AWS VPC Interview Questions (Top 100 Questions with Answers)

Master AWS VPC Interview Questions with production-oriented questions covering VPC architecture, subnets, route tables, Internet Gateway, NAT Gateway, Security Groups, NACLs, VPC Peering, Transit Gateway, Endpoints, Direct Connect, VPN, and production networking scenarios.

Module Navigation

Previous: AWS RDS QA | Parent: AWS Learning Path | Next: AWS IAM QA

Introduction

Amazon Virtual Private Cloud (VPC) allows you to build secure, isolated networks in AWS.

Almost every production application deployed on AWS runs inside a VPC.

Understanding VPC is mandatory for

  • AWS Solution Architect
  • DevOps Engineer
  • Cloud Engineer
  • Java Backend Engineer
  • Platform Engineer
  • SRE

This guide contains the Top 100 AWS VPC Interview Questions frequently asked in enterprise interviews.


AWS VPC Learning Roadmap

VPC Basics
      │
      ▼
Subnets
      │
      ▼
Route Tables
      │
      ▼
Internet Gateway
      │
      ▼
NAT Gateway
      │
      ▼
Security
      │
      ▼
VPC Connectivity
      │
      ▼
Hybrid Networking
      │
      ▼
Production Architecture

VPC Fundamentals

1. What is Amazon VPC?

Amazon Virtual Private Cloud (VPC) is a logically isolated virtual network where AWS resources are deployed securely.


2. Why use VPC?

  • Network Isolation
  • Security
  • Private Networking
  • Routing Control
  • Hybrid Connectivity

3. What does a VPC contain?

  • CIDR Block
  • Subnets
  • Route Tables
  • Internet Gateway
  • NAT Gateway
  • Security Groups
  • Network ACLs

4. Is VPC regional?

Yes.

A VPC belongs to one AWS Region.


5. Can multiple VPCs exist in one Region?

Yes.


CIDR

6. What is CIDR?

Classless Inter-Domain Routing.

Defines IP address ranges.

Example

10.0.0.0/16

7. Why choose a large CIDR?

Allows future expansion.


8. Can CIDR be expanded?

Yes.

Using additional CIDR blocks.


9. Overlapping CIDR allowed?

Not for directly connected VPCs.


10. Private IP Range Examples?

  • 10.0.0.0/8
  • 172.16.0.0/12
  • 192.168.0.0/16

Subnets

11. What is a Subnet?

A subnet is a subdivision of a VPC.


12. Public Subnet?

Subnet with route to Internet Gateway.


13. Private Subnet?

No direct Internet access.


14. Why private subnet?

Better security.


15. Can EC2 in private subnet access Internet?

Yes.

Using NAT Gateway.


16. Which resources belong in private subnet?

  • Databases
  • Internal APIs
  • Backend Services

17. Which resources belong in public subnet?

  • Load Balancers
  • Bastion Hosts
  • NAT Gateways

18. Best practice?

Deploy across multiple Availability Zones.


19. Can subnet span multiple AZs?

No.

One subnet belongs to one AZ.


20. Maximum subnet size?

Depends on CIDR allocation.


Route Tables

21. What is a Route Table?

Defines packet routing rules.


22. Default Route?

0.0.0.0/0

23. Public Route Table?

Routes Internet traffic to Internet Gateway.


24. Private Route Table?

Routes Internet traffic to NAT Gateway.


25. Multiple Route Tables?

Yes.


Internet Gateway

26. What is Internet Gateway?

Allows Internet connectivity for VPC.


27. Is IGW highly available?

Yes.


28. Can one IGW connect multiple VPCs?

No.

One VPC only.


29. Public IP required?

Yes.

For direct Internet access.


30. Internet Gateway use case?

Public web applications.


NAT Gateway

31. What is NAT Gateway?

Allows outbound Internet from private subnet.


32. Does NAT Gateway allow inbound traffic?

No.


33. NAT Gateway location?

Public subnet.


34. NAT Gateway vs Internet Gateway?

NAT Gateway Internet Gateway
Outbound Only Inbound + Outbound
Private Subnets Public Subnets

35. NAT Instance vs NAT Gateway?

NAT Gateway is managed.

NAT Instance requires administration.


Security Groups

36. What is Security Group?

Virtual firewall attached to EC2.


37. Stateful?

Yes.


38. Can Security Groups deny traffic?

No.

Only allow rules.


39. Inbound Rules?

Traffic entering instance.


40. Outbound Rules?

Traffic leaving instance.


Network ACL

41. What is Network ACL?

Subnet-level firewall.


42. Stateful?

No.

Stateless.


43. Can NACL deny traffic?

Yes.


44. Security Group vs NACL?

Security Group NACL
Instance Level Subnet Level
Stateful Stateless
Allow Only Allow & Deny

45. Processing Order?

NACL rules processed in ascending rule number order.


Elastic IP

46. What is Elastic IP?

Static public IPv4 address.


47. Why Elastic IP?

Static endpoint.


48. Charges?

Free while associated with a running instance, subject to AWS pricing policies.


49. Can Elastic IP move?

Yes.

Between instances in the same Region.


50. Common use?

NAT Gateway

Bastion Host


VPC Connectivity

51. What is VPC Peering?

Private communication between two VPCs.


52. Transitive?

No.


53. Cross Region Peering?

Supported.


54. What is Transit Gateway?

Central networking hub connecting multiple VPCs and on-premises networks.


55. Why Transit Gateway?

Simplifies large network architectures.


VPC Endpoints

56. What is VPC Endpoint?

Private access to AWS services.


57. Gateway Endpoint?

Supports

  • S3
  • DynamoDB

58. Interface Endpoint?

Uses AWS PrivateLink.


59. Why Endpoints?

Avoid Internet traffic.


60. Production Benefits?

Security

Lower latency

No NAT cost for supported services.


Hybrid Networking

61. Site-to-Site VPN?

Encrypted connection between AWS and on-premises.


62. AWS Direct Connect?

Dedicated private network connection.


63. VPN vs Direct Connect?

VPN Direct Connect
Internet Private Network
Lower Cost Higher Bandwidth
Variable Latency Consistent Latency

64. Hybrid Cloud?

On-premises

AWS.


65. Direct Connect Use Cases?

Large enterprise workloads.


Production Scenarios

66. EC2 has no Internet.

Check

  • Route Table
  • Internet Gateway
  • Security Group
  • NACL

67. Private EC2 cannot download updates.

Check NAT Gateway.


68. Database exposed publicly.

Move to private subnet.


69. SSH not working.

Check

  • Security Group
  • NACL
  • Route Table
  • Public IP

70. Internet slow.

Check

  • NAT Gateway
  • Network Throughput
  • Routing

71. Multiple VPC communication.

Use Transit Gateway.


72. Need private S3 access.

Use Gateway Endpoint.


73. Hybrid banking network.

Use Direct Connect.


74. Cross-region communication.

Use VPC Peering or Transit Gateway (where applicable).


75. Security audit.

Review

  • Security Groups
  • NACLs
  • IAM
  • Flow Logs

Monitoring

76. VPC Flow Logs?

Capture network traffic metadata.


77. Where stored?

  • CloudWatch Logs
  • Amazon S3

78. Why Flow Logs?

Troubleshooting.


79. Can Flow Logs capture packet payload?

No.

Only metadata.


80. CloudWatch?

Monitors networking metrics.


Architect Questions

81. Design secure VPC.

Public Subnet

ALB

Private EC2

Private Database.


82. Multi-AZ networking?

Deploy subnets across multiple AZs.


83. Public API architecture?

Route53

ALB

Private EC2.


84. Database architecture?

Private Subnet.

No public IP.


85. Microservices networking?

Private subnets.

Internal Load Balancers.


Senior Interview Questions

86. VPC Peering vs Transit Gateway?

Transit Gateway scales better for many VPCs.


87. NAT Gateway vs VPC Endpoint?

VPC Endpoint provides private AWS service access.

NAT Gateway provides outbound Internet.


88. Common networking mistakes?

  • Public Database
  • Open Security Groups
  • Wrong Route Table

89. Security best practices?

  • Least Privilege
  • Private Subnets
  • Flow Logs
  • Endpoints

90. Cost Optimization?

  • Use Gateway Endpoints
  • Minimize NAT Gateway traffic
  • Remove unused Elastic IPs

91. Bastion Host?

Jump server for accessing private resources.


92. AWS Systems Manager Session Manager vs Bastion?

Session Manager eliminates the need for public SSH access.


93. IPv6 support?

Supported.


94. Dual Stack VPC?

Supports IPv4 and IPv6.


95. DNS Resolution in VPC?

Provided by Amazon Route 53 Resolver.


96. DHCP Options Set?

Customizes DNS and DHCP settings for a VPC.


97. What should be monitored?

  • Flow Logs
  • NAT Gateway
  • VPN
  • Direct Connect
  • Route Changes

98. Production Readiness Checklist?

  • Multi-AZ
  • Private Subnets
  • Flow Logs
  • Endpoints
  • Security Groups
  • Monitoring

99. What do interviewers expect?

  • Networking knowledge
  • Security understanding
  • Production experience
  • Troubleshooting skills

100. How should you prepare?

  • Build multiple VPCs
  • Configure Peering
  • Create Transit Gateway
  • Use NAT Gateway
  • Configure Endpoints
  • Practice hybrid networking

Production VPC Architecture

                     Internet
                         │
                 Internet Gateway
                         │
      ┌──────────────────┴──────────────────┐
      ▼                                     ▼
 Public Subnet (AZ-1)                Public Subnet (AZ-2)
      │                                     │
      ▼                                     ▼
Application Load Balancer          NAT Gateway
      │                                     │
      └───────────────┬─────────────────────┘
                      ▼
          Private App Subnets
        ┌─────────────┴─────────────┐
        ▼                           ▼
    EC2 (AZ-1)                 EC2 (AZ-2)
        │                           │
        └─────────────┬─────────────┘
                      ▼
             Private DB Subnets
                      │
                      ▼
                  Amazon RDS

Quick Revision

Topic Key Point
VPC Private Network
CIDR IP Range
Public Subnet Internet Access
Private Subnet Internal Resources
Internet Gateway Public Connectivity
NAT Gateway Outbound Internet
Security Group Stateful Firewall
NACL Stateless Firewall
VPC Peering Two VPC Connection
Transit Gateway Hub for Multiple VPCs

Interview Tips

During AWS VPC interviews:

  • Clearly explain the relationship between VPC, Subnets, Route Tables, and Gateways.
  • Understand the difference between Internet Gateway, NAT Gateway, and VPC Endpoints.
  • Be able to compare Security Groups and Network ACLs.
  • Explain when to use VPC Peering versus Transit Gateway.
  • Discuss hybrid networking using Site-to-Site VPN and Direct Connect.
  • Relate answers to production architectures using private subnets, multi-AZ deployments, least-privilege security, and high availability.

Summary

Amazon VPC is the networking foundation for AWS workloads. Strong VPC interview performance requires understanding CIDR blocks, subnets, route tables, Internet Gateways, NAT Gateways, Security Groups, Network ACLs, VPC Peering, Transit Gateway, VPC Endpoints, hybrid connectivity, and production networking best practices.

Mastering these 100 AWS VPC interview questions prepares you for AWS Cloud Engineer, DevOps Engineer, Network Engineer, Platform Engineer, Site Reliability Engineer, and Solution Architect interviews.