Copyright (c) 2026 MindMesh Academy. All rights reserved. This content is proprietary and may not be reproduced or distributed without permission.
6.4. Reflection Checkpoint
Phase 6 covers the networking domain — work through these before the final review:
- What makes a subnet "public" in AWS? Is it the subnet name or the route table?
- A NACL allows inbound TCP 443 but traffic still fails. What likely missing rule causes this, and why?
- Security groups vs. NACLs: which supports explicit deny, and which is stateful?
- What is the difference between a VPC interface endpoint and a gateway endpoint for S3?
- A Site-to-Site VPN shows "tunnel UP" but instances can't reach on-premises hosts. What is the most likely configuration issue?
- Route 53 Latency routing vs. Geolocation routing: which routes based on measured network performance?
- CloudFront OAC vs. OAI: which is current/recommended for restricting S3 bucket access?
- Lambda@Edge vs. CloudFront Functions: which executes at all 400+ edge locations, and which supports network calls?
- Global Accelerator vs. CloudFront: which do you choose for a gaming application using UDP?
- VPC Flow Logs show no entries at all for a connection attempt. Does this mean the traffic was allowed? What does it likely mean?
💾 CHECKPOINT — Session 5 (Phase 6) Complete
Files saved: complete-guide.md (Phases 1–6), keywords.json, relationships.json
Resume Point: Write Phase 7 (Exam Readiness and Strategy) — final phase.
Written byAlvin Varughese
Founder•15 professional certifications