AWS Certified Advanced Networking – Specialty (ANS-C01) practice questions
200 free questions with answers and explanations.
- 51.An enterprise requires all network traffic leaving their AWS VPCs to pass through a centralized inspection VPC before reaching the internet. This includes traffic from multiple spoke VPCs in different accounts. The solution must provide deep packet inspection and intrusion prevention capabilities. Which networking and security constructs are essential to implement this architecture efficiently and securely?Network Security, Compliance, and Governance
- 52.A global enterprise has multiple AWS accounts and VPCs spread across different AWS Regions. They need to enable communication between VPCs in different Regions. The solution must be scalable and minimize administrative overhead. Which AWS service should be used?Network Implementation
- 53.A multinational corporation has a complex hybrid cloud architecture using AWS Direct Connect Gateway (DXGW) to connect multiple on-premises data centers to various VPCs across different AWS Regions. The network operations team is observing intermittent packet loss and increased latency between specific on-premises locations and certain AWS VPCs. They need to quickly identify the exact path segment where the performance degradation is occurring, whether it's on the AWS network, the Direct Connect link, or the on-premises network. Which AWS service can provide the most comprehensive end-to-end path analysis for this scenario?Network Management and Operations
- 54.A network architect is designing a multi-VPC environment where different application teams manage their own VPCs. They need to ensure that traffic between these VPCs can be routed efficiently without creating a complex mesh of peering connections. Additionally, the architects want to enforce centralized network policies and visibility. Which AWS networking component should be used to achieve this?Network Implementation
- 55.A financial institution requires a highly secure and compliant network architecture in AWS. They are using multiple VPCs in different accounts, and all inter-VPC communication must be inspected by a central set of firewalls. Additionally, they need to ensure that no traffic can bypass these firewalls, even if a misconfiguration occurs in a VPC route table. What networking configuration, beyond standard Transit Gateway setup, should the network engineer implement?Network Implementation
- 56.A company is designing a new multi-tier application in AWS. The application will have a web tier, an application tier, and a database tier. The web tier instances need to be publicly accessible, while the application and database tiers must remain private. All tiers require access to common AWS services like S3 and DynamoDB without traversing the public internet. The VPC CIDR block is 10.0.0.0/16. What is the most efficient way to ensure private access to S3 and DynamoDB for the private subnets?Network Implementation
- 57.An organization has multiple AWS accounts and VPCs across different AWS Regions. They need to establish secure and private communication between these VPCs and their on-premises data center, which has a single Direct Connect connection in eu-west-1. The solution must provide global connectivity and simplify routing. Which combination of AWS networking services should be used?Network Implementation
- 58.A healthcare provider is storing sensitive patient data in Amazon S3. To meet HIPAA compliance, all data must be encrypted at rest. Furthermore, the encryption keys must be managed by the customer, and there must be an audit trail of key usage. Which encryption method and key management strategy should be implemented?Network Security, Compliance, and Governance
- 59.A company is migrating its on-premises applications to AWS. They use multiple VPCs and need to establish secure, encrypted communication between these VPCs and their on-premises data center over existing AWS Direct Connect connections. The solution must support dynamic routing and be highly available. Which architecture should the company implement?Network Security, Compliance, and Governance
- 60.A global enterprise is migrating a legacy application to AWS. The application relies on multicast for service discovery and data distribution among its backend components. The new architecture uses multiple VPCs connected via AWS Transit Gateway. The network architect needs to enable multicast communication between specific EC2 instances located in different subnets across these Transit Gateway-attached VPCs. Which AWS service and configuration is required to support this multicast traffic flow?Network Management and Operations
- 61.A large enterprise needs to implement a robust network intrusion detection and prevention system (IDPS) for its applications hosted on AWS. The solution must provide deep packet inspection, be highly scalable, and capable of protecting multiple VPCs across different AWS accounts. Which AWS service or architecture best meets these requirements?Network Security, Compliance, and Governance
- 62.A company is setting up a new VPC for a containerized application. The application will use a private subnet (10.0.1.0/24) for its containers and requires a public subnet for a Load Balancer and NAT Gateway. The VPC CIDR is 10.0.0.0/16. What is the largest non-overlapping CIDR block that could be assigned to the public subnet while keeping it within the same VPC and ensuring it does not overlap with the private subnet?Network Implementation
- 63.A company is deploying a new containerized application that requires extremely low latency and high network throughput between its containers, which are deployed as EC2 instances. These instances must be located physically close to each other to minimize network hop and maximize performance. Which EC2 placement strategy should be used?Network Implementation
- 64.A company operates a critical application on AWS, serving a global user base. They use Amazon CloudWatch to monitor various metrics, but often find themselves manually correlating logs from VPC Flow Logs, CloudTrail, and application logs to troubleshoot network performance issues. This manual process is time-consuming and prone to errors. The company needs a solution that can centralize and analyze network-related logs efficiently, provide real-time insights into network performance, and help quickly identify the root cause of issues. Which AWS service is best suited to meet these requirements?Network Management and Operations
- 65.A security auditor needs to periodically review all network access control lists (NACLs) and security groups (SGs) across multiple AWS accounts to ensure they comply with the company's least-privilege security policies. The auditor needs to quickly identify any overly permissive rules, such as ingress rules allowing '0.0.0.0/0' on sensitive ports, or egress rules allowing all outbound traffic. What is the most efficient and scalable AWS service to perform this type of continuous compliance auditing for network access controls?Network Management and Operations
- 66.A research institution is deploying a new application that will process highly confidential data. They need to ensure that all data in transit across public networks is encrypted end-to-end to meet stringent privacy regulations. The application will communicate between different AWS regions and also with on-premises data centers over the internet. Which solution provides the most secure and compliant method for encrypting data in transit in this scenario?Network Security, Compliance, and Governance
- 67.A large enterprise has a multi-account AWS environment with hundreds of VPCs across several regions. They need to enforce a consistent set of security policies, including WAF rules, Shield Advanced protections, and custom Firewall Manager policies, across all their web applications and underlying resources. This must be managed centrally by the security team without manual configuration in each account or VPC. Which AWS service provides this centralized, automated policy enforcement?Network Security, Compliance, and Governance
- 68.A financial institution requires a highly secure and compliant network architecture in AWS. They need to ensure that all traffic between their on-premises data center and their AWS VPCs is encrypted end-to-end and traverses a private, dedicated connection. Furthermore, they must have a backup connectivity solution that also meets the encryption requirements. Which combination of AWS networking services should be implemented?Network Implementation
- 69.A large medical research institution uses AWS to host sensitive patient data and genomic analysis applications. Due to strict compliance requirements (e.g., HIPAA), all network traffic, including traffic between EC2 instances within the same VPC and between VPCs, must be inspected by a centralized set of security appliances (e.g., firewalls, IDS/IPS). The institution uses AWS Transit Gateway for inter-VPC connectivity. Which architectural pattern, supported by AWS Transit Gateway, should be implemented to ensure all traffic passes through the centralized inspection VPC?Network Management and Operations
- 70.A global software-as-a-service (SaaS) provider uses AWS for its multi-tenant application. They have multiple AWS accounts for different environments (dev, staging, prod) and regions. The security team needs to ensure consistent network security policies, such as specific firewall rules for web application traffic, are applied and enforced across all accounts and regions. Manual configuration is prone to errors and policy drift. Which AWS service can be used to centrally manage and automatically deploy these network security policies across all accounts and regions within an AWS Organization?Network Management and Operations
- 71.A company is experiencing high network latency between its on-premises data center and AWS VPCs over its AWS Site-to-Site VPN connections. They have already verified that their internet connection bandwidth is sufficient and on-premises firewall rules are correctly configured. They suspect that the issue might be related to suboptimal routing or network congestion within the AWS network or the internet path to AWS. Which AWS service can help diagnose and optimize the network path performance between their on-premises network and AWS?Network Management and Operations
- 72.A security auditor has identified that several Amazon EC2 instances in a company's AWS environment are running outdated operating systems and have open, unnecessary ports to the internet, creating significant security vulnerabilities. The company needs a service that can continuously assess their EC2 instances for software vulnerabilities and unintended network exposure. Which AWS service is designed to address this requirement?Network Security, Compliance, and Governance
- 73.A global e-commerce company uses AWS Direct Connect for its critical operations. They have multiple Direct Connect connections to different AWS regions. The network team needs to ensure consistent bandwidth availability and quickly identify any potential bottlenecks or saturation points across their Direct Connect links. Which AWS service and metric combination would provide the most effective real-time visibility into the aggregated bandwidth utilization of all Direct Connect connections?Network Management and Operations
- 74.A media company streams video content globally using Amazon CloudFront. To comply with regional data protection laws, the company must ensure that content served to users in specific geographic locations is blocked if it originates from unapproved regions. The security team also wants to prevent access from known malicious IP addresses or ranges. Which CloudFront feature should be configured to meet these requirements?Network Security, Compliance, and Governance
- 75.A compliance team needs to ensure that all AWS accounts within their organization adhere to a strict policy that prevents the creation of any Amazon S3 bucket that allows public read or write access. This policy must be applied universally and prevent any user or role from overriding it. Which AWS service can enforce this preventive control across the entire organization?Network Security, Compliance, and Governance
- 76.A security auditor discovers that a company's AWS environment has several Amazon EC2 instances with overly permissive security group rules, allowing SSH (port 22) and RDP (port 3389) access from '0.0.0.0/0'. This poses a significant security risk. The company needs to implement a solution to centrally manage and automatically enforce strict security group rules across all existing and newly created AWS accounts and VPCs in its AWS Organization, ensuring that such permissive rules are never deployed. Which AWS service combination should be used?Network Security, Compliance, and Governance
- 77.A global enterprise uses AWS Direct Connect to establish a private connection between their on-premises data centers and their AWS VPCs. They need to ensure that all data transmitted over these Direct Connect connections is encrypted in transit to meet stringent regulatory requirements. Which solution provides the MOST secure and compliant method for encrypting data over AWS Direct Connect?Network Security, Compliance, and Governance
- 78.A large enterprise uses AWS Organizations to manage multiple AWS accounts across different business units. Each business unit has its own VPCs and applications. The central networking team needs to enforce a consistent set of network security group rules across all newly created EC2 instances in all accounts. They want to automate this enforcement and ensure compliance, preventing individual teams from deviating from the standard. Which AWS service combination can achieve this goal most efficiently and scalably?Network Management and Operations
- 79.A company is experiencing intermittent connectivity issues to an application hosted on an EC2 instance. Users report slow response times and occasional timeouts. The network engineer suspects packet loss or high latency. Which CloudWatch metric should the engineer examine first to investigate these issues?Network Management and Operations
- 80.A security-conscious organization requires that all outbound internet traffic from its private subnets in a VPC be routed through a centralized set of security appliances (e.g., firewalls, IDS/IPS). These appliances are deployed in a dedicated 'DMZ' public subnet within the same VPC. How should the network engineer configure the routing to enforce this policy?Network Implementation
- 81.A global enterprise uses AWS for its applications and has a complex hybrid cloud environment. They need to ensure that DNS resolution for internal, on-premises resources (e.g., internalapp.corp.com) works seamlessly from EC2 instances in their AWS VPCs. They also have a Route 53 private hosted zone for AWS-internal applications (e.g., awsapp.internal). Which AWS service should be configured to allow EC2 instances to resolve on-premises DNS records without modifying instance configurations?Network Implementation
- 82.A highly regulated financial institution is deploying a new trading platform on AWS. Regulatory compliance mandates that all data at rest must be encrypted with customer-managed encryption keys (CMKs) and all data in transit must use TLS 1.2 or higher. The platform uses Amazon EC2 instances, Amazon S3 for data storage, and an Amazon RDS database. Which combination of actions will meet these encryption requirements?Network Security, Compliance, and Governance
- 83.A large enterprise with a multi-account AWS environment needs to centrally manage network access control for all VPCs. The security team wants to define a set of common egress filtering rules (e.g., blocking access to known malicious IPs, allowing access only to specific SaaS endpoints) and ensure these rules are automatically applied to new and existing VPCs across all accounts. Which AWS service is designed to achieve this centralized, automated management of network perimeter security?Network Security, Compliance, and Governance
- 84.A company is migrating an on-premises application that relies on multicast communication to discover services. The application will be deployed across multiple EC2 instances in different subnets within a single AWS VPC. Which AWS networking service or feature can enable multicast routing within the VPC?Network Implementation
- 85.A media company uses Amazon S3 to store large video files accessed by EC2 instances in private subnets. To optimize costs and improve security, the company wants to ensure that all traffic to S3 from these EC2 instances remains within the AWS network and does not traverse the public internet. Which VPC endpoint type should the network engineer implement?Network Implementation
- 86.A company is deploying a new web application that needs to automatically scale based on demand. The application requires high availability across multiple Availability Zones within a single region. Which AWS load balancing service should be used to distribute incoming web traffic to the EC2 instances running the application?Network Implementation
- 87.A network architect is designing a new VPC for a multi-tier application. The application consists of web servers in a public subnet and database servers in a private subnet. The database servers need to communicate with an external third-party API over the internet, but they must not be directly exposed to the internet. Which AWS networking component should the architect deploy in the public subnet to enable secure outbound internet access for the database servers?Network Implementation
- 88.A company has multiple AWS accounts and VPCs, all connected via a central AWS Transit Gateway. They need to ensure that their on-premises network, connected to the Transit Gateway via Direct Connect, can resolve DNS queries for private hosted zones in different AWS accounts that are also attached to the same Transit Gateway. What is the most efficient way to achieve this cross-account, on-premises to VPC DNS resolution?Network Implementation
- 89.A developer needs to deploy a new web application that requires a highly available and scalable database. The database should only be accessible from application servers within specific private subnets and should not be exposed to the public internet. Which AWS service and configuration would best meet these requirements?Network Implementation
- 90.A company has a multi-VPC architecture for different environments (development, staging, production) within the same AWS Region. Each VPC uses a distinct CIDR block. They need to simplify DNS resolution across these VPCs so that instances in one VPC can resolve private DNS hostnames (e.g., `app.dev.internal`) of instances in another VPC, without relying on IP addresses or complex routing table entries. All VPCs are connected via a Transit Gateway. Which Route 53 feature should be enabled and configured to achieve this seamless private DNS resolution?Network Implementation
- 91.A media streaming platform needs to protect its content delivery infrastructure on AWS from large-scale Distributed Denial of Service (DDoS) attacks. The platform uses Amazon CloudFront, Application Load Balancers, and EC2 instances. The solution must include advanced DDoS mitigation capabilities, 24/7 access to DDoS experts, and cost protection against scaling charges during an attack. Which AWS service is specifically designed to provide these comprehensive DDoS protections?Network Security, Compliance, and Governance
- 92.A global software-as-a-service (SaaS) provider uses AWS for its multi-tenant application. They are concerned about data exfiltration and unauthorized access attempts to their AWS resources. The security team wants to implement a service that continuously monitors AWS accounts for malicious activity and unauthorized behavior, such as unusual API calls, compromised EC2 instances, or cryptocurrency mining. This service should also integrate with their existing security operations center (SOC) for alerting. Which AWS service is best suited for this task?Network Security, Compliance, and Governance
- 93.A network engineer is designing a highly available and scalable solution for a web application deployed across multiple Availability Zones (AZs) within a single VPC. The application uses EC2 instances and needs to distribute incoming traffic evenly, while also supporting path-based routing for different microservices. Which AWS service should the engineer choose to meet these requirements?Network Implementation
- 94.A company is deploying a new service in a VPC with a CIDR block of 10.0.0.0/20. They need to create three private subnets of equal size and one public subnet for NAT Gateways, also of equal size. Each subnet must support at least 1000 usable IP addresses. Which subnet CIDR blocks should the network engineer use to meet these requirements?Network Implementation
- 95.A network security engineer needs to configure a highly available and secure connection between an on-premises data center and multiple VPCs in AWS. The solution must provide a private connection, encrypt all traffic, and automatically fail over in case of a connection disruption. The on-premises network uses redundant customer gateway devices. Which AWS networking components should be used to achieve this?Network Implementation
- 96.A financial services company is migrating a legacy application to AWS. The application requires strict network segmentation and stateful packet inspection at the subnet level within a VPC. Which AWS networking construct should be used to meet these requirements?Network Security, Compliance, and Governance
- 97.A security-conscious organization needs to ensure that all network traffic leaving their VPCs for the internet passes through a specific set of security appliances for deep packet inspection. The solution must be highly available and allow for scaling of these appliances. Which AWS networking construct should be utilized to achieve this centralized egress inspection?Network Implementation
- 98.A financial services company operates a critical online banking application on AWS. They need to ensure that all network traffic between their Amazon EC2 instances within a VPC is inspected for malicious content and potential data exfiltration without introducing significant latency. The solution must be scalable and centrally managed. Which AWS service combination is MOST suitable for this requirement?Network Security, Compliance, and Governance
- 99.A large multinational enterprise uses a hub-and-spoke network topology in AWS, with a central Transit Gateway in a shared services VPC. They have hundreds of spoke VPCs connected to this Transit Gateway. The network operations team frequently needs to troubleshoot routing issues and verify connectivity between specific EC2 instances in different spoke VPCs. Manually checking route tables and security groups for each path is time-consuming and error-prone. What is the most efficient AWS service to quickly visualize and diagnose potential network path issues across this complex environment?Network Management and Operations
- 100.A security-conscious organization needs to ensure that all network configurations in their AWS environment adhere to strict internal policies and regulatory compliance standards. They want to automate the detection of non-compliant network configurations, such as security groups with overly permissive rules or unapproved Network ACL changes, and ideally, automatically remediate these issues. Which two AWS services, when combined, provide the most robust solution for continuous auditing and automated remediation of network configurations?Network Management and Operations