DNS, CDN, and edge services account for 33 questions on SOA-C03, making this one of the most heavily tested areas. This guide explains each service from the basics, so you understand not just the facts but the reasoning behind them.
What is DNS and Why Does It Exist?
When you type www.example.com into your browser, your computer does not actually know where that server is. It only understands IP addresses like 192.0.2.1. DNS (Domain Name System) acts as the internet's phone book, translating human-friendly domain names into machine-readable IP addresses.
Just like looking up a friend's name in a phone book to find their number, your device looks up a domain name in DNS to find the server's IP address. Only then can it make a connection.
Amazon Route 53 — AWS DNS and Traffic Routing
Route 53 is AWS's DNS service. Beyond simple name-to-IP translation, it provides powerful routing policies that let you control exactly where traffic goes based on various criteria.
The name comes from DNS port number 53, combined with the word Route to suggest traffic routing.
Hosted Zones — Containers for DNS Records
A hosted zone is like one company's phone book, a collection of DNS records for a single domain.
Public Hosted Zone manages records for internet-facing domains. Anyone on the internet can look up example.com and get an answer.
Private Hosted Zone manages records visible only within specific VPCs. Useful for internal domains like internal.company.com that should not be resolvable from the public internet.
DNS Record Types
| Type | Purpose | Example | |------|---------|---------| | A record | Domain to IPv4 address | www.example.com -> 192.0.2.1 | | AAAA record | Domain to IPv6 address | www.example.com -> 2001:db8::1 | | CNAME record | Domain to another domain name | blog.example.com -> www.example.com | | Alias record | Domain to AWS resource | example.com -> ALB or CloudFront |
The Alias vs CNAME distinction is frequently tested. You must know this clearly.
CNAME points one domain name to another domain name. However, it cannot be used at the Zone Apex, which means the root domain itself (example.com). You can use CNAME for www.example.com but not for example.com directly. This is a DNS standard limitation. Additionally, CNAME queries incur charges per lookup.
Alias is a Route 53 extension to the DNS standard. It can be used at the Zone Apex (example.com), solving the problem CNAME cannot handle. It points directly to AWS resources like ALB, CloudFront distributions, S3 static website endpoints, and Elastic Beanstalk URLs. Alias queries are free. Use Alias whenever you need to point your root domain to an AWS resource.
Route 53 Routing Policies — The Most Critical Topic
You must know all seven routing policies and which scenario each one solves. This is heavily tested.
Simple Routing is the most basic policy. It returns a single IP address for a domain. Use it when you have one resource and need no special logic. It does not support health checks.
Weighted Routing assigns weights to multiple resources and distributes traffic proportionally. It is ideal for A/B testing. For example, send 90 percent of traffic to your stable production version and 10 percent to your new version to test it safely. Setting a weight of 0 stops traffic to that resource entirely.
Latency-based Routing routes each user to the AWS Region that provides the lowest network latency for them. A user in Seoul connects to the Tokyo or Seoul region. A user in New York connects to the Virginia region. Use this to optimize user experience for a globally deployed application.
Failover Routing creates an Active-Passive disaster recovery setup. While the primary resource passes its health check, all traffic goes there. The moment the health check fails, Route 53 automatically redirects traffic to the secondary resource. This is essential for any high-availability architecture.
Geolocation Routing directs traffic based on where the user is located geographically, country or continent level. Users from South Korea go to a Korean-language server. Users from the United States go to an English-language server. This is also useful for legal compliance, such as restricting certain content to specific countries.
Geoproximity Routing routes based on geographic distance between users and resources, but adds a Bias value that lets you shift the boundary. Increasing bias for a resource expands the geographic area it serves. Must be used with Route 53 Traffic Flow, the visual traffic policy editor.
Multivalue Routing returns multiple IP addresses (up to 8) and includes only healthy resources, those passing health checks. It provides basic load distribution. It is not a replacement for Elastic Load Balancer but works well for simple use cases with multiple servers.
Route 53 Health Checks
Health checks periodically verify that your resources are functioning correctly, like a doctor scheduling regular checkups for a patient.
You can monitor HTTP/HTTPS endpoints, TCP connections, or the status of other health checks (calculated health checks). Combined with Failover routing, health checks enable automatic failover when a primary resource becomes unavailable. You can also integrate with CloudWatch alarms to get notifications when resources fail.
Amazon CloudFront — Global Content Delivery Network
CloudFront is a CDN (Content Delivery Network) service. It caches your content at edge locations distributed around the world so users receive it faster, from a location closer to them.
Think of a convenience store chain. You could run one central warehouse and make everyone travel there to buy products. Or you could stock products in local convenience stores near where customers live. CloudFront is the convenience store network. Your origin server is the warehouse.
Without CloudFront, a user in Seoul downloading an image stored in an S3 bucket in Virginia must wait for data to travel halfway around the world, hundreds of milliseconds. With CloudFront, the image is cached at the Seoul edge location and delivered in tens of milliseconds.
CloudFront Origins
An origin is the source server where CloudFront fetches content when it is not already cached.
S3 buckets store static files like images, CSS, JavaScript, and HTML. ALB (Application Load Balancer) sits in front of dynamic web applications. EC2 instances can serve as web servers directly. External HTTP servers outside AWS can also be origins.
CloudFront Caching
TTL (Time to Live) defines how long cached content remains valid before CloudFront fetches a fresh copy from the origin. The default is 24 hours (86,400 seconds). Set longer TTL for rarely-changing content like images or fonts. Set shorter TTL for frequently-changing content like news feeds.
Cache Invalidation forces CloudFront to delete cached content before its TTL expires. If you update your website but users still see the old version, run an invalidation. You can specify path patterns like /images/* to invalidate specific files only. Invalidations do incur a small charge.
Cache Key determines which requests share the same cached response. A cache key is typically the URL path, but can also include query strings, headers, and cookies. A simpler cache key means more requests hit the cache, improving performance. Adding unnecessary headers or cookies to the cache key reduces cache efficiency.
CloudFront OAC (Origin Access Control) — Protecting S3 Content
OAC restricts access to your S3 bucket so that content is only accessible through CloudFront, not directly via S3 URLs.
Imagine this scenario: you serve images through CloudFront. Someone figures out the direct S3 URL and starts downloading content without going through CloudFront. OAC solves this by configuring the S3 bucket policy to only allow requests that come from CloudFront's service principal. Direct S3 URL requests are blocked. OAC is the modern replacement for the older OAI (Origin Access Identity).
AWS Global Accelerator — Static IPs Plus AWS Global Network
Global Accelerator improves application performance by routing user traffic to the nearest AWS edge location and then carrying it across AWS's high-speed internal network to your application endpoints.
Here is the problem it solves. The public internet routes traffic through many independent ISP networks. Each segment has different speeds and reliability. Global Accelerator takes your traffic off the public internet as early as possible, routing it onto AWS's fast, reliable backbone network for most of the journey.
It provides two static Anycast IP addresses. Because these IPs never change, you can fail over between regions without any DNS changes or propagation delays. It supports both TCP and UDP protocols, making it ideal for real-time applications like multiplayer games, VoIP calls, and financial trading systems.
CloudFront vs Global Accelerator
| Feature | CloudFront | Global Accelerator | |---------|-----------|-------------------| | Primary use | Cacheable content (images, video, HTML) | Non-cacheable real-time applications | | IP addresses | Domain-based, can change | 2 static Anycast IPs, never change | | Protocols | HTTP and HTTPS | TCP and UDP | | Caching | Yes, at edge locations | No caching | | Best for | Websites, media distribution | Gaming, VoIP, IoT, financial apps |