Virtual private cloud
Isolated section where you can launch resources in a virtual network
Subnets
Public/private group of resources
Network control access list
Checks for permission to leave/enter subnet based on sender and how it’s communicating if touches boundary
Stateful
Memory on who to let in/out
Domain name service
Translates website name to IP address
Security groups
Stateful, deny inbound traffic by default