Architect network connectivity
Choose scalable connectivity, routing, DNS, segmentation, inspection, hybrid, and multi-Region patterns for complex organizations.
- Lesson
- d1-lesson
- Practice pool
- d1-questions
- Application
- sap-l02
Design organization-wide connectivity, security, resilience, governance, and cost visibility across accounts, Regions, workloads, and business boundaries.
Choose scalable connectivity, routing, DNS, segmentation, inspection, hybrid, and multi-Region patterns for complex organizations.
Establish organization-wide identity, detective, preventive, data, network, and delegated-administration controls with clear ownership.
Set availability, dependency, failure-isolation, recovery, quota, and operational patterns across organizational workloads.
Structure organizations, OUs, accounts, shared services, landing zones, guardrails, identity, logging, and account vending.
Allocate, attribute, forecast, govern, and optimize cost across accounts and business ownership boundaries.
Map business ownership, regulatory scope, autonomy, blast radius, quotas, billing, data residency, networking, identity, and operational responsibility before drawing accounts or VPCs. AWS accounts are strong ownership, isolation, and quota boundaries; organizational units group policy inheritance and administration.
Design account vending, identity federation, permission sets, organization policies, delegated administration, logging, security operations, backup, network, shared services, exceptions, acquisitions, and closure as lifecycles. Avoid routine workload administration from the management account.
Trace sites, Regions, VPCs, addresses, routes, DNS, inspection, encryption, bandwidth, latency, convergence, failure paths, and costs. Compare Site-to-Site VPN, Direct Connect, Transit Gateway, Cloud WAN, peering, PrivateLink, endpoints, and service-specific patterns from requirements. Centralization can improve governance while increasing shared-fate and routing complexity.
Set service and business objectives, dependency tolerances, quota headroom, recovery, and validation at the organizational level. Establish preventive, detective, response, data, network, and identity ownership. Use account tags, cost categories, budgets, allocation data, and unit economics so the people who can change demand can see its cost.
Design an organization for regulated and unregulated products across three business units and two Regions. Explain every account, OU, network, identity, security, logging, and billing boundary.