AWS Certified Advanced Networking - Specialty - (ANS-C01) Logo
Amazon Logo

AWS Certified Advanced Networking - Specialty - (ANS-C01) Exam Questions

200

Total Questions

SEP
2025

Last Updated

1st

1st Try Guaranteed

Expert Verified

Experts Verified

Question 11 Multiple Choice

A VPC peering connection exists between VPC A and VPC B. The network team has added the following additional configurations to the existing peering connection:

VPC A has an AWS Direct Connect connection to a corporate network

VPC A has a VPC gateway endpoint that connects it to Amazon S3

What will be the outcome? (Select Two)

Question 12 Single Choice

An e-commerce company has its technology infrastructure deployed in hybrid mode with applications running in a single AWS Region as well as its on-premises data center. The company has a 10 Gbps AWS Direct Connect connection from the data center to AWS that is 70% utilized. The company wants to deploy a new flagship application on AWS that will connect with existing applications running on-premises. The application SLA requires a minimum of 99.9% network uptime between the on-premises data center and the AWS Cloud. The company has an AWS Enterprise Support plan.

Which of the following options would you recommend as the MOST cost-effective solution to address this requirement?

Question 13 Single Choice

An analytics company uses Amazon QuickSight (Enterprise Edition) to easily create and publish interactive BI dashboards that can be accessed from any device. For a specific requirement, the company needs to create a private connection from Amazon QuickSight to an Amazon RDS DB instance that's in a private subnet to fetch data for analysis.

Which of the following represents an optimal solution for configuring a private connection between QuickSight and Amazon RDS DB instance?

Question 14 Single Choice

A developer has configured a private hosted zone using Route 53. The developer needs to configure health checks for record sets within the private hosted zone that are associated with EC2 instances.

How can the developer build a solution to address the given use-case?

Question 15 Single Choice

A company has a Direct Connect connection between its on-premises data center and its VPC on the AWS Cloud. An application running on an EC2 instance in the VPC needs to access customer data stored in the on-premises data center with consistent performance. To meet the compliance guidelines, the data should remain encrypted during this operation.

As an AWS Certified Networking Specialist, which of the following solutions would you recommend to address these requirements?

Question 16 Single Choice

An ecommerce company has a hybrid environment between its on-premises data center and the AWS Cloud. The company wants to use the Elastic File System (EFS) to store and share data between the on-premises applications that need to resolve DNS queries through the on-premises DNS servers. The company wants to use a custom domain name to connect to EFS. The company also wants to avoid using the Amazon EFS target IP address.

Which of the following solutions would you recommend to address these requirements?

Question 17 Multiple Choice

The networking team at a retail company is configuring a virtual interface for accessing your VPC on a newly provisioned 10-Gbps AWS Direct Connect connection.

Which of the following configuration values do you need to provide? (Select two)

Question 18 Multiple Choice

A company has three VPCs: X, Y, and Z. VPCs X and Z are both peered with VPC Y. The IP address ranges are as follows:

VPC X: 10.1.0.0/16

VPC Y: 192.168.0.0/16

VPC Z: 10.1.0.0/16

Instance x-1 in VPC X has the IP address 10.1.0.10. Instance z-1 in VPC Z has the IP address 10.1.0.10. Instances y-1 and y-2 in VPC Y have the IP addresses 192.168.2.10 and 192.168.2.20 respectively. The instances y-1 and y-2 are in the subnet 192.168.2.0/24.

The networking team at the company has mandated that y-1 must be able to communicate with x-1, and y-2 must be able to communicate with z-1. However, the team has noticed that both y-1 and y-2 are only able to communicate with x-1, instead of y-1 communicating with x-1 and y-2 communicating with z-1.

Which of the following combination of steps will address this issue? (Select two)

Question 19 Multiple Choice

A company has set up an AWS network consisting of three transit gateways (tgw-1, tgw-2, and tgw-3) each present in different AWS accounts and different AWS Regions. The development team owns transit gateways tgw-1 and tgw-3. Transit gateway tgw-1 has a peering attachment with transit gateway tgw-2 owned by another team. The entire network is within AWS and does not consist of on-premises resources. The company has decided to use Transit Gateway Network Manager for managing the network topology.

Which of the following would you identify as the key points of consideration while implementing this requirement? (Select three)

Question 20 Single Choice

A financial services application runs on a fleet of Amazon EC2 instances that are configured with an Auto Scaling Group (ASG). The instances are fronted by an Elastic Load Balancer (ELB). The security team has flagged an exploitable vulnerability in the encryption protocol and cipher that the application uses. The listener of the ELB is configured on an HTTPS protocol.

Which step will you take to secure the application from the newly detected vulnerability?

Page: 2 / 20