, ISO 27018, SOC 1, SOC 2, SOC 3, FedRAMP Moderate, FedRAMP High, and HIPAA compliance requirements.


AWS Cloudwatch interview Questions and Answers


Ques. 15): What is the procedure for installing AWS Transit Gateway Network Manager?

Answer:

To set up and operate Transit Gateway Network Manager, follow the steps below:

Create a new 'global network' object that is initially empty.

AWS Transit Gateways can be registered from any AWS Region.

Adding on-premises and cloud resources: Enter details about your on-premises and cloud devices, sites, links, and connections. Connect peers and the Site-to-Site VPN connections they're connected to.

Network Manager's visualisations, events, and analytics let you keep track of your worldwide network.

 

AWS Elastic Block Store (EBS) Interview Questions and Answers


Ques. 16): When I register an AWS Transit Gateway, what resources are immediately added to the global network?

Answer:

All attachments are automatically added for registered AWS Transit Gateways. VPCs, VPNs, Direct Connect gateways, AWS Transit Gateway Connect, and AWS Transit Gateway peering are examples of attachments.


AWS Amplify Interview Questions and Answers 


Ques. 17): To route multicast traffic, which attachment kinds may I use?

Answer:

You may use a Transit Gateway to transport multicast traffic inside and between VPC attachments. AWS Direct Connect, AWS Site-to-Site VPN, and peering attachments do not enable multicast routing.

 

AWS Secrets Manager Interview Questions and Answers


Ques. 18): Is AWS Transit Gateway Connect compatible with IPv6?

Answer:

Yes, IPv6 is supported by AWS Transit Gateway Connect. IPv6 addresses can be configured for both the GRE tunnel and the Border Gateway Protocol (BGP).


AWS Django Interview Questions and Answers


Ques. 19): AWS Transit Gateway Network Manager is supported by which AWS partners?

Answer:

A number of notable SD-WAN partners support AWS Transit Gateway Network Manager. For further information, please see the Partners page. Their SD-WAN solutions' integration of Network Manager allows you to automate branch-cloud connectivity and delivers end-to-end network monitoring from a single dashboard.

 

AWS Cloud Support Engineer Interview Question and Answers


Ques. 20): What appliances are compatible with AWS Transit Gateway Connect?

Answer:

AWS Transit Gateway Connect will operate with any third-party network appliances that support standard protocols like GRE and BGP.


AWS Solution Architect Interview Questions and Answers


More AWS Interview Questions and Answers:


AWS Glue Interview Questions and Answers


AWS Cloud Interview Questions and Answers


AWS VPC Interview Questions and Answers         


AWS DevOps Cloud Interview Questions and Answers


AWS Aurora Interview Questions and Answers


AWS Database Interview Questions and Answers


AWS ActiveMQ Interview Questions and Answers


AWS CloudFormation Interview Questions and Answers


AWS GuardDuty Questions and Answers


AWS Control Tower Interview Questions and Answers


AWS Lake Formation Interview Questions and Answers


AWS Data Pipeline Interview Questions and Answers


Amazon CloudSearch Interview Questions and Answers 


AWS Transit Gateway Interview Questions and Answers


Amazon Detective Interview Questions and Answers


Amazon EMR Interview Questions and Answers


Amazon OpenSearch Interview Questions and Answers