Build application networks whose access you can explain and test. Use AWS CLI to configure resources and AWS View to observe actual requests, source addresses, service routes and blocked paths.
Six guided labs introduce address planning, public connectivity, security groups, private outbound access, S3 gateway endpoints and network ACL diagnosis. An independent challenge combines a missing private service route with a response-port fault. Follow the six labs in order before the challenge.
What You Will Learn
- Plan a VPC and create separate application subnets with appropriate CIDR ranges
- Connect a public application through an Internet gateway, route table and public address
- Limit application sources and ports with stateful security groups
- Provide private outbound access through a NAT gateway while blocking unsolicited inbound requests
- Read S3 through a gateway endpoint and diagnose its route-table membership
- Repair stateless ACL return ports and test first-match rule priority
- Recover private storage across two independent boundaries while preserving isolation and restoring the supplied baseline
Who This Course Is For
For cloud beginners and application developers who want to understand why an application can or cannot connect before designing larger cloud systems.
Prerequisites: Complete Get Started with AWS on LabEx and the CLI/resource-query units in AWS Foundations for Beginners, then learn identity and permission basics in AWS IAM for Beginners. Basic terminal familiarity is sufficient; networking concepts are explained near first use.
Learning environment: Each unit starts independently in a fresh browser-based LabEx Linux environment. Use Terminal and the adjacent AWS View. Tools, connection and unrelated application fixtures are prepared; no personal AWS account or access keys are needed. Network exercises preserve the connection used to reach the environment.
Frequently Asked Questions
Does the name “public-subnet” make an application public?
No. Check the actual route, Internet gateway, public address and security permissions. The course tests these conditions separately.
Does a NAT gateway allow outside clients to initiate connections?
It provides outbound connectivity and response traffic for the private application. You also test that unsolicited inbound access stays blocked.
Does an S3 endpoint provide ordinary Internet access?
No. Its managed service route applies to the associated route tables and S3 destinations. Ordinary Internet requests remain a separate path.
Why must ACL rules account for responses?
ACLs are stateless and check each direction independently. Responses target client ports. Security groups track allowed connections; ACLs still form a separate boundary.
How do I finish and clean up?
Run actual request and authenticated inventory checks first. Delete only resources you create; where resources are supplied, restore the documented baseline instead. Pass the final check before removing temporary CLI configuration. No screenshot submission is required.
Is this a full certification or production deployment course?
It provides introductory practice, not full exam coverage or a complete production architecture. Wider design, DNS, hybrid connectivity and operational topics belong to later courses.





