AWS VPC Interview Questions (Top 100 Questions with Answers)
Master AWS VPC Interview Questions with production-oriented questions covering VPC architecture, subnets, route tables, Internet Gateway, NAT Gateway, Security Groups, NACLs, VPC Peering, Transit Gateway, Endpoints, Direct Connect, VPN, and production networking scenarios.
Module Navigation
Previous: AWS RDS QA | Parent: AWS Learning Path | Next: AWS IAM QA
Introduction
Amazon Virtual Private Cloud (VPC) allows you to build secure, isolated networks in AWS.
Almost every production application deployed on AWS runs inside a VPC.
Understanding VPC is mandatory for
- AWS Solution Architect
- DevOps Engineer
- Cloud Engineer
- Java Backend Engineer
- Platform Engineer
- SRE
This guide contains the Top 100 AWS VPC Interview Questions frequently asked in enterprise interviews.
AWS VPC Learning Roadmap
VPC Basics
│
▼
Subnets
│
▼
Route Tables
│
▼
Internet Gateway
│
▼
NAT Gateway
│
▼
Security
│
▼
VPC Connectivity
│
▼
Hybrid Networking
│
▼
Production Architecture
VPC Fundamentals
1. What is Amazon VPC?
Amazon Virtual Private Cloud (VPC) is a logically isolated virtual network where AWS resources are deployed securely.
2. Why use VPC?
- Network Isolation
- Security
- Private Networking
- Routing Control
- Hybrid Connectivity
3. What does a VPC contain?
- CIDR Block
- Subnets
- Route Tables
- Internet Gateway
- NAT Gateway
- Security Groups
- Network ACLs
4. Is VPC regional?
Yes.
A VPC belongs to one AWS Region.
5. Can multiple VPCs exist in one Region?
Yes.
CIDR
6. What is CIDR?
Classless Inter-Domain Routing.
Defines IP address ranges.
Example
10.0.0.0/16
7. Why choose a large CIDR?
Allows future expansion.
8. Can CIDR be expanded?
Yes.
Using additional CIDR blocks.
9. Overlapping CIDR allowed?
Not for directly connected VPCs.
10. Private IP Range Examples?
- 10.0.0.0/8
- 172.16.0.0/12
- 192.168.0.0/16
Subnets
11. What is a Subnet?
A subnet is a subdivision of a VPC.
12. Public Subnet?
Subnet with route to Internet Gateway.
13. Private Subnet?
No direct Internet access.
14. Why private subnet?
Better security.
15. Can EC2 in private subnet access Internet?
Yes.
Using NAT Gateway.
16. Which resources belong in private subnet?
- Databases
- Internal APIs
- Backend Services
17. Which resources belong in public subnet?
- Load Balancers
- Bastion Hosts
- NAT Gateways
18. Best practice?
Deploy across multiple Availability Zones.
19. Can subnet span multiple AZs?
No.
One subnet belongs to one AZ.
20. Maximum subnet size?
Depends on CIDR allocation.
Route Tables
21. What is a Route Table?
Defines packet routing rules.
22. Default Route?
0.0.0.0/0
23. Public Route Table?
Routes Internet traffic to Internet Gateway.
24. Private Route Table?
Routes Internet traffic to NAT Gateway.
25. Multiple Route Tables?
Yes.
Internet Gateway
26. What is Internet Gateway?
Allows Internet connectivity for VPC.
27. Is IGW highly available?
Yes.
28. Can one IGW connect multiple VPCs?
No.
One VPC only.
29. Public IP required?
Yes.
For direct Internet access.
30. Internet Gateway use case?
Public web applications.
NAT Gateway
31. What is NAT Gateway?
Allows outbound Internet from private subnet.
32. Does NAT Gateway allow inbound traffic?
No.
33. NAT Gateway location?
Public subnet.
34. NAT Gateway vs Internet Gateway?
| NAT Gateway | Internet Gateway |
|---|---|
| Outbound Only | Inbound + Outbound |
| Private Subnets | Public Subnets |
35. NAT Instance vs NAT Gateway?
NAT Gateway is managed.
NAT Instance requires administration.
Security Groups
36. What is Security Group?
Virtual firewall attached to EC2.
37. Stateful?
Yes.
38. Can Security Groups deny traffic?
No.
Only allow rules.
39. Inbound Rules?
Traffic entering instance.
40. Outbound Rules?
Traffic leaving instance.
Network ACL
41. What is Network ACL?
Subnet-level firewall.
42. Stateful?
No.
Stateless.
43. Can NACL deny traffic?
Yes.
44. Security Group vs NACL?
| Security Group | NACL |
|---|---|
| Instance Level | Subnet Level |
| Stateful | Stateless |
| Allow Only | Allow & Deny |
45. Processing Order?
NACL rules processed in ascending rule number order.
Elastic IP
46. What is Elastic IP?
Static public IPv4 address.
47. Why Elastic IP?
Static endpoint.
48. Charges?
Free while associated with a running instance, subject to AWS pricing policies.
49. Can Elastic IP move?
Yes.
Between instances in the same Region.
50. Common use?
NAT Gateway
Bastion Host
VPC Connectivity
51. What is VPC Peering?
Private communication between two VPCs.
52. Transitive?
No.
53. Cross Region Peering?
Supported.
54. What is Transit Gateway?
Central networking hub connecting multiple VPCs and on-premises networks.
55. Why Transit Gateway?
Simplifies large network architectures.
VPC Endpoints
56. What is VPC Endpoint?
Private access to AWS services.
57. Gateway Endpoint?
Supports
- S3
- DynamoDB
58. Interface Endpoint?
Uses AWS PrivateLink.
59. Why Endpoints?
Avoid Internet traffic.
60. Production Benefits?
Security
Lower latency
No NAT cost for supported services.
Hybrid Networking
61. Site-to-Site VPN?
Encrypted connection between AWS and on-premises.
62. AWS Direct Connect?
Dedicated private network connection.
63. VPN vs Direct Connect?
| VPN | Direct Connect |
|---|---|
| Internet | Private Network |
| Lower Cost | Higher Bandwidth |
| Variable Latency | Consistent Latency |
64. Hybrid Cloud?
On-premises
AWS.
65. Direct Connect Use Cases?
Large enterprise workloads.
Production Scenarios
66. EC2 has no Internet.
Check
- Route Table
- Internet Gateway
- Security Group
- NACL
67. Private EC2 cannot download updates.
Check NAT Gateway.
68. Database exposed publicly.
Move to private subnet.
69. SSH not working.
Check
- Security Group
- NACL
- Route Table
- Public IP
70. Internet slow.
Check
- NAT Gateway
- Network Throughput
- Routing
71. Multiple VPC communication.
Use Transit Gateway.
72. Need private S3 access.
Use Gateway Endpoint.
73. Hybrid banking network.
Use Direct Connect.
74. Cross-region communication.
Use VPC Peering or Transit Gateway (where applicable).
75. Security audit.
Review
- Security Groups
- NACLs
- IAM
- Flow Logs
Monitoring
76. VPC Flow Logs?
Capture network traffic metadata.
77. Where stored?
- CloudWatch Logs
- Amazon S3
78. Why Flow Logs?
Troubleshooting.
79. Can Flow Logs capture packet payload?
No.
Only metadata.
80. CloudWatch?
Monitors networking metrics.
Architect Questions
81. Design secure VPC.
Public Subnet
↓
ALB
↓
Private EC2
↓
Private Database.
82. Multi-AZ networking?
Deploy subnets across multiple AZs.
83. Public API architecture?
Route53
↓
ALB
↓
Private EC2.
84. Database architecture?
Private Subnet.
No public IP.
85. Microservices networking?
Private subnets.
Internal Load Balancers.
Senior Interview Questions
86. VPC Peering vs Transit Gateway?
Transit Gateway scales better for many VPCs.
87. NAT Gateway vs VPC Endpoint?
VPC Endpoint provides private AWS service access.
NAT Gateway provides outbound Internet.
88. Common networking mistakes?
- Public Database
- Open Security Groups
- Wrong Route Table
89. Security best practices?
- Least Privilege
- Private Subnets
- Flow Logs
- Endpoints
90. Cost Optimization?
- Use Gateway Endpoints
- Minimize NAT Gateway traffic
- Remove unused Elastic IPs
91. Bastion Host?
Jump server for accessing private resources.
92. AWS Systems Manager Session Manager vs Bastion?
Session Manager eliminates the need for public SSH access.
93. IPv6 support?
Supported.
94. Dual Stack VPC?
Supports IPv4 and IPv6.
95. DNS Resolution in VPC?
Provided by Amazon Route 53 Resolver.
96. DHCP Options Set?
Customizes DNS and DHCP settings for a VPC.
97. What should be monitored?
- Flow Logs
- NAT Gateway
- VPN
- Direct Connect
- Route Changes
98. Production Readiness Checklist?
- Multi-AZ
- Private Subnets
- Flow Logs
- Endpoints
- Security Groups
- Monitoring
99. What do interviewers expect?
- Networking knowledge
- Security understanding
- Production experience
- Troubleshooting skills
100. How should you prepare?
- Build multiple VPCs
- Configure Peering
- Create Transit Gateway
- Use NAT Gateway
- Configure Endpoints
- Practice hybrid networking
Production VPC Architecture
Internet
│
Internet Gateway
│
┌──────────────────┴──────────────────┐
▼ ▼
Public Subnet (AZ-1) Public Subnet (AZ-2)
│ │
▼ ▼
Application Load Balancer NAT Gateway
│ │
└───────────────┬─────────────────────┘
▼
Private App Subnets
┌─────────────┴─────────────┐
▼ ▼
EC2 (AZ-1) EC2 (AZ-2)
│ │
└─────────────┬─────────────┘
▼
Private DB Subnets
│
▼
Amazon RDS
Quick Revision
| Topic | Key Point |
|---|---|
| VPC | Private Network |
| CIDR | IP Range |
| Public Subnet | Internet Access |
| Private Subnet | Internal Resources |
| Internet Gateway | Public Connectivity |
| NAT Gateway | Outbound Internet |
| Security Group | Stateful Firewall |
| NACL | Stateless Firewall |
| VPC Peering | Two VPC Connection |
| Transit Gateway | Hub for Multiple VPCs |
Interview Tips
During AWS VPC interviews:
- Clearly explain the relationship between VPC, Subnets, Route Tables, and Gateways.
- Understand the difference between Internet Gateway, NAT Gateway, and VPC Endpoints.
- Be able to compare Security Groups and Network ACLs.
- Explain when to use VPC Peering versus Transit Gateway.
- Discuss hybrid networking using Site-to-Site VPN and Direct Connect.
- Relate answers to production architectures using private subnets, multi-AZ deployments, least-privilege security, and high availability.
Summary
Amazon VPC is the networking foundation for AWS workloads. Strong VPC interview performance requires understanding CIDR blocks, subnets, route tables, Internet Gateways, NAT Gateways, Security Groups, Network ACLs, VPC Peering, Transit Gateway, VPC Endpoints, hybrid connectivity, and production networking best practices.
Mastering these 100 AWS VPC interview questions prepares you for AWS Cloud Engineer, DevOps Engineer, Network Engineer, Platform Engineer, Site Reliability Engineer, and Solution Architect interviews.