Pair your devices with a code and playback position follows you: pause on this device, hit resume on the other. Position is saved to the site every minute and on pause.
Open this panel on your other device and enter the same code.
Starts this lesson and continues through 10 more to the end of certification prep.
Task statement 3.4 — "Determine high-performing and/or scalable network architectures" — has four knowledge items and four skills. Reduced to their nouns:
SAA2 lesson 3Plus one skill that isn't about the network at all, until you read it closely: "Determining the appropriate placement of resources to meet business requirements." That's placement groups — where instances sit relative to each other.
Network performance questions ask where the distance is, and which hop to remove:
user ─── internet ─── Region → shorten with the EDGE (CloudFront / Global Accelerator)
data centre ─── internet ─── VPC → replace with a LINK (VPN / Direct Connect)
VPC ─── internet ─── service in a VPC → replace with PRIVATE path (PrivateLink / gateway endpoint)
instance ─── rack ─── instance → shorten with PLACEMENT (cluster placement group, ENA, EFA)
Both use AWS's edge network. They are not interchangeable, and the exam loves pairing them.
From What is Amazon CloudFront?, verified 2026-09-25:
"Amazon CloudFront is a web service that speeds up distribution of your static and dynamic web content … CloudFront delivers your content through a worldwide network of data centers called edge locations."
From What is AWS Global Accelerator?:
The use cases, from Understanding AWS Global Accelerator use cases: static IPs to put "on allow lists just once"; latency-sensitive apps in "gaming, media, mobile apps, ad-tech, and financials"; multi-Region failover that "instantly triggers traffic re-routing"; DDoS protection with AWS Shield by default; and "VoIP or online gaming applications" via custom routing.
| CloudFront | Global Accelerator | |
|---|---|---|
| What it does | caches content at the edge | routes connections over the AWS network to a Regional endpoint |
| Protocol shape | HTTP/HTTPS content | any application behind NLB/ALB/EC2/EIP — including non-HTTP |
| Entry point | a distribution domain name | two static anycast IPs |
| Answers | "static assets", "video", "reduce origin load" | "static IPs to allowlist", "UDP/gaming/VoIP", "fast regional failover without DNS caching" |
⚠️ If the stem requires fixed IP addresses, CloudFront is wrong. If the stem says "cache", Global
Accelerator is wrong — it doesn't cache. SAA2 lesson 3 covered why this matters for failover: the static IPs never change, so clients holding stale DNS
answers aren't the problem they are with DNS-based failover.
From Subnets for your VPC:
| Type | Defined by |
|---|---|
| Public | "a direct route to an internet gateway" |
| Private | no direct route to an IGW; "require a NAT device to access the public internet" |
| VPN-only | "a route to a Site-to-Site VPN connection through a virtual private gateway" |
| Isolated | "no routes to destinations outside its VPC" |
That's the multi-tier topology skill in one picture: load balancer in public subnets, application in
private subnets, database in private or isolated subnets, one of each per AZ. (SAA2 lesson 3 did the
load balancer half.)
From Subnet CIDR blocks:
"The allowed IPv4 CIDR block size for a subnet is between a
/28netmask and/16netmask. The first four IP addresses and the last IP address in each subnet CIDR block are not available for your use."
In 10.0.0.0/24: .0 network, .1 VPC router, .2 DNS, .3 "future use", .255 broadcast. So a
/24 gives 251 usable addresses, and a /28 gives 11.
⚠️ Size for the future. The skill "Determining network configurations that can scale to accommodate
future needs" is IP exhaustion. Every Lambda-in-VPC ENI, every Fargate task (awsvpc, SAA2 lesson
4), every interface endpoint consumes an address. A /28 app subnet that "only has four servers" will
run out the day you add containers. And "If you create more than one subnet in a VPC, the CIDR blocks
of the subnets cannot overlap."
From What is AWS Site-to-Site VPN?:
From What is Direct Connect?:
"Direct Connect links your internal network to a Direct Connect location over a standard Ethernet fiber-optic cable … bypassing internet service providers in your network path."
| Dedicated connection | Hosted connection | |
|---|---|---|
| Who | "associated with a single customer", ordered through the console | "an AWS Direct Connect Partner provisions on behalf of a customer" |
| Speeds | 1, 10, 100, 400 Gbps | 50 Mbps – 25 Gbps (50/100/200/300/400/500 Mbps, 1/2/5/10/25 Gbps) |
| Change speed | "can't change the port speed" — new connection | partner can change it |
Three virtual interface types, verbatim: private ("used to access an Amazon Virtual Private Cloud (VPC) using private IP addresses"), public ("access all AWS public services using public IP addresses"), transit ("access one or more Amazon VPC Transit Gateways associated with Direct Connect gateways").
⚠️ Lead time. For a dedicated connection, "It can take up to 72 business hours for AWS to review your request and provision a port" — and then a physical cross-connect has to be ordered through your provider. A stem that says "needed next week" or "needed today" is not satisfied by a new Direct Connect line. VPN is the stop-gap.
⚠️ I did not retrieve a Direct Connect page stating whether traffic is encrypted by default, or the
"IPsec VPN over Direct Connect" pattern. The dedicated-connection page confirms MACsec can be
associated with dedicated connections. Read docs.aws.amazon.com/directconnect/latest/UserGuide/MACsec.html
and the Direct Connect FAQ before answering encryption-in-transit questions on DX.
| Requirement | Answer |
|---|---|
| quick to set up, encrypted, over the internet | Site-to-Site VPN |
| consistent performance, high bandwidth, bypass the internet | Direct Connect |
| more than 10 Gbps, dedicated | Direct Connect dedicated (100 or 400 Gbps ports exist) |
| sub-1 Gbps, via a partner | Direct Connect hosted |
| DX is weeks away; need connectivity now | VPN now, DX later |
| many VPCs across accounts and Regions over one DX | transit VIF + Direct Connect gateway + transit gateways |
⚠️ I did not fetch the Transit Gateway documentation for this lesson. Its role here is only as the VPN or DX termination point named on the VPN and DX pages.
From What is AWS PrivateLink?:
"privately connect your VPC to services and resources as if they were in your VPC. You do not need to use an internet gateway, NAT device, public IP address, Direct Connect connection, or AWS Site-to-Site VPN connection."
From AWS PrivateLink concepts:
→ Expose one service to many VPCs or accounts, without peering whole networks = PrivateLink. Private S3/DynamoDB access from a private subnet, no NAT charges = gateway endpoint.
The skill "Determining the appropriate placement of resources". From Placement groups and Placement strategies:
| Strategy | What it does | Limits |
|---|---|---|
| Cluster | "Packs instances close together inside an Availability Zone" for "low-latency network performance necessary for tightly coupled node-to-node communication" | "can't span multiple Availability Zones" |
| Partition | "each partition … has its own set of racks" — "HDFS, HBase, and Cassandra" | "a maximum of seven partitions per Availability Zone"; instances limited only by account limits |
| Spread | "Strictly places a small group of instances across distinct underlying hardware" | "a maximum of seven running instances in each Availability Zone" |
Cluster numbers worth knowing: instances inside a cluster placement group "can use up to 10 Gbps for single-flow traffic", versus "up to 5 Gbps" outside one. AWS recommends a single launch request and the same instance type — otherwise "you increase your chances of getting an insufficient capacity error." There's "no charge for creating a placement group."
⚠️ Cluster = performance, not availability. It's one AZ. A stem that asks for lowest latency and survival of an AZ failure can't be answered by a single cluster placement group.
Enhanced networking (Enhanced networking): SR-IOV providing "higher bandwidth, higher packet per second (PPS) performance, and consistently lower latency", "no additional charge". ENA "supports network speeds of up to 100 Gbps"; "All Nitro-based instances use ENA."
Elastic Fabric Adapter (EFA): for "AI/ML and HPC applications", with "OS-bypass" so MPI and NCCL talk "directly with the EFA device". ⚠️ "EFA traffic can't cross Availability Zones or VPCs" and "is not routable." Tightly coupled MPI job ⇒ EFA + cluster placement group.
| The stem says | Answer |
|---|---|
| "global users, static images and video, reduce origin load" | CloudFront |
| "partners must allowlist two fixed IPs; app is in two Regions" | Global Accelerator |
| "multiplayer UDP game, lowest jitter" | Global Accelerator (custom routing if users map to specific servers) |
| "clients cache DNS, regional failover is too slow" | Global Accelerator |
| "encrypted link to on-premises this week" | Site-to-Site VPN |
| "consistent 10 Gbps to on-premises, not over the internet" | Direct Connect (dedicated) |
| "offer our service privately to 200 customer VPCs, overlapping CIDRs possible" | PrivateLink endpoint service behind an NLB |
| "private instances reach S3 without NAT" | S3 gateway endpoint |
| "HPC nodes need lowest latency between each other" | cluster placement group + EFA |
| "Cassandra ring, keep replicas off shared racks" | partition placement group |
| "five critical instances must never share hardware" | spread placement group |
| "app subnet ran out of IPs after moving to Fargate" | larger subnet CIDR — 5 addresses reserved per subnet |
/26 subnet?/24, /26, /28 on the board. People lose marks on the five
reserved addresses more than on anything conceptual.