Pair your devices with a code and playback position follows you: pause on this device, hit resume on the other. Position is saved to the site every minute and on pause.
Open this panel on your other device and enter the same code.
Starts this lesson and continues through 27 more to the end of certification prep.
The VPC and Route 53 FAQs contain the most quotable hard constraints in the whole reading list. Not guidance — constraints. Sentences that begin with "No." And an exam option that violates one of them is eliminated instantly, without weighing anything.
Four of them are worth learning word for word. They're marked ⭐ below.
⚠️ Same sourcing caveat as lesson 3: my fetches returned substantial answers from both pages on 2026-09-21 but not the complete documents. Verbatim quotes are from what I retrieved; gaps are flagged rather than filled from memory.
What it is, verbatim:
"Amazon VPC lets you provision a logically isolated section of the Amazon Web Services (AWS) cloud where you can launch AWS resources in a virtual network that you define."
"No. A subnet must reside within a single Availability Zone."
That is the answer to "can a subnet span Availability Zones". No.
And it is the load-bearing fact for the entire resilience domain. It means:
⚠️ Conversely, a VPC spans all the Availability Zones in its Region. VPC: Regional. Subnet: zonal. If you hold nothing else from this lesson, hold that pair.
"Amazon reserves the first four (4) IP addresses and the last one (1) IP address of every subnet for IP networking purposes."
Five addresses, for "network administration functions including router, DNS server, and broadcast address allocation".
The arithmetic consequence, which is a genuine exam question:
| Subnet | Total addresses | Usable |
|---|---|---|
| /28 | 16 | 11 |
| /27 | 32 | 27 |
| /26 | 64 | 59 |
| /24 | 256 | 251 |
⚠️ A /28 gives you 11 usable addresses, not 16 and not 14. Standard network maths says 14 (you lose 2); AWS takes 5. If a question asks how many instances fit in a /28, the answer is 11 — and one of the distractors will be 14, aimed at people applying on-premises intuition.
"Each of these ranges can be between /28 (in CIDR notation) and /16 in size."
So the smallest VPC CIDR is a /28 (16 addresses) and the largest is a /16 (65,536). An option proposing a /8 VPC is impossible; so is a /29.
"No. Transitive peering relationships are not supported."
If VPC A peers with B, and B peers with C, then A cannot reach C. Not "it's discouraged" — it isn't supported.
This single fact is the entire commercial argument for AWS Transit Gateway, and it's how the exam builds a large family of questions: a hub-and-spoke requirement with n VPCs, where peering needs n(n-1)/2 connections and doesn't route transitively anyway. Ten VPCs fully meshed is 45 peering connections. The answer is a transit gateway.
"A highly available, managed Network Address Translation (NAT) service for your resources in a private subnet to access the Internet."
Outbound only — it allows outbound communication while blocking inbound connections from the internet. This is the same fact as SAA1 lesson 3, from a second source: connections originate inside the VPC.
⚠️ I did not retrieve, from this page: security group and NACL rule quotas, the number of VPCs per
Region, whether a VPC CIDR can be expanded after creation, VPC endpoint details, or Transit Gateway
specifics. Those are examinable. Read the rest of the VPC FAQ and
docs.aws.amazon.com/vpc/latest/userguide/amazon-vpc-limits.html.
What it is, verbatim:
"Amazon Route 53 provides highly available and scalable Domain Name System (DNS), domain name registration, and health-checking web services."
Three services in one, and the exam uses all three: DNS, domain registration, and health checks. The health checks are what make failover routing work, so they aren't a footnote.
From the FAQ, with the distinguishing detail for each:
| Policy | What it does | The stem phrase |
|---|---|---|
| Simple | one record, no routing logic | default |
| Weighted (Round Robin) | "assign weights to resource record sets in order to specify the frequency with which different responses are served" | "send 10% of traffic to…", canary, blue/green |
| Latency-based | routes to the AWS Region giving the lowest latency | "lowest latency" |
| Failover | "Automatic redirection when endpoints fail health checks" | "automatically fail over", active-passive |
| Geolocation (Geo DNS) | routes on geographic origin — "continent, country, or state level" | "users in Germany must see…", legal/licensing |
| Geoproximity | routes on "physical proximity with configurable bias" | "shift traffic toward a Region", bias |
| Multivalue answer | "Returns up to eight health-checkable IP addresses per query" | "return multiple healthy records" |
⚠️ Latency-based and geolocation are the classic confusion, and the distinction is the requirement's motive. Latency-based optimises performance — it sends users wherever is fastest, which may not be their own country. Geolocation enforces where the user is — for licensing, data sovereignty or language. If the stem says "must be served from the EU for GDPR reasons", latency-based routing is wrong even though it would probably route them there anyway: "probably" is not a compliance control.
⚠️ Geoproximity is the one with "bias" — that's its fingerprint in a question.
⚠️ Multivalue answer returns up to eight health-checkable records. It is not a load balancer, and that's a favourite distractor: if the stem wants real load balancing with health-based distribution, the answer is an ELB, not multivalue DNS.
From the FAQ, alias records are "an Amazon Route 53-specific extension to DNS" that map a domain name to AWS resources like "load balancers, CloudFront distributions, and S3 buckets".
The two properties that matter:
Unlike CNAMEs, alias records work at the zone apex (example.com) and automatically return current IP addresses when AWS resource addresses change.
And the cost:
"There is no additional charge for queries to Alias records that are mapped to AWS ELB load balancers" — also CloudFront distributions, Elastic Beanstalk environments, API Gateways, and VPC endpoints. These queries appear as "Intra-AWS-DNS-Queries".
⚠️ This is the answer to "point example.com at our load balancer". A CNAME cannot exist at the zone apex — that's a DNS protocol restriction, not an AWS limitation. So the option offering a CNAME for the naked domain is wrong, and the alias record is right. It's also free for AWS targets, which makes it the right answer on cost grounds too. Two pillars, one record type.
"Both the Amazon Route 53 authoritative service and the Amazon Route 53 Resolver Endpoints service provide for a service credit if a customer's monthly uptime percentage is below our service commitment."
⚠️ I did not retrieve the actual percentage from the FAQ — it points at the Route 53 SLA page. Route 53's availability commitment is widely quoted as 100%, and I am not asserting that from this source. If you need the figure, read the SLA document.
Also not retrieved: private hosted zones, Resolver inbound/outbound endpoints, health check types and intervals, and DNSSEC. All examinable; all worth reading.
If this lesson compresses to three sentences:
Each of those eliminates options rather than merely informing a preference, which is why they're worth more per byte than anything else on the reading list.
example.com (no www) to resolve to an Application Load Balancer. What record type, and
what does it cost?