AWS Certified Advanced Networking – Specialty (ANS-C01) practice questions

200 free questions with answers and explanations.

Practice test
  1. 101.A company has multiple VPCs in a single AWS Region. They need to establish full mesh connectivity between all VPCs and also provide centralized internet egress for all private subnets through a set of security appliances. What is the most scalable and manageable solution for this scenario?Network Implementation
  2. 102.A company is deploying a new multi-tier application in a VPC (10.0.0.0/16). They require three private subnets for application servers (10.0.1.0/24), databases (10.0.2.0/24), and caching services (10.0.3.0/24). Additionally, they need a public subnet for load balancers and NAT Gateways, which should accommodate at least 50 usable IP addresses. Which of the following CIDR blocks is the most appropriate choice for the public subnet while ensuring no overlap and efficient use of IP addresses?Network Implementation
  3. 103.A media company uses Amazon CloudFront to distribute video content globally. To comply with regional content licensing agreements, they need to restrict access to specific content based on the viewer's geographic location. Additionally, they must protect against common web exploits like SQL injection and cross-site scripting. Which combination of AWS services should be used to meet these requirements?Network Security, Compliance, and Governance
  4. 104.A cybersecurity firm is deploying a network intrusion detection/prevention system (IDPS) in their AWS environment. They need to inspect all ingress and egress traffic for multiple VPCs in a centralized manner for deep packet inspection and threat analysis. The solution must be highly available, scalable, and minimize operational overhead. Which architectural pattern and AWS service facilitate this requirement?Network Security, Compliance, and Governance
  5. 105.A global enterprise uses AWS Transit Gateway to connect its numerous VPCs across multiple regions. The security team mandates that all outbound internet traffic from any VPC must be inspected by a third-party firewall appliance, which is deployed as an EC2 instance in a dedicated security VPC (10.0.0.0/16) in the `us-east-1` region. This appliance should be the single egress point for all internet-bound traffic from all connected VPCs, regardless of their region. How should a network engineer configure the Transit Gateway to enforce this security requirement?Network Implementation
  6. 106.A global media company uses AWS for its streaming platform, which experiences significant and unpredictable spikes in traffic during major live events. Their current Auto Scaling Group for web servers is configured to scale based on CPU utilization. However, customers are reporting buffering and slow load times during these spikes, even before CPU utilization reaches the scaling threshold. The network team suspects that the instances are being overwhelmed by network traffic before the CPU-based scaling can react. Which CloudWatch metric should be used as the primary scaling trigger to ensure the Auto Scaling Group reacts more quickly and effectively to network-intensive traffic spikes?Network Management and Operations
  7. 107.A company is deploying a new application that uses Amazon S3 to store critical business data. To meet compliance requirements, all data must be encrypted at rest. The security team wants to ensure that the encryption is enabled by default for all new objects uploaded to S3 buckets, without requiring application changes or users to explicitly specify encryption headers. Which S3 bucket configuration would achieve this?Network Security, Compliance, and Governance
  8. 108.A security engineer needs to ensure that all network configuration changes across multiple AWS accounts and Regions are audited and can be reverted if necessary. The solution should provide a centralized view of changes and prevent unauthorized modifications to critical network resources like VPCs, subnets, and route tables. Which AWS service combination should be used?Network Management and Operations
  9. 109.A company is deploying a new web application in AWS that processes sensitive customer data. The application requires robust protection against common web exploits such as SQL injection and cross-site scripting (XSS). Additionally, the company wants to implement rate-based rules to mitigate potential DDoS attacks at the application layer. Which AWS service should be used to meet these requirements?Network Security, Compliance, and Governance
  10. 110.A global enterprise has a multi-Region AWS deployment, with VPCs in `us-east-1`, `eu-west-1`, and `ap-southeast-2`. They use AWS Transit Gateway in each Region to connect local VPCs. The enterprise needs to enable secure and low-latency communication between applications running in VPCs across these different Regions. What is the most appropriate networking construct to achieve this goal?Network Implementation
  11. 111.A solutions architect is designing a network for a new application that will host multiple microservices in a single VPC. Each microservice needs to operate in its own isolated subnet and communicate with other microservices as well as an external API over the internet. The architect wants to ensure that all outbound traffic from the microservice subnets is routed through a centralized firewall appliance deployed in a dedicated subnet. How can this be achieved while maintaining high availability and minimizing network complexity?Network Implementation
  12. 112.A media streaming platform needs to protect its content delivery infrastructure on AWS from distributed denial-of-service (DDoS) attacks. The platform uses Amazon CloudFront, Application Load Balancers (ALB), and Amazon EC2 instances. The company requires advanced DDoS protection, including automatic inline mitigation, near real-time visibility into attacks, and cost protection for scaling resources during an attack. Which AWS service should be implemented?Network Security, Compliance, and Governance
  13. 113.An innovative startup is developing a new serverless application on AWS, utilizing AWS Lambda, Amazon API Gateway, and Amazon DynamoDB. The application processes user data, and the company needs to control access to specific Lambda functions and DynamoDB tables based on the authenticated user's role and permissions, following the principle of least privilege. Which AWS service should be used to implement this fine-grained access control mechanism?Network Security, Compliance, and Governance
  14. 114.A company requires a highly secure and compliant network architecture for its sensitive data in AWS. All EC2 instances in private subnets must have outbound internet access for patching and updates, but all traffic must be inspected by a third-party firewall appliance. The solution needs to be highly available and scale automatically. Which approach should a network architect choose?Network Implementation
  15. 115.A security architect is designing a multi-account AWS environment for a new highly regulated application. The primary requirement is to ensure that all Amazon EBS volumes created in any account within the organization are always encrypted by default, and that unencrypted volume creation is explicitly prevented. Additionally, administrators should not be able to bypass this encryption requirement. Which AWS Organizations feature, combined with a specific policy, can enforce this across all accounts?Network Security, Compliance, and Governance
  16. 116.A solutions architect is designing a network for a new application in AWS. The application will be deployed in a private subnet and needs to access several AWS services (e.g., S3, DynamoDB) without traversing the public internet. Furthermore, the company policy dictates that all traffic to these AWS services must remain within the AWS network for security and compliance reasons. Which type of VPC endpoint should be configured to meet these requirements?Network Implementation
  17. 117.A network architect is designing a highly secure network for a financial services application. All outbound internet traffic from private subnets must be inspected by a third-party firewall appliance running on an EC2 instance before reaching the Internet Gateway. The solution must be highly available and scale automatically. Which AWS service should be used to route traffic through the firewall appliance transparently?Network Implementation
  18. 118.A large enterprise uses AWS Transit Gateway to interconnect hundreds of VPCs. The network operations team frequently needs to troubleshoot routing issues and verify network paths between specific EC2 instances in different VPCs. Manually inspecting Transit Gateway route tables and VPC route tables for each connection path is time-consuming and error-prone. Which AWS Network Manager feature can simplify this task?Network Management and Operations
  19. 119.A global enterprise needs to ensure all data transferred between their on-premises data centers and AWS VPCs is encrypted in transit using FIPS 140-2 validated cryptography. They are currently using AWS Direct Connect for connectivity. Which solution provides the required encryption and compliance?Network Security, Compliance, and Governance
  20. 120.A company operates a high-traffic web application with backend services hosted on EC2 instances behind an Application Load Balancer (ALB). During peak hours, the application experiences intermittent 5xx errors and increased latency, even though individual EC2 instance CPU utilization remains low. Analysis of network metrics shows a high number of dropped packets at the network interface level for the EC2 instances. The network engineer suspects that the instances are hitting network limits for packet processing. Which EC2 instance attribute can be modified to increase the maximum packets per second (PPS) and overall network bandwidth for the instances?Network Management and Operations
  21. 121.A company operates a critical multi-tier application in an AWS VPC. They want to ensure that all network changes, such as modifications to security groups, network ACLs, or route tables, are reviewed and approved before being applied to production environments. They also need a way to easily roll back changes if issues arise. Which AWS service can be used to manage network infrastructure as code, facilitate change review, and enable version control for network configurations?Network Management and Operations
  22. 122.A global e-commerce company uses AWS Direct Connect to establish a dedicated network connection between its on-premises data centers and AWS VPCs in multiple regions. They are experiencing intermittent latency spikes and packet loss for traffic traversing the Direct Connect connection. The network team needs to quickly identify if the issue lies with the AWS network, the Direct Connect connection itself, or their on-premises network. Which AWS monitoring tool provides the most direct visibility into the health and performance of the Direct Connect connection?Network Management and Operations
  23. 123.A financial services company is deploying a new critical application in AWS that requires extremely low latency and high network throughput between its EC2 instances. The application architecture involves several tightly coupled microservices communicating frequently. The company needs to ensure that these instances are placed in a way that minimizes network jitter and maximizes bandwidth. Which AWS networking feature should a solutions architect recommend to meet these requirements?Network Implementation
  24. 124.A global company uses AWS Transit Gateway to connect its numerous VPCs across multiple regions. They have a requirement to centrally inspect all east-west traffic (VPC-to-VPC) for security and compliance purposes using a set of third-party network virtual appliances. The appliances reside in a dedicated inspection VPC. How can the network engineer configure Transit Gateway to meet this requirement efficiently?Network Implementation
  25. 125.A large enterprise is transitioning to a microservices architecture on AWS. They require that all newly provisioned EC2 instances automatically adhere to baseline security configurations, such as specific AMI versions, mandatory security groups, and encryption of EBS volumes. This compliance needs to be continuously monitored, and any non-compliant resources must be automatically remediated. Which combination of AWS services can achieve this goal?Network Security, Compliance, and Governance
  26. 126.A global media company uses AWS for its streaming platform, which experiences significant and unpredictable traffic spikes during major live events. The current network architecture includes several EC2 instances behind an Application Load Balancer (ALB) in each region. The company wants to optimize network performance and reduce the time it takes for new EC2 instances to become fully operational and handle traffic during these spikes. Which networking optimization strategy will most effectively reduce the latency associated with new instance registration and warm-up time for the ALB?Network Management and Operations
  27. 127.A data analytics company needs to process large datasets stored in Amazon S3 from EC2 instances in a private subnet. To ensure data privacy and reduce data transfer costs, all S3 traffic must remain within the AWS network and not traverse the public internet. Which type of VPC Endpoint should be configured?Network Implementation
  28. 128.A media company streams large volumes of video content globally using Amazon CloudFront and S3. They want to optimize the cost of data transfer out of AWS while maintaining high performance for their global audience. What is the MOST cost-effective strategy to achieve this?Network Management and Operations
  29. 129.A company is migrating an on-premises application to AWS. The application uses a custom DNS suffix, `corp.example.com`, for internal services. The AWS environment consists of multiple VPCs, and the company wants to ensure that EC2 instances in these VPCs can resolve both public domain names and the internal `corp.example.com` names without using custom DNS servers on each instance. The internal DNS records for `corp.example.com` are managed by an on-premises DNS server located in the corporate data center. Which AWS networking service should be configured to enable this hybrid DNS resolution?Network Implementation
  30. 130.A software company operates a highly sensitive application on AWS. They need to ensure that all network traffic between their application servers (EC2 instances) and their database servers (EC2 instances) within the same VPC is strictly controlled at the instance level. Specifically, they want to allow only necessary ports and protocols between these tiers and deny all other traffic by default. Which AWS security construct provides this granular, stateful filtering capability at the instance level?Network Security, Compliance, and Governance
  31. 131.A compliance officer needs to ensure that all Amazon S3 buckets across their AWS organization are configured with block public access settings enabled and that server access logging is always turned on. Any new or existing bucket that violates these rules must be automatically flagged and, if possible, remediated. Which combination of AWS services offers the most effective solution for continuous auditing and automated remediation of these S3 configurations?Network Security, Compliance, and Governance
  32. 132.A company is deploying a new web application in a VPC. The application requires a highly available and scalable solution for distributing incoming HTTP/HTTPS traffic across multiple EC2 instances. The solution must support path-based routing, host-based routing, and SSL termination. Which AWS load balancing service should be used?Network Implementation
  33. 133.A financial institution requires strict network segmentation and isolation for different environments (e.g., development, staging, production) within a single AWS account. Each environment has its own set of VPCs, and direct communication between them is strictly prohibited unless explicitly allowed through a central inspection point. How can this be architected using AWS Transit Gateway to enforce strict isolation and controlled inter-VPC communication?Network Management and Operations
  34. 134.A software-as-a-service (SaaS) company hosts its multi-tenant application on AWS. They need to restrict access to their Amazon DynamoDB tables based on the tenant ID present in the user's IAM role session. This ensures that a tenant can only access their own data. Which IAM policy condition key should be used to enforce this fine-grained access control?Network Security, Compliance, and Governance
  35. 135.A network engineer is configuring a new AWS VPC (10.10.0.0/20) for a development environment. The VPC will host several EC2 instances that need to access the internet for software updates and external APIs, but no inbound internet traffic should reach these instances. Which is the most secure and cost-effective solution for outbound internet access?Network Implementation
  36. 136.A large enterprise uses AWS Organizations to manage multiple AWS accounts. They have a strict security policy requiring that all S3 buckets in specific accounts must deny public access and enforce encryption at rest. The security team needs an automated solution to continuously monitor and enforce these compliance rules across new and existing S3 buckets without manual intervention. Which AWS service combination should be used to achieve this goal efficiently?Network Management and Operations
  37. 137.A global enterprise needs to enforce strict, consistent security policies across hundreds of AWS accounts and VPCs. These policies include ensuring that all Amazon S3 buckets are encrypted by default, all EC2 instances use approved AMIs, and specific network traffic patterns are blocked at the perimeter. The solution must provide centralized management and automated remediation for non-compliant resources. Which AWS service is best suited for this comprehensive governance and compliance requirement?Network Security, Compliance, and Governance
  38. 138.A network engineer wants to monitor the flow of traffic between EC2 instances in different subnets within a VPC and detect anomalies. The solution must be cost-effective and provide detailed insights into IP traffic. Which AWS service should the engineer use?Network Management and Operations
  39. 139.A company is experiencing high network latency and jitter for a critical application hosted on EC2 instances when accessing an external third-party API over the public internet. The application is sensitive to network performance, and standard internet connectivity is proving unreliable. They need to optimize the routing of their outbound internet-bound traffic to improve performance and reduce latency. Which AWS service can intelligently route traffic over the AWS global network to minimize latency to internet destinations?Network Management and Operations
  40. 140.A company is migrating its critical applications to AWS and requires a network architecture that provides isolated environments for different departments (Finance, HR, Engineering) within the same AWS account. Each department needs its own IP address space, and communication between departments should be restricted by default but selectively allowed through a central firewall. Which networking construct is best suited to achieve this segmentation?Network Design
  41. 141.A media company needs to provide low-latency access to its content for users across North America, Europe, and Asia. They have deployed their application and content in multiple AWS Regions. The company wants to use a global load balancing solution that routes users to the nearest available Region, considering the actual network latency from the user to the AWS edge. Which AWS service should they choose?Network Design
  42. 142.A financial services company needs to establish secure communication between its on-premises data center and a new application hosted in an AWS VPC. The connection must use IPsec VPN, support multiple tunnels for redundancy and increased throughput, and automatically failover between tunnels. Which AWS service provides a fully managed solution for this requirement?Network Design
  43. 143.A financial institution needs to establish a highly available and secure hybrid DNS resolution strategy. On-premises DNS servers must be able to resolve AWS private hosted zones, and AWS workloads must be able to resolve on-premises DNS records. The solution should minimize latency and provide redundancy. Which combination of AWS services should be used?Network Design
  44. 144.A company is designing a new multi-tenant SaaS application that requires strong network isolation between each tenant's resources while maintaining shared access to central services (e.g., identity, logging) within the same AWS Region. Each tenant will have their own dedicated VPC. How can the shared services be accessed privately and securely by each tenant VPC without complex routing or exposing the shared services to the public internet?Network Design
  45. 145.A global media company uses AWS for its content delivery platform. They need to optimize the routing of user requests to the nearest healthy application endpoint across multiple AWS regions. The solution should dynamically route traffic based on both geographic proximity and real-time application health. Which Amazon Route 53 routing policy should be configured?Network Design
  46. 146.A global company has a complex network architecture with hundreds of VPCs spread across multiple AWS accounts and regions. They need to implement a new IP addressing scheme to prevent CIDR block overlaps and simplify routing. The new scheme must allow for future growth and be easily auditable. Which IP addressing strategy is most suitable for this scenario?Network Design
  47. 147.An e-commerce company experiences seasonal traffic spikes and needs to ensure its application remains highly available and performs optimally during peak loads. The application is deployed across multiple EC2 instances behind an Application Load Balancer (ALB) in an Auto Scaling group. The company wants to distribute incoming traffic evenly across healthy instances and scale capacity automatically. Which load balancing feature is crucial for achieving this distribution while handling variable traffic?Network Design
  48. 148.A global enterprise with hundreds of AWS accounts needs to manage IP addresses for its VPCs in a scalable and organized manner. The company wants to ensure that IP address ranges do not overlap and that allocations are consistent across different business units and environments. Which AWS service is best suited for this requirement?Network Design
  49. 149.A large manufacturing company has a hybrid cloud environment, with critical applications running both on-premises and in AWS. They need to ensure that their on-premises users can consistently resolve DNS records for AWS resources, including private hosted zones, and that AWS applications can resolve on-premises DNS records. The solution must be fault-tolerant and highly available. Which AWS service provides the most robust solution for this bidirectional DNS resolution?Network Design
  50. 150.A company is deploying a new microservices application across multiple VPCs in different AWS accounts, all within the same region. Each microservice needs to communicate with other microservices without exposing them to the public internet, and the network architecture should minimize the number of direct network connections. The solution must also allow for central network visibility and control. Which AWS service is ideal for connecting these microservices VPCs?Network Design