AWS Certified Advanced Networking – Specialty (ANS-C01) practice questions

200 free questions with answers and explanations.

Practice test
  1. 151.A company is migrating a legacy application to AWS that relies on multicast for service discovery and inter-instance communication. The application will be deployed across several subnets within a single VPC. How can multicast traffic be supported in this AWS environment?Network Design
  2. 152.A large corporation uses AWS Organizations to manage hundreds of accounts. They need to establish secure and private connectivity between their on-premises data centers and multiple VPCs spread across different accounts and Regions. The solution must provide a single point of entry and exit for all on-premises traffic to AWS, simplify network management, and support dynamic routing. Which networking construct should be implemented?Network Design
  3. 153.A company is designing a new application that will run in multiple AWS Regions. The application requires high availability and low-latency access for users globally. The architecture includes a global Accelerator that directs user traffic to the nearest healthy endpoint. Which component is essential for ensuring that only healthy application endpoints receive traffic?Network Design
  4. 154.A security-conscious organization requires all outbound internet traffic from its development and test VPCs to be inspected by a third-party firewall appliance. These VPCs are in different accounts but within the same AWS Region. The solution must be scalable, minimize routing complexity, and ensure that no traffic can bypass the firewall. What is the most effective architecture to implement this?Network Design
  5. 155.A global company operates a highly available web application with users distributed across multiple continents. The application uses Amazon Route 53 for DNS resolution. To minimize latency for users, the company wants to route traffic to the AWS Region that provides the best user experience based on actual network conditions. Which Route 53 routing policy should be implemented?Network Design
  6. 156.A global software company needs to provide private and secure access to its SaaS application, hosted in an AWS VPC, for its enterprise customers. Each customer has their own AWS account and VPCs. The solution must ensure that traffic between customer VPCs and the SaaS application VPC does not traverse the public internet and simplifies network configuration for customers. What is the most appropriate service to achieve this?Network Design
  7. 157.A company is designing a new application that will process sensitive financial data. The application's backend services need to access Amazon S3 and Amazon DynamoDB without traversing the public internet. The security team mandates that all traffic must remain within the AWS network and be fully private. Which networking construct should be implemented to ensure secure and private access to these AWS services from within the VPC?Network Design
  8. 158.A global software company is deploying a new multi-tenant SaaS application. Each customer's environment is isolated in its own AWS account and VPC. The SaaS application, hosted in a central 'Provider' VPC, needs to offer private and secure access to its services for hundreds of customer VPCs without exposing the services to the public internet or requiring VPC peering. The solution must scale efficiently as new customers are onboarded. Which AWS networking service should the company use?Network Design
  9. 159.A global enterprise is deploying a new web application that requires extremely low latency for users worldwide. The application backend is hosted in EC2 instances behind an Application Load Balancer (ALB) in multiple AWS Regions (e.g., N. Virginia, Ireland, Sydney). The enterprise wants to ensure that users are always directed to the closest healthy endpoint, bypassing potential internet congestion. Which AWS service is best suited to achieve this goal?Network Design
  10. 160.A large enterprise with a complex hybrid cloud environment needs to resolve DNS queries for both on-premises resources (using Windows DNS servers) and AWS resources (within VPCs). They require a highly available and secure solution that allows EC2 instances in AWS to resolve on-premises hostnames and on-premises servers to resolve private DNS names of AWS resources. Which AWS service and configuration should be used to achieve this bidirectional DNS resolution?Network Design
  11. 161.An e-commerce company operates a highly available web application across multiple AWS Regions. They need to implement a disaster recovery (DR) strategy where if the primary Region becomes unavailable, traffic automatically fails over to a secondary Region with minimal downtime. The solution must use DNS-based failover.Network Design
  12. 162.A global software company provides a SaaS application to customers worldwide. Each customer requires strict network isolation and dedicated access to the application's API endpoints, which are hosted in a shared AWS account (the SaaS provider's account). The customers' applications reside in their own AWS accounts and cannot traverse the public internet for security reasons. Which AWS service should the software company use to provide secure, private, and dedicated access to its SaaS API endpoints for each customer?Network Design
  13. 163.A financial institution needs to establish a highly secure and private connection between its on-premises data center and its AWS VPCs. This connection must support high bandwidth and consistently low latency for sensitive transaction data. The solution should also be resilient to single points of failure. Which AWS hybrid connectivity option is most appropriate?Network Design
  14. 164.A company is deploying a new containerized application that requires high availability across multiple Availability Zones within a single VPC. The application's backend services need to communicate with each other using internal DNS names, and the frontend services need to distribute incoming traffic efficiently while maintaining session stickiness for certain user interactions. Which combination of AWS networking components should be used to meet these requirements?Network Design
  15. 165.A global company has a complex network architecture with hundreds of VPCs spread across multiple AWS Regions and accounts. They need a robust and scalable solution to manage IP addresses, prevent overlaps, and centralize the allocation of CIDR blocks to new VPCs. The solution should also integrate with their existing on-premises IPAM system for hybrid cloud consistency. Which AWS service is explicitly designed for this purpose?Network Design
  16. 166.A global gaming company is launching a new multiplayer game that requires extremely low latency for all players worldwide. The game servers are deployed in multiple AWS Regions. The company needs a solution that provides a single, static entry point for players, automatically routes them to the optimal game server based on real-time network conditions, and ensures rapid failover if a server or region becomes unhealthy, without relying on DNS caching. Which AWS service is purpose-built for these requirements?Network Design
  17. 167.A global enterprise with a complex on-premises network and hundreds of AWS VPCs needs a robust IP address management solution. They require centralized visibility, automated IP allocation, and the ability to prevent IP overlaps across their hybrid cloud environment. The solution must integrate with existing AWS services and support delegated administration. Which AWS service should they utilize?Network Design
  18. 168.A financial institution is migrating a legacy mainframe application that relies heavily on IP multicast for service discovery and inter-process communication to AWS. The application will be deployed across multiple EC2 instances in different subnets within a single VPC. The security team insists on keeping the application in a private subnet and only allowing necessary traffic. How can multicast traffic be supported efficiently and securely within this AWS VPC?Network Design
  19. 169.A global manufacturing company has deployed a new application across multiple AWS Regions. They need to implement a DNS strategy that routes users to the application endpoint in the Region that provides the lowest network latency. Additionally, if an endpoint in a preferred Region becomes unhealthy, traffic should automatically fail over to a healthy endpoint in another Region. Which Route 53 routing policies should they combine to achieve this?Network Design
  20. 170.A global enterprise is migrating several critical applications to AWS. These applications reside in different VPCs across multiple AWS accounts, all within the same AWS Region. The enterprise requires secure and high-throughput communication between these VPCs, without exposing traffic to the public internet. They also need to simplify network management and avoid complex peering relationships. Which AWS networking service is the most appropriate solution to meet these requirements?Network Design
  21. 171.A large enterprise with a complex hybrid cloud environment needs to resolve DNS queries for both on-premises resources and AWS VPC resources. They have multiple AWS accounts and VPCs in different regions, and their on-premises data centers use Active Directory integrated DNS. The solution must allow applications in any AWS VPC to resolve on-premises DNS records and on-premises applications to resolve DNS records for any AWS VPC, without exposing internal DNS to the public internet. Furthermore, the solution must be highly available and resilient to failure. Which AWS DNS architecture should be implemented?Network Design
  22. 172.An infrastructure team is deploying a new application that will use a private subnet for its backend services and requires secure access to Amazon S3 and DynamoDB without traversing the public internet. The application must also fetch container images from Amazon ECR. All traffic must remain within the AWS network. Which networking components are required to meet these connectivity requirements?Network Design
  23. 173.A global enterprise is expanding its AWS footprint across multiple regions and accounts. They have a strict requirement for network segmentation, ensuring that specific environments (e.g., Development, Staging, Production) cannot communicate directly with each other, even if they reside in different VPCs within the same region or across regions, unless explicitly allowed through a centralized firewall. All inter-VPC traffic must flow through a central hub. Which AWS networking service and configuration strategy will best achieve this granular network segmentation?Network Design
  24. 174.A company is deploying a new web application that requires high availability and low-latency access for users globally. The application is hosted in `us-east-1`, `eu-west-1`, and `ap-northeast-1`. They want to ensure that if a user's local DNS resolver fails or is slow, the application remains reachable and responsive. Which DNS strategy provides high availability for DNS resolution itself and can direct users to the closest healthy endpoint?Network Design
  25. 175.A large organization uses multiple AWS accounts and VPCs across several regions. They need to implement a centralized egress strategy where all outbound internet traffic from development and test VPCs passes through a dedicated set of security appliances in a 'security VPC' in the primary region. This setup must also support IPv6 traffic. Which architecture pattern should they implement?Network Design
  26. 176.A multinational corporation has a hybrid cloud environment with its primary data center in Frankfurt and several AWS VPCs across different regions. They use AWS Transit Gateway in each region to connect their VPCs. They need to establish a highly available and low-latency private connection between their on-premises data center and all their AWS VPCs. This connection must also support routing between the on-premises network and VPCs in other AWS Regions. Which combination of AWS services should be implemented?Network Design
  27. 177.A media company is streaming high-definition video content globally. They need to ensure users experience the lowest possible latency when accessing their content, regardless of their geographic location. The solution must intelligently route user requests to the nearest healthy application endpoint. Which AWS service is best suited for this requirement?Network Design
  28. 178.A large multinational corporation has hundreds of AWS accounts organized under AWS Organizations, with VPCs spread across multiple regions. The networking team needs a robust solution to centrally manage and allocate IP addresses for all VPCs, ensuring no CIDR block overlaps. They also need to provide visibility into IP utilization and automate the IP address management process. Which AWS service is purpose-built to address these requirements?Network Design
  29. 179.A software development company has multiple development VPCs in different AWS accounts, all within the same region. They need to establish secure and efficient communication between these development VPCs for various microservices and shared tooling. The security team also requires that specific development environments (e.g., 'feature-dev' vs. 'bugfix-dev') maintain network isolation, only allowing explicitly permitted traffic. Which AWS networking solution provides the most scalable and manageable way to connect these VPCs while enforcing segmentation?Network Design
  30. 180.A large-scale data analytics company needs to migrate a legacy application to AWS. This application relies heavily on IP multicast for service discovery and data distribution among its components. The company has identified that standard AWS VPC networking does not natively support IP multicast. Which AWS networking component can facilitate IP multicast traffic within and across VPCs?Network Design
  31. 181.A global company operates a web application with users distributed across North America, Europe, and Asia. They have deployed identical application stacks in AWS Regions in N. Virginia, Ireland, and Singapore. The company wants to ensure that users are routed to the closest healthy application endpoint to minimize latency. If an entire region becomes unhealthy, traffic should automatically fail over to the next closest healthy region. Which Amazon Route 53 routing policy combination should be used to achieve this goal?Network Design
  32. 182.A multinational corporation has a hybrid cloud environment with its primary data center in Frankfurt and AWS presence in `eu-central-1` and `eu-west-1`. They use AWS Direct Connect for private connectivity between their data center and AWS. The corporate IT policy requires that all internal traffic between their on-premises network and any AWS VPC, as well as between VPCs themselves (across regions), must be routed through their Direct Connect Gateway and then through a centralized Transit Gateway in `eu-central-1` before reaching its destination. How should this complex routing be configured to ensure high availability and proper traffic flow?Network Design
  33. 183.A global software company needs to provide private and secure access to its SaaS application, hosted in multiple AWS VPCs across different accounts, for its enterprise customers. Each customer requires dedicated private access without traversing the public internet, and the solution must simplify network management for both the SaaS provider and the customers. Which AWS service should the company use?Network Design
  34. 184.A global enterprise with operations in North America, Europe, and Asia is migrating its critical customer-facing applications to AWS. The applications are hosted in separate VPCs in `us-east-1`, `eu-west-1`, and `ap-southeast-2`. The enterprise needs to ensure that users are always routed to the nearest healthy application endpoint to minimize latency and improve user experience. If an application endpoint in a region becomes unhealthy, traffic should automatically fail over to the next closest healthy region. Which routing strategy should the enterprise implement?Network Design
  35. 185.A large e-commerce company uses AWS for its entire infrastructure. They have multiple production VPCs across different AWS accounts within the same AWS Region. The security team mandates that all outbound internet traffic from these production VPCs must be inspected and filtered by a centralized set of security appliances (firewalls, IDS/IPS) hosted in a dedicated 'Security VPC'. Which AWS networking service should be used to achieve this centralized egress routing for all production VPCs?Network Design
  36. 186.A company is designing a new cloud-native application that requires isolation between different environments (development, staging, production) within the same AWS account. Each environment will reside in its own VPC. They need a routing strategy that allows controlled communication between these VPCs without exposing them to the public internet, and facilitates shared services access while maintaining security boundaries. Which solution provides the most scalable and manageable inter-VPC connectivity?Network Design
  37. 187.A software development company has multiple development VPCs in different AWS accounts, all connected to a central Transit Gateway. They need to implement a network segmentation strategy to ensure that traffic from one development VPC cannot directly reach another development VPC, but all development VPCs must be able to reach a shared services VPC. Which Transit Gateway routing configuration will achieve this?Network Design
  38. 188.A global enterprise with hundreds of AWS accounts and VPCs needs to establish private and secure connectivity between its on-premises data centers and its AWS resources. The solution must support thousands of routes, redundant connections, and centralize network management to reduce operational overhead. Which AWS networking service combination should the enterprise use?Network Design
  39. 189.An international media company has deployed a content streaming application across multiple AWS Regions (`us-east-1`, `eu-central-1`, `ap-southeast-1`) to serve its global audience. They need to ensure that users experience the lowest possible latency when accessing content, even if there are intermittent network issues or performance degradations between the user and their nearest AWS Region. The solution must provide intelligent traffic routing that considers real-time network conditions. Which AWS networking solution can best meet these requirements?Network Design
  40. 190.A healthcare provider is migrating its critical patient data applications to AWS. The applications are hosted in private subnets across multiple VPCs in the `us-east-2` region. Due to strict compliance requirements (HIPAA), all communication between these applications and shared services (e.g., Amazon S3 for data archival, Amazon CloudWatch for logging) must occur privately, without traversing the public internet. Furthermore, the solution must be simple to deploy and manage. Which AWS networking solution should the provider implement?Network Design
  41. 191.A large multi-national corporation uses hundreds of AWS accounts organized under AWS Organizations. Each business unit operates its own set of VPCs in various AWS Regions. The corporate IT department needs to implement a standardized and centralized IP address management solution that can allocate IP addresses for new VPCs and subnets across all accounts and regions, prevent IP conflicts, and provide a clear hierarchical view of IP space utilization. Which AWS service is best suited for this requirement?Network Design
  42. 192.A financial institution needs to establish a highly available and secure hybrid DNS resolution strategy. On-premises applications must resolve AWS internal hostnames (e.g., EC2 private IPs), and AWS applications must resolve on-premises hostnames. The solution must not expose internal DNS resolvers to the public internet.Network Design
  43. 193.A solutions architect needs to design a network for a new application that will host multiple microservices. Each microservice needs to be isolated from the others and have its own dedicated subnet. The application requires highly available internet access for outbound connections from these private subnets. Which AWS networking component should the architect use to provide a scalable and highly available outbound internet connection for these private subnets?Network Implementation
  44. 194.A multinational corporation has hundreds of AWS accounts organized under AWS Organizations. Each account manages multiple VPCs across various regions. The networking team needs a centralized solution to allocate and manage IP addresses for all VPCs, ensuring non-overlapping CIDR blocks and simplifying IP space planning. What AWS service should they implement?Network Design
  45. 195.An e-commerce company operates a highly available web application across multiple AWS Regions. They want to ensure that users are always directed to the closest healthy endpoint to minimize latency. If an endpoint becomes unhealthy, traffic should automatically fail over to another healthy endpoint. Which Amazon Route 53 routing policy combination should be used?Network Design
  46. 196.A large manufacturing company has a hybrid cloud environment, with critical applications running both on-premises and in AWS. They need to ensure seamless DNS resolution for all resources, regardless of their location. Specifically, AWS resources must be able to resolve on-premises DNS records, and on-premises resources must be able to resolve AWS private DNS records (e.g., those in Route 53 private hosted zones). Which AWS service combination provides this bi-directional, hybrid DNS resolution?Network Design
  47. 197.A global software company provides a Software-as-a-Service (SaaS) application to customers worldwide. Each customer has their own AWS account and requires private and secure access to the SaaS application, which runs in the vendor's AWS account. The solution must ensure that customer traffic does not traverse the public internet and that the SaaS application remains highly available and scalable. Which AWS networking service should the SaaS provider use to enable this private connectivity?Network Design
  48. 198.A large enterprise with hundreds of AWS accounts and VPCs needs to establish private and secure connectivity between their on-premises network and their AWS resources. They require high bandwidth and consistent network performance, bypassing the public internet, and the solution must support connectivity to multiple VPCs across different AWS Regions. Which networking service combination should they use to meet these requirements?Network Design
  49. 199.A software development company uses AWS Organizations to manage multiple accounts, with each team owning several VPCs. They need to implement a centralized egress strategy for all internet-bound traffic from Development VPCs to ensure all traffic passes through a set of security appliances (firewalls, IDS/IPS) in a dedicated Egress VPC before reaching the public internet. This must apply to both IPv4 and IPv6 traffic. How can this be achieved efficiently?Network Design
  50. 200.A global enterprise requires a highly secure and private connection between their on-premises network and AWS, specifically for accessing Amazon S3 and DynamoDB without traversing the public internet. They have multiple VPCs in different accounts, and the solution must be cost-effective and scalable. Which approach should the networking team recommend?Network Design