What's changed: Deepened SOA-C02 Chapter 5 to Associate depth (tables, scenarios, FAQ, traps; localized figures)
5.4In-scope services for networking and content delivery
A roundup of in-scope SOA-C03 services for networking and content delivery—VPC, connectivity, DNS, and delivery.
5.4.1In-scope services for networking and content delivery
For networking and content delivery, focus on the VPC and its components, connectivity, and DNS. VPC and components: Amazon VPC (virtual network), Amazon VPC IP Address Manager (centralized IP planning), Elastic IP addresses (static public IPs), VPC Endpoints (private access to AWS services), VPC peering (direct VPC-to-VPC), and VPC Reachability Analyzer (connectivity diagnostics). Connectivity: AWS Site-to-Site VPN (site-to-site), AWS Client VPN (user devices), AWS Transit Gateway (hub many VPCs), AWS PrivateLink (private access to services), and AWS Global Accelerator (speed up over the AWS network). DNS/delivery: Amazon Route 53 (authoritative DNS) and Amazon Route 53 Resolver DNS Firewall (DNS threat protection).
5.4.2Section summary
- VPC: VPC, VPC IPAM, Elastic IP, VPC Endpoints, VPC peering, VPC Reachability Analyzer
- Connectivity/DNS: Site-to-Site VPN, Client VPN, Transit Gateway, PrivateLink, Global Accelerator / Route 53, Route 53 Resolver DNS Firewall
Sign in to track progress — Log in.
Quick check
(just a quick review)Q1. Which AWS service plans, tracks, and audits IP address allocation across accounts/VPCs?
Q2. Which VPC feature diagnoses reachability (whether/where traffic is blocked) from configuration?
Keep track of your progress
The full study guide is free to read. Sign up free to practice with the question bank, track what you have read, review your mistakes, and highlight passages.

