Step2Study
IT & TechnologyANS-C01100% Free

AWS Certified Advanced Networking – Specialty (ANS-C01)

Practice bank
200 Qs
Real exam
65 Qs
Time limit
170 min
Passing
Scaled score of 750 out of 1,000

Exam blueprint

Network Design
30%
Network Implementation
26%
Network Management and Operations
20%
Network Security, Compliance, and Governance
24%

Practice

Untimed · instant feedback · 4 practice tests of 90 questions

Questions per test

Custom practice

Flashcard on every question Mental map when you miss

Exam simulation

4 timed tests · 90 questions each · 235 min · pass 75% · 200 questions in the bank

+50 XP per test · +100 XP for a pass

Random simulation (weighted by domain)

Everything is open to everyone. Create a free account to save scores, XP, badges and get progress emails.

Free study resources

All resources →

Study with friends

Challenge a friend to beat your score.

AWS Certified Advanced Networking – Specialty (ANS-C01) practice test questions

Sample questions from the 200-question bank, with answers and explanations.

All questions
  1. 1. A development team needs to deploy a web application that will be accessed by users globally. The application requires a single, static entry point (IP address) for users, and traffic needs to be routed to the nearest healthy endpoint in one of three AWS Regions (`us-east-1`, `eu-central-1`, `ap-northeast-1`). The solution must also improve performance by routing user traffic over the AWS global network backbone. Which AWS service should be used?

    Network Implementation

    • A. Amazon Route 53 with latency-based routing
    • B. AWS Transit Gateway with inter-Region peering
    • C. Application Load Balancer (ALB) with cross-Region load balancing
    • D. AWS Global Accelerator
    Show answer

    D. AWS Global Accelerator

    AWS Global Accelerator provides static IP addresses as a fixed entry point and uses the AWS global network backbone to route user traffic to the closest healthy endpoint. This significantly improves performance for global applications and offers faster failover than DNS-based solutions.

  2. 2. A network engineer needs to establish network connectivity between two VPCs, VPC-A (10.0.0.0/16) and VPC-B (10.1.0.0/16), located in different AWS accounts within the same AWS Region. The connection must support high bandwidth and low latency, and the number of connected VPCs is expected to grow significantly over time. Which solution provides the most scalable and efficient way to achieve this connectivity?

    Network Implementation

    • A. Set up a Site-to-Site VPN connection directly between VPC-A and VPC-B.
    • B. Deploy a NAT Gateway in each VPC and route traffic between them.
    • C. Configure an AWS Transit Gateway and attach both VPC-A and VPC-B to it.
    • D. Establish a VPC Peering connection between VPC-A and VPC-B.
    Show answer

    C. Configure an AWS Transit Gateway and attach both VPC-A and VPC-B to it.

    AWS Transit Gateway is designed for connecting thousands of VPCs and on-premises networks centrally. It simplifies network management and provides a highly scalable solution compared to managing numerous point-to-point VPC Peering connections as the number of VPCs grows.

  3. 3. A company requires a highly available and secure connection between their on-premises data center and their AWS VPC. They have an existing AWS Direct Connect connection. To enhance security and provide an additional layer of encryption for specific sensitive traffic, they want to establish VPN connections over the Direct Connect. Which type of VPN connection should be configured?

    Network Implementation

    • A. Site-to-Site VPN over Direct Connect (VPN over DX)
    • B. AWS Managed VPN without Direct Connect
    • C. AWS Client VPN
    • D. VPC Endpoint VPN
    Show answer

    A. Site-to-Site VPN over Direct Connect (VPN over DX)

    A Site-to-Site VPN connection can be established over a Direct Connect private VIF. This configuration provides an additional layer of encryption (IPsec) for data traversing the Direct Connect connection, meeting the security requirement for sensitive traffic.

  4. 4. A pharmaceutical company is moving its research data to Amazon S3. The data is highly sensitive and subject to strict regulatory compliance, requiring all data to be encrypted at rest and in transit, with encryption keys fully managed by the customer for maximum control. Which S3 encryption option, combined with appropriate key management, would meet these stringent requirements?

    Network Security, Compliance, and Governance

    • A. Server-Side Encryption with Customer-Provided Keys (SSE-C)
    • B. Server-Side Encryption with KMS Customer Master Keys (CMKs) – customer managed (SSE-KMS)
    • C. Server-Side Encryption with Amazon S3-Managed Keys (SSE-S3)
    • D. Client-Side Encryption with AWS Key Management Service (KMS)
    Show answer

    D. Client-Side Encryption with AWS Key Management Service (KMS)

    Client-Side Encryption (CSE) ensures that data is encrypted before it leaves the customer's environment, providing the highest level of customer control over the encryption process and keys. Using AWS KMS with CSE allows for management of the encryption keys within a FIPS 140-2 validated service, meeting the 'customer managed keys' and 'maximum control' requirements for both data at rest and in transit (as it's encrypted before transit).

  5. 5. A global manufacturing company needs to establish secure, encrypted connectivity between their on-premises data centers and multiple VPCs in different AWS regions. The solution must support dynamic routing and automatically failover in case of a connection disruption. They currently do not have AWS Direct Connect. Which AWS networking solution is most appropriate?

    Network Security, Compliance, and Governance

    • A. AWS Direct Connect with a dedicated connection to each region.
    • B. AWS Global Accelerator with endpoint groups in each region.
    • C. VPC Peering Connections between on-premises and each VPC.
    • D. AWS Site-to-Site VPN with AWS Transit Gateway in each region.
    Show answer

    D. AWS Site-to-Site VPN with AWS Transit Gateway in each region.

    AWS Site-to-Site VPN creates encrypted tunnels over the public internet, satisfying the 'encrypted connectivity' requirement without Direct Connect. Using AWS Transit Gateway allows for hub-and-spoke connectivity to multiple VPCs within a region and can peer with Transit Gateways in other regions for inter-region connectivity. VPN connections support BGP for dynamic routing and automatic failover.

  6. 6. A company is deploying a new web application that will handle sensitive customer data. They need to ensure that all data in transit between the client browser and the application's Elastic Load Balancer (ELB) is encrypted using TLS 1.2 or higher. Additionally, they must prevent any connections using older, less secure TLS versions. How can this be achieved using AWS services?

    Network Security, Compliance, and Governance

    • A. Install a custom Nginx configuration on the EC2 instances behind the ELB to enforce TLS 1.2.
    • B. Implement AWS WAF rules to block requests that negotiate TLS versions older than 1.2.
    • C. Configure the ELB listener to use a custom security policy that specifies TLS 1.2 and later, and disable older protocols.
    • D. Use Security Groups to block incoming traffic on ports associated with older TLS versions.
    Show answer

    C. Configure the ELB listener to use a custom security policy that specifies TLS 1.2 and later, and disable older protocols.

    Elastic Load Balancers (both Application Load Balancer and Classic Load Balancer) allow you to configure listener security policies. These policies define the SSL/TLS protocols and ciphers that the load balancer uses for frontend connections, enabling you to enforce TLS 1.2 or higher.

  7. 7. A company is deploying a new web application that requires high availability and low latency, distributed across multiple AWS regions. They need to ensure that users are always routed to the nearest healthy application endpoint. The networking team wants to implement a solution that automatically performs health checks and shifts traffic away from unhealthy endpoints without manual intervention. Which AWS service is most appropriate for this requirement?

    Network Management and Operations

    • A. AWS Global Accelerator with endpoint groups
    • B. Amazon CloudFront with origin failover
    • C. Application Load Balancer (ALB) with cross-zone load balancing
    • D. Amazon Route 53 with CNAME records
    Show answer

    A. AWS Global Accelerator with endpoint groups

    AWS Global Accelerator improves application availability and performance for global users by directing traffic to optimal healthy endpoints. It uses static IP addresses as entry points, and its health checks automatically reroute traffic to the next best healthy endpoint across regions, ensuring high availability and low latency.

  8. 8. A company is migrating its on-premises data center to AWS. They need to establish a highly available and resilient network connection between their on-premises network and their AWS VPCs. The solution must support multiple VPN tunnels and automatically fail over in case of a connection failure. Which AWS service provides this capability?

    Network Management and Operations

    • A. AWS Global Accelerator
    • B. AWS Client VPN
    • C. AWS Site-to-Site VPN
    • D. AWS Direct Connect
    Show answer

    C. AWS Site-to-Site VPN

    AWS Site-to-Site VPN provides a highly available and resilient connection between an on-premises network and AWS. Each VPN connection consists of two tunnels, ensuring automatic failover. It's suitable for secure, encrypted connectivity over the public internet.

  9. 9. A company is deploying a new service in a VPC with a CIDR block of 10.0.0.0/20. They need to create a private subnet that can host exactly 20 EC2 instances, with room for 50% growth. Which of the following CIDR blocks is the smallest and most appropriate for this subnet?

    Network Implementation

    • A. 10.0.0.0/27
    • B. 10.0.0.0/26
    • C. 10.0.0.0/25
    • D. 10.0.0.0/24
    Show answer

    B. 10.0.0.0/26

    20 instances + 50% growth = 30 instances. AWS reserves 5 IPs. So, 30 + 5 = 35 total IPs needed. A /26 CIDR block provides 64 total IPs (59 usable), which is the smallest block that accommodates 35 IPs. A /27 provides only 27 usable IPs, which is insufficient.

  10. 10. A company heavily relies on AWS Direct Connect for hybrid connectivity, utilizing multiple Direct Connect gateways (DXGWs) to connect various on-premises locations to multiple VPCs across different AWS regions. The network team needs to implement a cost optimization strategy to reduce data transfer costs over these Direct Connect links, specifically for traffic between VPCs in different regions that are connected to the same DXGW. Which approach is the most cost-effective for inter-region VPC traffic when using Direct Connect Gateways?

    Network Management and Operations

    • A. Route inter-region VPC traffic through the on-premises network.
    • B. Utilize VPC peering connections between VPCs in different regions instead of Direct Connect.
    • C. Use AWS Transit Gateway peering to connect VPCs across regions.
    • D. Ensure all inter-region VPC traffic connected to the same DXGW uses the AWS global network.
    Show answer

    D. Ensure all inter-region VPC traffic connected to the same DXGW uses the AWS global network.

    When VPCs in different regions are associated with the same Direct Connect Gateway, traffic between these VPCs can traverse the AWS global network without leaving AWS. This inter-region data transfer over the AWS global network, when initiated from a Direct Connect Gateway, is significantly more cost-effective than routing it back to on-premises (A), using separate VPC peering (B), or even Transit Gateway peering (D) which has its own data transfer costs. The key is that the traffic stays within AWS's optimized backbone.

  11. 11. A large healthcare organization utilizes AWS for hosting sensitive patient data and applications. Due to strict HIPAA compliance requirements, all network traffic within their VPCs and between VPCs must be inspected for malicious activity and unauthorized data exfiltration. They need a scalable, managed solution that can be centrally deployed and enforced across multiple VPCs and AWS accounts. Which AWS service is best suited for this requirement?

    Network Security, Compliance, and Governance

    • A. AWS Network Firewall
    • B. AWS GuardDuty
    • C. AWS Firewall Manager
    • D. VPC Endpoint Services
    Show answer

    A. AWS Network Firewall

    AWS Network Firewall is a managed service that provides intrusion prevention and detection, URL filtering, and stateful inspection for VPC traffic. It can be centrally managed and deployed across multiple VPCs via AWS Firewall Manager, making it ideal for the described scenario.

  12. 12. A company is migrating its on-premises data center to AWS. They need to establish a secure and private connection between their on-premises network and their AWS VPC. The connection must support multiple VLANs and have a dedicated bandwidth of 10 Gbps. Additionally, they require a backup connection that can also support high bandwidth. Which networking solution should they implement?

    Network Implementation

    • A. AWS Site-to-Site VPN with two tunnels
    • B. AWS Direct Connect with two 10 Gbps dedicated connections and a failover Site-to-Site VPN
    • C. AWS Direct Connect with a single 10 Gbps connection
    • D. AWS Direct Connect with two 10 Gbps dedicated connections and a Direct Connect Gateway
    Show answer

    D. AWS Direct Connect with two 10 Gbps dedicated connections and a Direct Connect Gateway

    Two 10 Gbps Direct Connect connections provide the required dedicated bandwidth and high availability. Using a Direct Connect Gateway allows these connections to access multiple VPCs in different regions, and supports multiple VLANs (Private VIFs) over the same connection. A failover Site-to-Site VPN is an option for resilience, but the question implies high bandwidth backup, which DX can provide.

  13. 13. A company is extending its on-premises data center to AWS using a combination of AWS Direct Connect and AWS Site-to-Site VPN for redundancy. They have multiple VPCs in different AWS Regions that need to communicate with the on-premises network. What is the most effective way to centralize and simplify the routing between the on-premises network and all AWS VPCs across multiple Regions?

    Network Implementation

    • A. Establish separate Direct Connect and VPN connections to each VPC in each Region.
    • B. Utilize a Direct Connect Gateway and associate it with Transit Gateways in each Region.
    • C. Configure a custom routing solution using EC2 instances as routers in a central VPC.
    • D. Implement a Transit Gateway in each Region and peer them together.
    Show answer

    B. Utilize a Direct Connect Gateway and associate it with Transit Gateways in each Region.

    A Direct Connect Gateway allows you to connect your Direct Connect connection to multiple VPCs in different AWS Regions and accounts. By associating the Direct Connect Gateway with Transit Gateways in each Region, you can centralize routing for all VPCs within those Regions to the on-premises network, providing a scalable and simplified architecture.

  14. 14. A global e-commerce company needs to secure its web application, which is hosted on Amazon EC2 instances behind an Application Load Balancer (ALB). They require protection against common web exploits like SQL injection and cross-site scripting (XSS), and also need to implement rate-based limiting to mitigate DDoS attacks. Which AWS service is best suited to address these requirements?

    Network Security, Compliance, and Governance

    • A. Amazon GuardDuty
    • B. AWS Shield Advanced
    • C. AWS WAF
    • D. AWS Network Firewall
    Show answer

    C. AWS WAF

    AWS WAF (Web Application Firewall) is specifically designed to protect web applications from common web exploits (like SQL injection and XSS) and allows for the creation of custom rules, including rate-based rules, to control bot traffic and mitigate Layer 7 DDoS attacks. It integrates directly with ALBs.

  15. 15. A company is using AWS Transit Gateway to connect over 100 VPCs across multiple AWS Regions. The network operations team frequently needs to troubleshoot routing issues and ensure that traffic between specific source and destination VPCs traverses the expected path. Manually inspecting route tables for each VPC and Transit Gateway attachment is becoming unmanageable and error-prone. Which AWS Network Manager feature can automate the validation of network paths across this complex environment?

    Network Management and Operations

    • A. Network Manager Global Network Dashboard.
    • B. Network Manager Events and Alarms.
    • C. Network Manager Route Analyzer.
    • D. Network Manager Insights.
    Show answer

    C. Network Manager Route Analyzer.

    AWS Network Manager's Route Analyzer is specifically designed to simulate and analyze network paths between a source and a destination within a global network, including Transit Gateway attachments and VPCs. It verifies that traffic follows the expected routes and helps identify misconfigurations or unexpected routing behavior, making it ideal for large-scale Transit Gateway environments.

  16. 16. A large enterprise uses AWS Organizations to manage multiple AWS accounts and has a strict policy that all internet-bound traffic from EC2 instances must be inspected by a centralized set of security appliances in a dedicated security VPC. They also need to ensure that this policy is automatically enforced across all new and existing VPCs without manual intervention. Which AWS service combination provides the most efficient and compliant solution?

    Network Management and Operations

    • A. AWS Transit Gateway with static routes and AWS Config rules
    • B. AWS Transit Gateway with Route Analyzer and AWS CloudFormation
    • C. AWS Transit Gateway with Appliance Mode and AWS Firewall Manager
    • D. AWS VPN with EC2 instances and AWS Systems Manager
    Show answer

    C. AWS Transit Gateway with Appliance Mode and AWS Firewall Manager

    AWS Transit Gateway with Appliance Mode allows routing traffic through a specific network appliance (like a firewall) in a centralized VPC. AWS Firewall Manager can then automatically deploy and manage the necessary Transit Gateway routes and firewall rules across all accounts and VPCs within an AWS Organization, ensuring consistent and automated enforcement of the security policy.

  17. 17. A network engineer needs to configure a new VPC with a CIDR block of 10.0.0.0/20. The VPC requires at least five subnets, with the largest subnet needing to accommodate 100 EC2 instances and the smallest needing to accommodate 10 instances. What is the most efficient subnetting scheme to meet these requirements while minimizing wasted IP addresses?

    Network Implementation

    • A. Use one /25, one /26, and three /28 subnets.
    • B. Use five /24 subnets.
    • C. Use one /25, one /26, one /27, one /28, and one /29 subnet.
    • D. Use one /25, one /26, and three /27 subnets.
    Show answer

    B. Use five /24 subnets.

    A /24 subnet provides 256 IP addresses (256-5 = 251 usable), which can accommodate 100 instances and 10 instances comfortably. Using five /24 subnets from a /20 VPC (which has 4096 addresses) allows for future growth and simplifies management, while still being efficient given the requirement for a subnet with 100 instances. This provides enough addresses for current needs and allows for expansion without complex VLSM for just five subnets.

  18. 18. A global Software-as-a-Service (SaaS) provider uses Amazon DynamoDB for its multi-tenant application. Each tenant has a unique identifier, and the application needs to ensure that users can only access data belonging to their own tenant within DynamoDB. The solution must provide fine-grained access control based on the tenant ID present in the user's authentication context, without requiring extensive application-level logic for authorization. Which IAM policy configuration, leveraging DynamoDB's capabilities, would best achieve this?

    Network Security, Compliance, and Governance

    • A. Use an IAM policy with a Condition key `dynamodb:LeadingKeys` to match the tenant ID in the partition key.
    • B. Implement an IAM policy that allows access to all DynamoDB tables, and filter results at the application layer.
    • C. Use AWS WAF to filter DynamoDB queries based on tenant ID before they reach the database.
    • D. Apply resource-based policies directly to each DynamoDB item to restrict access.
    Show answer

    A. Use an IAM policy with a Condition key `dynamodb:LeadingKeys` to match the tenant ID in the partition key.

    DynamoDB supports fine-grained access control through IAM policies, specifically using the `dynamodb:LeadingKeys` condition key. This allows restricting access to items where the partition key (or the first part of a composite primary key) matches a specific value, such as a tenant ID derived from the authenticated user's context, without complex application-level filtering.

  19. 19. A company is expanding its AWS footprint and needs to connect multiple new VPCs to an existing Transit Gateway in a different AWS Region. The new VPCs are in `us-east-1`, and the Transit Gateway is in `us-west-2`. All traffic between these VPCs and the existing Transit Gateway must be routed privately and efficiently. How should the solutions architect configure this cross-region connectivity?

    Network Implementation

    • A. Create a Transit Gateway peering attachment between the Transit Gateway in `us-west-2` and a new Transit Gateway in `us-east-1`, then attach the new VPCs to the `us-east-1` TGW.
    • B. Configure Site-to-Site VPN connections from each new VPC in `us-east-1` to the Transit Gateway in `us-west-2`.
    • C. Establish a VPC Peering connection between each new VPC in `us-east-1` and the Transit Gateway in `us-west-2`.
    • D. Use AWS Direct Connect Gateway to connect the `us-east-1` VPCs to the `us-west-2` Transit Gateway.
    Show answer

    A. Create a Transit Gateway peering attachment between the Transit Gateway in `us-west-2` and a new Transit Gateway in `us-east-1`, then attach the new VPCs to the `us-east-1` TGW.

    Transit Gateway peering allows you to connect Transit Gateways across different AWS Regions. This creates a global network where VPCs in one region can communicate with VPCs in another region via their respective Transit Gateways. Attaching the new VPCs to a local Transit Gateway in `us-east-1` and then peering that TGW with the `us-west-2` TGW is the most scalable and efficient solution for cross-region VPC connectivity.

  20. 20. A global e-commerce platform experienced a large-scale Distributed Denial of Service (DDoS) attack that severely impacted their website availability, resulting in significant revenue loss. They need to implement a proactive, always-on DDoS protection service that automatically mitigates layer 3 and layer 4 attacks and provides advanced protection for their web applications and DNS. They also require 24/7 access to DDoS response experts. Which AWS service provides these capabilities?

    Network Security, Compliance, and Governance

    • A. AWS WAF
    • B. Amazon CloudFront
    • C. AWS Shield Standard
    • D. AWS Shield Advanced
    Show answer

    D. AWS Shield Advanced

    AWS Shield Advanced provides enhanced DDoS protection for EC2, ELB, CloudFront, Global Accelerator, and Route 53. It offers always-on detection and automatic inline mitigations for L3/L4 attacks, and advanced protection for web applications. Critically, it includes 24/7 access to the AWS DDoS Response Team (DRT) for manual attack mitigation and post-attack analysis, which is a key requirement for this scenario.

  21. 21. A company is migrating its on-premises applications to AWS. They need to establish a dedicated, private connection between their on-premises data center and their AWS VPCs. The connection must offer high throughput and low latency. Which AWS service is designed for this purpose?

    Network Implementation

    • A. Internet Gateway
    • B. AWS Direct Connect
    • C. AWS Site-to-Site VPN
    • D. VPC Peering
    Show answer

    B. AWS Direct Connect

    AWS Direct Connect provides a dedicated, private network connection from your premises to AWS. This offers consistent network performance, higher bandwidth options, and lower latency compared to internet-based connections like VPN, making it ideal for high throughput and low latency requirements.

  22. 22. A company operates a web application with dynamic traffic patterns. During peak hours, users experience increased latency and connection timeouts. The current network configuration uses a single NAT Gateway in a public subnet for outbound internet access from private subnets. The NAT Gateway is showing high CPU utilization and dropped packets. What is the MOST effective way to optimize the network performance and improve resilience for outbound traffic?

    Network Management and Operations

    • A. Migrate the application to use VPC Endpoints for all external services.
    • B. Deploy multiple NAT Gateways, each in a different Availability Zone (AZ), and configure route tables accordingly.
    • C. Increase the Elastic IP address count on the existing NAT Gateway.
    • D. Change the instance type of the NAT Gateway to a larger size.
    Show answer

    B. Deploy multiple NAT Gateways, each in a different Availability Zone (AZ), and configure route tables accordingly.

    NAT Gateways are designed to scale automatically up to 45 Gbps, but they are zonal resources. High CPU and dropped packets indicate that the single NAT Gateway might be a bottleneck. Deploying multiple NAT Gateways across different AZs and configuring route tables to distribute traffic across them improves both performance and resilience by distributing the load and providing redundancy.

  23. 23. A security architect is designing a multi-account AWS environment for a new highly regulated application. They need to ensure that all data stored in Amazon EBS volumes attached to EC2 instances is encrypted by default. This encryption must use customer-managed keys (CMKs) from AWS Key Management Service (KMS), and the policy must be enforced at an organizational level to prevent any non-compliant EBS volumes from being created. How can this be achieved?

    Network Security, Compliance, and Governance

    • A. Use IAM policies on EC2 roles to enforce EBS encryption with a CMK when instances are launched.
    • B. Apply an AWS Organizations Service Control Policy (SCP) that denies the 'ec2:RunInstances' and 'ec2:CreateVolume' actions if the encryption parameters do not specify a CMK.
    • C. Implement an AWS Config rule to detect unencrypted EBS volumes and trigger a Lambda function for remediation.
    • D. Configure default encryption for EBS in each region for every account, using a specified CMK.
    Show answer

    B. Apply an AWS Organizations Service Control Policy (SCP) that denies the 'ec2:RunInstances' and 'ec2:CreateVolume' actions if the encryption parameters do not specify a CMK.

    To enforce preventive controls at an organizational level, an AWS Organizations Service Control Policy (SCP) is the most effective solution. An SCP can explicitly deny actions like 'ec2:RunInstances' or 'ec2:CreateVolume' if the request parameters do not include the necessary encryption configuration (e.g., KmsKeyId for a CMK or 'Encrypted': 'true' with a default CMK), ensuring that only compliant EBS volumes are created.

  24. 24. An organization uses AWS Direct Connect to establish a private connection between their on-premises data center and their AWS VPC. They need to ensure that the maximum possible network throughput is achieved over this connection for large data transfers, and they are currently using a single 1 Gbps Direct Connect connection. The application is highly sensitive to latency and packet loss. Which configuration modification would best optimize the Direct Connect connection for higher throughput and resilience?

    Network Implementation

    • A. Implement ECMP (Equal-Cost Multi-Path) routing over multiple Direct Connect connections.
    • B. Provision a dedicated 10 Gbps Direct Connect connection and remove the existing 1 Gbps connection.
    • C. Configure a VPN over the existing Direct Connect connection for increased security and performance.
    • D. Increase the MTU (Maximum Transmission Unit) to 9001 bytes on the Direct Connect virtual interface.
    Show answer

    A. Implement ECMP (Equal-Cost Multi-Path) routing over multiple Direct Connect connections.

    ECMP routing over multiple Direct Connect connections allows traffic to be distributed across all available paths, effectively increasing the aggregate throughput beyond a single connection's limit and providing redundancy. While increasing MTU (B) can reduce overhead, it doesn't increase raw bandwidth as significantly as ECMP. A VPN over Direct Connect (C) adds encryption overhead and decreases performance. Provisioning a single 10 Gbps connection (D) increases bandwidth but lacks the resilience of multiple connections with ECMP.

  25. 25. A compliance officer needs to verify that all Amazon S3 buckets in their AWS organization are configured with server-side encryption and that public access is blocked. They also need to ensure that this compliance posture is continuously maintained across all existing and newly created accounts. Which AWS service should be used to achieve this continuous monitoring and enforcement?

    Network Security, Compliance, and Governance

    • A. AWS Config with conformance packs for continuous monitoring and AWS Lambda for automated remediation.
    • B. AWS CloudTrail for auditing S3 bucket changes and Amazon EventBridge for alerts.
    • C. AWS Trusted Advisor for security checks and manual remediation.
    • D. AWS Organizations Service Control Policies (SCPs) to deny S3 bucket creation without encryption and allow public access.
    Show answer

    A. AWS Config with conformance packs for continuous monitoring and AWS Lambda for automated remediation.

    AWS Config provides continuous monitoring of resource configurations against desired rules. Conformance packs allow deploying a collection of Config rules to multiple accounts. Combining this with AWS Lambda for automated remediation can ensure that non-compliant S3 buckets are automatically encrypted and public access is blocked, meeting the continuous monitoring and enforcement requirement.

AWS Certified Advanced Networking – Specialty (ANS-C01) flashcards

Tap a card to flip it. 132 flashcards in the full deck.

  • AWS Global Accelerator

    Flip card

    An AWS networking service that improves the availability and performance of applications by directing user traffic to optimal endpoints over the AWS global network backbone.

    • Provides two static Anycast IP addresses
    • Routes traffic over AWS global network
    • Improves performance and availability for global users
    Study this card →
  • AWS Transit Gateway

    Flip card

    AWS Transit Gateway connects VPCs and on-premises networks through a central hub, simplifying network management and scaling connectivity.

    • Acts as a cloud router for centralizing network connections.
    • Supports inter-region peering and multi-account connectivity.
    • Eliminates the need for numerous point-to-point connections.
    Study this card →
  • VPN over Direct Connect

    Flip card

    VPN over Direct Connect combines the dedicated bandwidth and consistent network experience of Direct Connect with the IPsec encryption of a Site-to-Site VPN, adding an extra layer of security.

    • Uses an AWS Site-to-Site VPN connection
    • Traffic travels over a Direct Connect Private VIF
    • Provides IPsec encryption for sensitive data
    Study this card →
  • Client-Side Encryption with KMS

    Flip card

    Encrypts data before it is sent to AWS, using keys managed by AWS KMS, providing maximum customer control over encryption for data in transit and at rest.

    • Data is encrypted on the client-side before upload to AWS.
    • Encryption keys are managed within AWS KMS, offering strong security and auditability.
    • Provides the highest level of control and assurance for data encryption.
    Study this card →
  • AWS Site-to-Site VPN with Transit Gateway

    Flip card

    Provides secure, encrypted connectivity between on-premises networks and multiple AWS VPCs (potentially across regions) with dynamic routing and high availability.

    • Site-to-Site VPN: Encrypted tunnels over public internet.
    • Transit Gateway: Central hub for VPCs and on-premises connections.
    • Supports BGP for dynamic routing.
    Study this card →
  • ELB Listener Security Policies

    Flip card

    ELB listener security policies define the SSL/TLS protocols and ciphers that the load balancer uses when negotiating connections with clients, allowing for enforcement of specific TLS versions.

    • Configured on ELB listeners (e.g., HTTPS listener).
    • Controls accepted TLS protocols (e.g., TLS 1.2, 1.3).
    • Controls accepted cipher suites.
    Study this card →
  • AWS Site-to-Site VPN

    Flip card

    A service that creates an encrypted connection between your on-premises network and your Amazon VPCs, typically over the public internet.

    • Each VPN connection has two tunnels for high availability.
    • Supports BGP for dynamic routing and automatic failover.
    • Cost-effective solution for secure connectivity over the internet.
    Study this card →
  • Subnet Sizing (Growth)

    Flip card

    When sizing subnets, calculate current IP needs, add a buffer for expected growth, and account for AWS-reserved IP addresses (5 per subnet).

    • Total IPs = 2^(32-CIDR_mask)
    • Usable IPs = Total IPs - 5 (AWS reserved)
    • Plan for current needs + future growth
    Study this card →
  • DXGW Inter-Region VPC Traffic Cost

    Flip card

    Inter-region data transfer between VPCs associated with the *same* Direct Connect Gateway leverages the AWS global network at optimized, lower costs.

    • Applies to VPCs in different regions
    • VPCs must be associated with the same DXGW
    • Traffic stays within AWS global network
    Study this card →
  • AWS Network Firewall

    Flip card

    A managed firewall service that provides network intrusion prevention and detection, URL filtering, and stateful packet inspection for all traffic traversing a VPC.

    • Managed, highly available service.
    • Stateful inspection, IPS/IDS, URL filtering.
    • Deployed at the subnet level.
    Study this card →
  • Direct Connect Gateway

    Flip card

    A globally available resource that allows you to connect your AWS Direct Connect connection to one or more VPCs in any AWS Region (except China) using private virtual interfaces.

    • Connects DX to multiple VPCs across regions
    • Supports private virtual interfaces (VIFs)
    • Enables cross-account connectivity
    Study this card →
  • Direct Connect Gateway with Transit Gateway

    Flip card

    A combination that allows a single AWS Direct Connect connection to connect to multiple VPCs across different AWS Regions and accounts through Transit Gateways.

    • Enables global hybrid connectivity.
    • Simplifies routing and network architecture.
    • Supports multiple VPCs and AWS accounts.
    Study this card →
  • AWS Web Application Firewall (WAF)

    Flip card

    AWS WAF helps protect web applications from common web exploits and bots that may affect availability, compromise security, or consume excessive resources.

    • Protects against SQL injection, XSS, etc.
    • Integrates with CloudFront, ALB, API Gateway, AppSync.
    • Supports custom rules, including rate-based rules for DDoS mitigation.
    Study this card →
  • Network Manager Route Analyzer

    Flip card

    An AWS Network Manager feature that simulates and analyzes network paths within a global network, including Transit Gateway, to validate routing and identify misconfigurations.

    • Simulates network paths.
    • Verifies expected routing.
    • Crucial for complex TGW environments.
    Study this card →
  • TGW Appliance Mode & Firewall Manager

    Flip card

    A combination of AWS services for centralized network traffic inspection and automated security policy enforcement across an AWS Organization.

    • Transit Gateway Appliance Mode enables routing traffic through a security VPC.
    • Firewall Manager centralizes security policy deployment across accounts.
    • Ensures all internet-bound traffic is inspected consistently.
    Study this card →
  • VPC Subnet Sizing

    Flip card

    The process of dividing a VPC's CIDR block into smaller subnets, considering the number of IP addresses needed for resources and future growth.

    • AWS reserves 5 IP addresses in each subnet.
    • Number of usable IPs = 2^(32-CIDR) - 5.
    • Allocate slightly more IPs than immediately needed for flexibility.
    Study this card →
  • DynamoDB Fine-Grained Access (LeadingKeys)

    Flip card

    Leverages IAM policies with the `dynamodb:LeadingKeys` condition to grant fine-grained access to DynamoDB items based on the item's partition key.

    • Enables tenant isolation in multi-tenant applications.
    • Access is restricted at the database level, enforcing least privilege.
    • Reduces the need for complex authorization logic within the application.
    Study this card →
  • Transit Gateway Peering

    Flip card

    Transit Gateway peering connects two AWS Transit Gateways across different AWS Regions, enabling inter-region connectivity for all VPCs and on-premises networks attached to those Transit Gateways.

    • Extends your global network across regions.
    • Traffic between peered TGWs remains on the AWS global network.
    • Requires route table configuration on both TGWs.
    Study this card →
  • AWS Shield Advanced

    Flip card

    A paid, managed DDoS protection service that provides enhanced protections against larger and more sophisticated DDoS attacks, including 24/7 access to the AWS DDoS Response Team.

    • Always-on detection and automatic inline mitigations for L3/L4 DDoS attacks.
    • Advanced protection for web applications (L7) when integrated with WAF.
    • Protects CloudFront, Route 53, ELB, EC2, Global Accelerator.
    Study this card →
  • AWS Direct Connect

    Flip card

    A cloud service solution that makes it easy to establish a dedicated network connection from your premises to AWS.

    • Dedicated, private connection.
    • High throughput and consistent low latency.
    • Reduces network costs and increases bandwidth.
    Study this card →
  • NAT Gateway Scaling and Resilience

    Flip card

    AWS NAT Gateways scale automatically but are zonal resources. For high availability and performance across AZs, multiple NAT Gateways should be used.

    • Scales automatically up to 45 Gbps throughput.
    • A single NAT Gateway is tied to a specific Availability Zone.
    • Deploying one NAT Gateway per AZ and configuring route tables provides redundancy and load distribution.
    Study this card →
  • EBS Encryption Enforcement with SCPs

    Flip card

    AWS Organizations Service Control Policies (SCPs) can be used to prevent the creation of unencrypted EBS volumes or volumes not using a specified KMS CMK, enforcing encryption at rest as a preventive control across an entire organization.

    • SCPs are preventive, organization-wide guardrails.
    • Denies specific EC2 actions if encryption conditions are not met.
    • Ensures compliance with encryption-at-rest policies.
    Study this card →
  • Direct Connect ECMP

    Flip card

    ECMP (Equal-Cost Multi-Path) routing with AWS Direct Connect allows you to use multiple virtual interfaces or connections to an AWS Direct Connect gateway, distributing traffic across them to increase aggregate bandwidth and provide redundancy.

    • Requires multiple Direct Connect connections or VIFs to the same Direct Connect Gateway.
    • BGP advertises identical prefixes over multiple paths.
    • Increases throughput and improves fault tolerance.
    Study this card →
  • Continuous Compliance with AWS Config and Lambda

    Flip card

    AWS Config continuously monitors AWS resource configurations for compliance. When combined with AWS Lambda, it can automatically remediate non-compliant resources, ensuring a desired security posture is maintained.

    • AWS Config assesses resource configurations against rules.
    • Conformance Packs deploy rules across an organization.
    • AWS Lambda can be triggered by Config to automate remediation.
    Study this card →

Questions are original practice items written to match the published exam objectives. Step2Study is not affiliated with or endorsed by any certification body.