AWS Training
Modules Listen All tracks
0:00 0:00

← Whitepapers and FAQs

Starts this lesson and continues through 27 more to the end of certification prep.

Networking — VPC and Route 53 FAQs

Why these two FAQs are the highest-yield pages on the list

The VPC and Route 53 FAQs contain the most quotable hard constraints in the whole reading list. Not guidance — constraints. Sentences that begin with "No." And an exam option that violates one of them is eliminated instantly, without weighing anything.

Four of them are worth learning word for word. They're marked ⭐ below.

⚠️ Same sourcing caveat as lesson 3: my fetches returned substantial answers from both pages on 2026-09-21 but not the complete documents. Verbatim quotes are from what I retrieved; gaps are flagged rather than filled from memory.

Amazon VPC

What it is, verbatim:

"Amazon VPC lets you provision a logically isolated section of the Amazon Web Services (AWS) cloud where you can launch AWS resources in a virtual network that you define."

⭐ A subnet lives in exactly one Availability Zone

"No. A subnet must reside within a single Availability Zone."

That is the answer to "can a subnet span Availability Zones". No.

And it is the load-bearing fact for the entire resilience domain. It means:

⚠️ Conversely, a VPC spans all the Availability Zones in its Region. VPC: Regional. Subnet: zonal. If you hold nothing else from this lesson, hold that pair.

⭐ AWS reserves five addresses per subnet

"Amazon reserves the first four (4) IP addresses and the last one (1) IP address of every subnet for IP networking purposes."

Five addresses, for "network administration functions including router, DNS server, and broadcast address allocation".

The arithmetic consequence, which is a genuine exam question:

Subnet Total addresses Usable
/28 16 11
/27 32 27
/26 64 59
/24 256 251

⚠️ A /28 gives you 11 usable addresses, not 16 and not 14. Standard network maths says 14 (you lose 2); AWS takes 5. If a question asks how many instances fit in a /28, the answer is 11 — and one of the distractors will be 14, aimed at people applying on-premises intuition.

⭐ VPC CIDR size range

"Each of these ranges can be between /28 (in CIDR notation) and /16 in size."

So the smallest VPC CIDR is a /28 (16 addresses) and the largest is a /16 (65,536). An option proposing a /8 VPC is impossible; so is a /29.

⭐ Peering is not transitive

"No. Transitive peering relationships are not supported."

If VPC A peers with B, and B peers with C, then A cannot reach C. Not "it's discouraged" — it isn't supported.

This single fact is the entire commercial argument for AWS Transit Gateway, and it's how the exam builds a large family of questions: a hub-and-spoke requirement with n VPCs, where peering needs n(n-1)/2 connections and doesn't route transitively anyway. Ten VPCs fully meshed is 45 peering connections. The answer is a transit gateway.

NAT gateway, in the FAQ's own words

"A highly available, managed Network Address Translation (NAT) service for your resources in a private subnet to access the Internet."

Outbound only — it allows outbound communication while blocking inbound connections from the internet. This is the same fact as SAA1 lesson 3, from a second source: connections originate inside the VPC.

⚠️ I did not retrieve, from this page: security group and NACL rule quotas, the number of VPCs per Region, whether a VPC CIDR can be expanded after creation, VPC endpoint details, or Transit Gateway specifics. Those are examinable. Read the rest of the VPC FAQ and docs.aws.amazon.com/vpc/latest/userguide/amazon-vpc-limits.html.

Amazon Route 53

What it is, verbatim:

"Amazon Route 53 provides highly available and scalable Domain Name System (DNS), domain name registration, and health-checking web services."

Three services in one, and the exam uses all three: DNS, domain registration, and health checks. The health checks are what make failover routing work, so they aren't a footnote.

The routing policies

From the FAQ, with the distinguishing detail for each:

Policy What it does The stem phrase
Simple one record, no routing logic default
Weighted (Round Robin) "assign weights to resource record sets in order to specify the frequency with which different responses are served" "send 10% of traffic to…", canary, blue/green
Latency-based routes to the AWS Region giving the lowest latency "lowest latency"
Failover "Automatic redirection when endpoints fail health checks" "automatically fail over", active-passive
Geolocation (Geo DNS) routes on geographic origin — "continent, country, or state level" "users in Germany must see…", legal/licensing
Geoproximity routes on "physical proximity with configurable bias" "shift traffic toward a Region", bias
Multivalue answer "Returns up to eight health-checkable IP addresses per query" "return multiple healthy records"

⚠️ Latency-based and geolocation are the classic confusion, and the distinction is the requirement's motive. Latency-based optimises performance — it sends users wherever is fastest, which may not be their own country. Geolocation enforces where the user is — for licensing, data sovereignty or language. If the stem says "must be served from the EU for GDPR reasons", latency-based routing is wrong even though it would probably route them there anyway: "probably" is not a compliance control.

⚠️ Geoproximity is the one with "bias" — that's its fingerprint in a question.

⚠️ Multivalue answer returns up to eight health-checkable records. It is not a load balancer, and that's a favourite distractor: if the stem wants real load balancing with health-based distribution, the answer is an ELB, not multivalue DNS.

⭐ Alias records — the zone-apex answer

From the FAQ, alias records are "an Amazon Route 53-specific extension to DNS" that map a domain name to AWS resources like "load balancers, CloudFront distributions, and S3 buckets".

The two properties that matter:

Unlike CNAMEs, alias records work at the zone apex (example.com) and automatically return current IP addresses when AWS resource addresses change.

And the cost:

"There is no additional charge for queries to Alias records that are mapped to AWS ELB load balancers" — also CloudFront distributions, Elastic Beanstalk environments, API Gateways, and VPC endpoints. These queries appear as "Intra-AWS-DNS-Queries".

⚠️ This is the answer to "point example.com at our load balancer". A CNAME cannot exist at the zone apex — that's a DNS protocol restriction, not an AWS limitation. So the option offering a CNAME for the naked domain is wrong, and the alias record is right. It's also free for AWS targets, which makes it the right answer on cost grounds too. Two pillars, one record type.

The SLA

"Both the Amazon Route 53 authoritative service and the Amazon Route 53 Resolver Endpoints service provide for a service credit if a customer's monthly uptime percentage is below our service commitment."

⚠️ I did not retrieve the actual percentage from the FAQ — it points at the Route 53 SLA page. Route 53's availability commitment is widely quoted as 100%, and I am not asserting that from this source. If you need the figure, read the SLA document.

Also not retrieved: private hosted zones, Resolver inbound/outbound endpoints, health check types and intervals, and DNSSEC. All examinable; all worth reading.

The three facts to hold together

If this lesson compresses to three sentences:

  1. A subnet is zonal; a VPC is Regional. Every multi-AZ design is really a multi-subnet design.
  2. Peering isn't transitive, so anything hub-and-spoke at scale is a transit gateway.
  3. Alias records work at the apex and are free to AWS targets, so they beat CNAMEs for AWS resources every time.

Each of those eliminates options rather than merely informing a preference, which is why they're worth more per byte than anything else on the reading list.

Check yourself

  1. How many usable IP addresses in a /28 subnet, and why isn't it 14?
  2. VPC A peers with B; B peers with C. Can A reach C? What's the fix?
  3. A stem says "users in Germany must be served from eu-central-1 for regulatory reasons". Which routing policy — and which one is the trap?
  4. You need example.com (no www) to resolve to an Application Load Balancer. What record type, and what does it cost?
  5. Can a subnet span two Availability Zones?
Answers
  1. 11. "Amazon reserves the first four (4) IP addresses and the last one (1) IP address of every subnet" — five, not the two you'd lose on-premises. 16 − 5 = 11.
  2. No. "Transitive peering relationships are not supported." Fix: AWS Transit Gateway (or a direct A↔C peering, which doesn't scale — 10 VPCs fully meshed is 45 connections).
  3. Geolocation. The trap is latency-based, which would probably route them to eu-central-1 anyway — but "probably" isn't a regulatory control. Geolocation routes on where the user is.
  4. An alias record — a CNAME cannot exist at the zone apex. And there is "no additional charge for queries to Alias records that are mapped to AWS ELB load balancers." Free.
  5. No. "A subnet must reside within a single Availability Zone." The VPC spans the Region; the subnet does not.

Teaching this section

← PreviousCompute and storage — EC2 and S3 FAQsNext →Data and messaging — RDS and SQS FAQs