AWS Certified Advanced Networking – Specialty (ANS-C01) practice questions
200 free questions with answers and explanations.
- 1.A global e-commerce company uses AWS for its payment processing systems. Due to PCI DSS compliance requirements, all data in transit for these systems must be encrypted. The company heavily relies on AWS Direct Connect for connectivity between its on-premises data centers and AWS VPCs. Which solution provides the strongest encryption and meets the compliance requirements for data in transit over Direct Connect connections?Network Security, Compliance, and Governance
- 2.A company is using AWS Transit Gateway to connect multiple VPCs and on-premises networks via AWS Direct Connect. They need to implement automated routing updates between their on-premises routers and the Transit Gateway. The solution must support dynamic routing and automatically propagate route changes. Which routing protocol should be configured between the on-premises routers and the Transit Gateway?Network Management and Operations
- 3.A company is deploying a new containerized application that requires very high network throughput and low latency between its services. These services are deployed as EC2 instances within a single Availability Zone (AZ) in a private subnet. The application also needs to ensure that the instances are physically located close to each other to minimize inter-instance communication latency. Which placement strategy should the network engineer use for these EC2 instances?Network Implementation
- 4.A global e-commerce company uses AWS Direct Connect to establish a dedicated network connection between its on-premises data centers and AWS. They are experiencing intermittent connection issues and want to quickly identify if the problem lies with the Direct Connect connection itself, specifically packet loss or errors. Which AWS service and metric should they primarily monitor to diagnose this issue?Network Management and Operations
- 5.A large-scale application generates significant network traffic between EC2 instances. The network team wants to identify the top talkers and listeners within a VPC to optimize network performance and troubleshoot potential bottlenecks. The solution needs to process large volumes of flow data in near real-time and provide actionable insights. Which AWS service combination is best suited for this task?Network Management and Operations
- 6.A financial services company needs to establish secure and private connectivity between its on-premises data centers and multiple VPCs in AWS. The solution must support high bandwidth and low latency for critical financial transactions and ensure that all traffic is encrypted in transit. Which combination of AWS services would best meet these requirements?Network Security, Compliance, and Governance
- 7.A financial services company has a strict requirement for network traffic to be encrypted in transit between their on-premises data center and AWS VPCs. They are using AWS Site-to-Site VPN connections. To ensure compliance and verify that all VPN traffic is indeed encrypted, they need a mechanism to monitor the encryption status and key exchange process of their VPN tunnels. Which AWS monitoring capability directly provides this information?Network Management and Operations
- 8.A development team needs to deploy a web application that will be accessed by users globally. The application requires a single, static entry point (IP address) for users, and traffic needs to be routed to the nearest healthy endpoint in one of three AWS Regions (`us-east-1`, `eu-central-1`, `ap-northeast-1`). The solution must also improve performance by routing user traffic over the AWS global network backbone. Which AWS service should be used?Network Implementation
- 9.A network engineer needs to establish network connectivity between two VPCs, VPC-A (10.0.0.0/16) and VPC-B (10.1.0.0/16), located in different AWS accounts within the same AWS Region. The connection must support high bandwidth and low latency, and the number of connected VPCs is expected to grow significantly over time. Which solution provides the most scalable and efficient way to achieve this connectivity?Network Implementation
- 10.A company requires a highly available and secure connection between their on-premises data center and their AWS VPC. They have an existing AWS Direct Connect connection. To enhance security and provide an additional layer of encryption for specific sensitive traffic, they want to establish VPN connections over the Direct Connect. Which type of VPN connection should be configured?Network Implementation
- 11.A pharmaceutical company is moving its research data to Amazon S3. The data is highly sensitive and subject to strict regulatory compliance, requiring all data to be encrypted at rest and in transit, with encryption keys fully managed by the customer for maximum control. Which S3 encryption option, combined with appropriate key management, would meet these stringent requirements?Network Security, Compliance, and Governance
- 12.A global manufacturing company needs to establish secure, encrypted connectivity between their on-premises data centers and multiple VPCs in different AWS regions. The solution must support dynamic routing and automatically failover in case of a connection disruption. They currently do not have AWS Direct Connect. Which AWS networking solution is most appropriate?Network Security, Compliance, and Governance
- 13.A company is deploying a new web application that will handle sensitive customer data. They need to ensure that all data in transit between the client browser and the application's Elastic Load Balancer (ELB) is encrypted using TLS 1.2 or higher. Additionally, they must prevent any connections using older, less secure TLS versions. How can this be achieved using AWS services?Network Security, Compliance, and Governance
- 14.A company is deploying a new web application that requires high availability and low latency, distributed across multiple AWS regions. They need to ensure that users are always routed to the nearest healthy application endpoint. The networking team wants to implement a solution that automatically performs health checks and shifts traffic away from unhealthy endpoints without manual intervention. Which AWS service is most appropriate for this requirement?Network Management and Operations
- 15.A company is migrating its on-premises data center to AWS. They need to establish a highly available and resilient network connection between their on-premises network and their AWS VPCs. The solution must support multiple VPN tunnels and automatically fail over in case of a connection failure. Which AWS service provides this capability?Network Management and Operations
- 16.A company is deploying a new service in a VPC with a CIDR block of 10.0.0.0/20. They need to create a private subnet that can host exactly 20 EC2 instances, with room for 50% growth. Which of the following CIDR blocks is the smallest and most appropriate for this subnet?Network Implementation
- 17.A company heavily relies on AWS Direct Connect for hybrid connectivity, utilizing multiple Direct Connect gateways (DXGWs) to connect various on-premises locations to multiple VPCs across different AWS regions. The network team needs to implement a cost optimization strategy to reduce data transfer costs over these Direct Connect links, specifically for traffic between VPCs in different regions that are connected to the same DXGW. Which approach is the most cost-effective for inter-region VPC traffic when using Direct Connect Gateways?Network Management and Operations
- 18.A large healthcare organization utilizes AWS for hosting sensitive patient data and applications. Due to strict HIPAA compliance requirements, all network traffic within their VPCs and between VPCs must be inspected for malicious activity and unauthorized data exfiltration. They need a scalable, managed solution that can be centrally deployed and enforced across multiple VPCs and AWS accounts. Which AWS service is best suited for this requirement?Network Security, Compliance, and Governance
- 19.A company is migrating its on-premises data center to AWS. They need to establish a secure and private connection between their on-premises network and their AWS VPC. The connection must support multiple VLANs and have a dedicated bandwidth of 10 Gbps. Additionally, they require a backup connection that can also support high bandwidth. Which networking solution should they implement?Network Implementation
- 20.A company is extending its on-premises data center to AWS using a combination of AWS Direct Connect and AWS Site-to-Site VPN for redundancy. They have multiple VPCs in different AWS Regions that need to communicate with the on-premises network. What is the most effective way to centralize and simplify the routing between the on-premises network and all AWS VPCs across multiple Regions?Network Implementation
- 21.A global e-commerce company needs to secure its web application, which is hosted on Amazon EC2 instances behind an Application Load Balancer (ALB). They require protection against common web exploits like SQL injection and cross-site scripting (XSS), and also need to implement rate-based limiting to mitigate DDoS attacks. Which AWS service is best suited to address these requirements?Network Security, Compliance, and Governance
- 22.A company is using AWS Transit Gateway to connect over 100 VPCs across multiple AWS Regions. The network operations team frequently needs to troubleshoot routing issues and ensure that traffic between specific source and destination VPCs traverses the expected path. Manually inspecting route tables for each VPC and Transit Gateway attachment is becoming unmanageable and error-prone. Which AWS Network Manager feature can automate the validation of network paths across this complex environment?Network Management and Operations
- 23.A large enterprise uses AWS Organizations to manage multiple AWS accounts and has a strict policy that all internet-bound traffic from EC2 instances must be inspected by a centralized set of security appliances in a dedicated security VPC. They also need to ensure that this policy is automatically enforced across all new and existing VPCs without manual intervention. Which AWS service combination provides the most efficient and compliant solution?Network Management and Operations
- 24.A network engineer needs to configure a new VPC with a CIDR block of 10.0.0.0/20. The VPC requires at least five subnets, with the largest subnet needing to accommodate 100 EC2 instances and the smallest needing to accommodate 10 instances. What is the most efficient subnetting scheme to meet these requirements while minimizing wasted IP addresses?Network Implementation
- 25.A global Software-as-a-Service (SaaS) provider uses Amazon DynamoDB for its multi-tenant application. Each tenant has a unique identifier, and the application needs to ensure that users can only access data belonging to their own tenant within DynamoDB. The solution must provide fine-grained access control based on the tenant ID present in the user's authentication context, without requiring extensive application-level logic for authorization. Which IAM policy configuration, leveraging DynamoDB's capabilities, would best achieve this?Network Security, Compliance, and Governance
- 26.A security architect is designing a multi-account AWS environment for a new highly regulated application. They need to ensure that all data stored in Amazon EBS volumes attached to EC2 instances is encrypted by default. This encryption must use customer-managed keys (CMKs) from AWS Key Management Service (KMS), and the policy must be enforced at an organizational level to prevent any non-compliant EBS volumes from being created. How can this be achieved?Network Security, Compliance, and Governance
- 27.A company is expanding its AWS footprint and needs to connect multiple new VPCs to an existing Transit Gateway in a different AWS Region. The new VPCs are in `us-east-1`, and the Transit Gateway is in `us-west-2`. All traffic between these VPCs and the existing Transit Gateway must be routed privately and efficiently. How should the solutions architect configure this cross-region connectivity?Network Implementation
- 28.A global e-commerce platform experienced a large-scale Distributed Denial of Service (DDoS) attack that severely impacted their website availability, resulting in significant revenue loss. They need to implement a proactive, always-on DDoS protection service that automatically mitigates layer 3 and layer 4 attacks and provides advanced protection for their web applications and DNS. They also require 24/7 access to DDoS response experts. Which AWS service provides these capabilities?Network Security, Compliance, and Governance
- 29.A company is migrating its on-premises applications to AWS. They need to establish a dedicated, private connection between their on-premises data center and their AWS VPCs. The connection must offer high throughput and low latency. Which AWS service is designed for this purpose?Network Implementation
- 30.A company operates a web application with dynamic traffic patterns. During peak hours, users experience increased latency and connection timeouts. The current network configuration uses a single NAT Gateway in a public subnet for outbound internet access from private subnets. The NAT Gateway is showing high CPU utilization and dropped packets. What is the MOST effective way to optimize the network performance and improve resilience for outbound traffic?Network Management and Operations
- 31.An organization uses AWS Direct Connect to establish a private connection between their on-premises data center and their AWS VPC. They need to ensure that the maximum possible network throughput is achieved over this connection for large data transfers, and they are currently using a single 1 Gbps Direct Connect connection. The application is highly sensitive to latency and packet loss. Which configuration modification would best optimize the Direct Connect connection for higher throughput and resilience?Network Implementation
- 32.A compliance officer needs to verify that all Amazon S3 buckets in their AWS organization are configured with server-side encryption and that public access is blocked. They also need to ensure that this compliance posture is continuously maintained across all existing and newly created accounts. Which AWS service should be used to achieve this continuous monitoring and enforcement?Network Security, Compliance, and Governance
- 33.A global software-as-a-service (SaaS) provider uses AWS for its multi-tenant application. The security team needs to monitor for unusual and potentially unauthorized behavior, such as compromised EC2 instances, unusual API calls, or port scans, across all AWS accounts in their organization. They require a managed threat detection service that continuously monitors their AWS environment for these threats. Which AWS service is best suited for this requirement?Network Security, Compliance, and Governance
- 34.A healthcare provider is moving its sensitive patient data to Amazon S3. Compliance regulations mandate that all stored data must be encrypted at rest. Furthermore, access to this data must be strictly controlled, with different departments having varying levels of access. The security team wants to ensure that S3 bucket policies are not overly permissive and that access is granted based on the principle of least privilege. Which combination of AWS services and features should be used to enforce these access controls and compliance for the S3 buckets?Network Security, Compliance, and Governance
- 35.A company operates a critical application that relies on a stable and low-latency network connection to an on-premises data center. They use AWS Direct Connect for this hybrid connectivity. The network team needs to proactively detect any degradation in connection quality, such as an increase in packet loss or latency on the Direct Connect connection itself, before it impacts the application. Which CloudWatch metric, specifically for Direct Connect, should they monitor to identify packet loss?Network Management and Operations
- 36.A global company uses AWS Transit Gateway to connect multiple VPCs across several AWS Regions. They need to analyze network performance and identify potential bottlenecks for cross-region traffic. The solution must provide detailed visibility into latency, packet loss, and throughput between attachments. Which AWS service or feature provides this functionality?Network Management and Operations
- 37.A company is deploying a new web application that will host sensitive customer data. The security team requires that all HTTP traffic be automatically redirected to HTTPS, and that only strong ciphers and TLS versions are allowed for secure communication. This policy must be enforced at the load balancer level to offload SSL/TLS processing from the backend servers. Which configuration on an Application Load Balancer (ALB) listener would achieve these goals?Network Security, Compliance, and Governance
- 38.A financial services company operates a critical application on AWS that requires extremely low latency and high throughput between EC2 instances in different subnets within the same VPC. The application team is reporting inconsistent network performance and occasional spikes in latency, even during periods of low CPU utilization. They suspect network contention or resource exhaustion at the underlying infrastructure level. Which EC2 networking feature, when enabled, provides dedicated network bandwidth and improved packet-per-second (PPS) performance, making it suitable for such latency-sensitive workloads?Network Management and Operations
- 39.A solutions architect is designing a new VPC for a critical application that requires strict inbound and outbound traffic filtering at the subnet level. The application will run on EC2 instances within private subnets. Which AWS networking construct should the architect primarily use to achieve this granular subnet-level traffic control?Network Implementation
- 40.A company uses AWS Organizations to manage multiple AWS accounts. They need to ensure that all VPCs across all member accounts have consistent and compliant network configurations, such as specific security group rules, network ACLs, and routing policies. Manual configuration is prone to errors and does not scale. Which approach should the company use to automate and enforce these configurations?Network Management and Operations
- 41.A large enterprise needs to establish secure and private communication between hundreds of VPCs across multiple AWS Regions and their on-premises data centers, ensuring all traffic is routed through a central network appliance (e.g., a firewall virtual appliance) for inspection. The solution must be highly scalable and simplify network management. Which combination of AWS services would best meet these complex networking and security requirements?Network Security, Compliance, and Governance
- 42.A security audit reveals that several EC2 instances in a private subnet are directly accessing the internet for software updates, which is a security concern. The company policy requires all outbound internet traffic from private subnets to be inspected and logged. Which networking component should be deployed to allow private instances to securely initiate outbound internet connections while enabling centralized inspection and logging?Network Implementation
- 43.A global media company uses Amazon S3 to store large volumes of video content. They need to ensure that all data uploaded to an S3 bucket is encrypted at rest using server-side encryption with customer-provided encryption keys (SSE-C) to meet strict compliance requirements. How can the company enforce this encryption policy for all new objects uploaded to a specific S3 bucket?Network Security, Compliance, and Governance
- 44.A company is setting up a new VPC for a containerized application. The application will use a private IP address range of 10.100.0.0/20. The security team mandates that the VPC must have at least four private subnets, each capable of hosting a minimum of 200 instances. Additionally, there must be a separate public subnet for load balancers and NAT Gateways. What is the most efficient way to design the subnet CIDR blocks to meet these requirements while conserving IP addresses?Network Implementation
- 45.A company operates a web application that relies on a backend database in a private subnet. The application experiences intermittent performance issues, and network monitoring reveals high latency and occasional packet loss when the application instances communicate with the database. The application instances and the database are in the same Availability Zone. Which action would be MOST effective in reducing latency and improving network performance for this communication?Network Implementation
- 46.An organization is deploying a new application that uses a custom DNS domain, example.internal, for internal service discovery. The application will run on EC2 instances in a private subnet within a VPC. The organization also has an on-premises data center that needs to resolve these internal DNS names. What is the most appropriate solution to enable DNS resolution for example.internal from on-premises to AWS?Network Implementation
- 47.A security engineer needs to ensure that all network changes in their AWS environment are reviewed and approved before deployment. They want to implement a workflow that automatically flags any direct console or CLI changes to network configurations (e.g., Security Groups, Route Tables) that bypass their standard change management process. Which AWS service can be configured to detect and alert on these unauthorized direct changes?Network Management and Operations
- 48.An organization is migrating its on-premises applications to AWS. They use an existing IP address range (10.0.0.0/8) on-premises and want to extend this range into AWS using multiple VPCs. To avoid IP address conflicts and simplify routing, they plan to use non-overlapping subnets. However, they need a solution that allows them to allocate IP addresses for new EC2 instances and other network resources in a structured and automated way, ensuring that they don't accidentally provision resources with conflicting IPs. Which AWS service is designed to centrally manage and allocate IP address ranges for VPCs and their subnets?Network Management and Operations
- 49.An e-commerce company uses AWS CloudFront to distribute its content globally. To comply with regional data sovereignty laws and protect against common web exploits, the company needs to restrict content access based on the user's geographic location and filter malicious web requests before they reach the origin servers. Which AWS services should be configured together to achieve this?Network Security, Compliance, and Governance
- 50.A financial institution is migrating its on-premises applications to AWS. Due to stringent regulatory requirements, all network traffic, both internal and external, must be inspected for malicious activity and unauthorized data exfiltration. The institution needs a centralized solution that can enforce a consistent set of security policies across multiple AWS accounts and VPCs, and integrate with existing security information and event management (SIEM) systems. Which AWS service should be used to meet these requirements?Network Security, Compliance, and Governance