A virtual private cloud (VPC) is your own isolated network in an AWS Region, defined by an IPv4 CIDR (Classless Inter-Domain Routing) block such as 10.0.0.0/16. You divide it into subnets, and each subnet lives in exactly one Availability Zone (AZ). Security in a VPC comes in layers: where a subnet can route, which firewalls sit in front of each resource, and how administrators reach machines. The exam expects you to design all three so that only the load balancer faces the internet and everything else stays private.
Keep reading for free
Create a free StudyToCert account to read the rest of this lesson: 7 more sections, 6 key terms, a real-world example, an exam tip and self-check questions. Every lesson, lab and practice test is free with an account.