How do you restrict access to EC2 instances in a VPC?

What is a VPC peering connection and when would you use it?

How does AWS VPC support VPN connections?

What are security groups and how do they differ from network ACLs?

Can a subnet span multiple Availability Zones?