Home/Practice Test/AWS/Free ANS-C01 Practice Test | 550+ Real Exam Questions 2026

Free ANS-C01 Practice Test | 550+ Real Exam Questions 2026

Put your AWS networking knowledge to the test.
Use this ANS-C01 practice test to review routing, security, and connectivity.

Real Exam Style
Questions
Detailed
Explanations
All Domains
Covered
Timed
Practice
4.8919 learner reviews across Microsoft, AWS, and CompTIA tracksVerified purchases
Jump Straight to the ANS-C01 Questions (No Sign-Up or Credit Card required)
Why choose us
1
Expert Explanations + Sources Master every concept with clarity.
2
2026-Fresh Questions Always current, never outdated.
3
Real Exam Simulation Practice like you'll test.
4
90-Day Free Updates Stay ahead of changes.
5
Start in 60 Seconds No waiting, instant access.

ANS-C01 exam at a glance

AWS Certified Advanced Networking – Specialty · Specialty level

Status: This exam is being retired. The last day to take it is 25 August 2026. Certifications earned before retirement will remain active for the standard three-year period, but AWS will not issue new AWS Certified Advanced Networking – Specialty certifications after retirement.

Exam codeANS-C01
CertificationAWS Certified Advanced Networking – Specialty
LevelSpecialty
Number of questions65 questions: 50 scored and 15 unscored
Duration170 minutes
Passing score700 on a scale of 100–1,000
Question formatsMultiple response and matching
DeliveryPearson VUE testing center or online proctored exam
Exam cost300 USD; foreign exchange rates may apply
LanguagesEnglish, Japanese, Korean, and Simplified Chinese
Certification validity3 years from the date earned
Retake policyAfter a failed attempt, candidates must wait 14 calendar days. There is no attempt limit, and the full registration fee applies to each attempt. After passing, the same exam cannot be retaken for two years.

The exam is intended for individuals who perform an AWS networking specialist role. AWS describes the target candidate as having 5 or more years of networking experience, including 2 or more years of cloud and hybrid networking experience.

Skills measured and their weighting

Skill areaWeight
Network Design30%
Network Implementation26%
Network Management and Operation20%
Network Security, Compliance, and Governance24%

Source: aws.amazon.com — official ANS-C01 exam page. Figures were checked against AWS official documentation. Confirm current details there before booking.

Sit the whole exam before you sit the whole exam

The full bank covers every domain, with timed mode and per-domain scoring.

Premium
Timed mode Per-domain score tracking Unlimited free updates PDF + Practice Test
Get the full bank 30-day money back

ANS-C01 Practice Questions By Domains

4 domains covered

4. Network Security, Compliance, and Governance

17 free questions available

Start Practice
Premium 150 of 579 free

Practice the full exam, not a sample

Unlock the full bank and practise every domain end to end.

Unlock all 579 questions

ANS-C01 Practice Test

Preparing for the AWS Certified Advanced Networking – Specialty exam requires more than remembering networking terms. An effective ANS-C01 practice test should help you design, implement, monitor, troubleshoot, and secure AWS and hybrid networks in realistic situations. Before beginning, View all certification exams to compare your available preparation options and make sure ANS-C01 is still the right target for your schedule.

There is an important deadline for every current candidate: AWS is retiring the ANS-C01 exam on August 25, 2026. AWS states that this is the final day to take the exam. Certifications earned before retirement will remain active for the standard three-year period, but AWS Certified Advanced Networking – Specialty credentials will not be issued through this exam after the deadline. Because the date is close, candidates should confirm appointment availability before purchasing study materials or beginning an intensive plan. Read the official AWS retirement notice and exam overview.

This guide provides clear, current information for experienced networking professionals who plan to test before retirement. It explains the exam format, four domains, practice-test method, scoring, registration, online delivery, a focused study schedule, and exam-day preparation. It also explains what the retirement means so students can make an informed decision instead of following an outdated exam page.

ANS-C01 Retirement: What Candidates Need to Know

The last day to sit for ANS-C01 is August 25, 2026. Booking an appointment and taking the exam are not the same thing, so schedule the actual exam on or before that date. Available time slots can fill, especially near a retirement deadline.

Keep these points in mind:

  • ANS-C01 remains an active exam only through August 25, 2026.
  • A certification earned before retirement remains active for three years.
  • AWS says it will not issue new AWS Certified Advanced Networking – Specialty certifications after the exam retires.
  • AWS’s normal retake rule requires a 14-calendar-day wait after a failed attempt.
  • A late first attempt might leave no time for a retake before retirement.
  • Candidates should confirm availability and all deadlines in their AWS Certification Account before paying.

If you already have advanced AWS networking experience and have completed most of your preparation, a focused final review may be realistic. If you are new to BGP, Direct Connect, Transit Gateway, hybrid DNS, and multi-account routing, rushing only to meet the deadline is unlikely to build the depth expected by the exam. You can still use the topics as a networking learning path, but the certification deadline should not force an unsuitable attempt.

What Is the AWS ANS-C01 Exam?

ANS-C01 is the exam code for AWS Certified Advanced Networking – Specialty. It is intended for professionals who perform an AWS networking specialist role. The exam validates the ability to design, implement, manage, operate, and secure AWS and hybrid network architectures at scale.

The test covers more than basic Amazon VPC configuration. Questions can combine traditional networking knowledge with AWS services and business requirements. A scenario may involve redundant hybrid connectivity, route selection, domain name resolution, overlapping IP ranges, multi-account governance, inspection appliances, logging, or performance troubleshooting.

AWS says the target candidate should have five or more years of networking experience, including two or more years of cloud and hybrid networking experience. AWS also recommends knowledge of AWS networking behavior, AWS security best practices, and the relationship between networking, compute, and storage services. Review the official ANS-C01 exam guide.

Who Should Take ANS-C01 Before It Retires?

ANS-C01 is most suitable for candidates who already work with advanced networks and need focused exam practice rather than months of foundational study. Appropriate roles may include:

  • Senior network engineers working with AWS infrastructure
  • Cloud network architects designing multi-account or multi-Region connectivity
  • Hybrid-cloud engineers connecting data centers to AWS
  • Security engineers responsible for network segmentation and traffic inspection
  • Solutions architects who frequently make AWS routing, DNS, and connectivity decisions
  • Consultants who design or troubleshoot enterprise AWS networks

No AWS certification is a formal prerequisite. AWS explains that its certifications can be earned without completing another certification first. However, the ANS-C01 page says candidates may benefit from earning an AWS Associate or Professional certification before attempting a Specialty exam.

You are more likely to be ready if you can already explain:

  • How route tables decide where traffic goes
  • How BGP attributes influence hybrid routing
  • When to use VPC peering, Transit Gateway, or AWS PrivateLink
  • How Direct Connect differs from Site-to-Site VPN
  • How Route 53 Resolver supports hybrid DNS
  • How security groups, network ACLs, AWS Network Firewall, AWS WAF, and AWS Shield solve different problems
  • How to use VPC Flow Logs, CloudWatch, Reachability Analyzer, and Traffic Mirroring during troubleshooting

If these are unfamiliar, first build the networking foundation. Practice questions are useful for checking understanding, but they cannot replace the hands-on experience AWS expects for a Specialty-level role.

What Should an ANS-C01 Practice Test Help You Do?

A useful practice test should measure decision-making, not only service recall. It should place services inside a business or technical scenario and require you to select the design that meets all stated requirements.

Practice questions can help you develop five key abilities:

  1. Find the real requirement. Long scenarios may include details about availability, bandwidth, latency, encryption, operations, and cost. Identify which conditions are mandatory.
  2. Select the correct connectivity pattern. Compare peering, Transit Gateway, PrivateLink, VPN, and Direct Connect based on scale and purpose.
  3. Follow the traffic path. Trace traffic through subnets, route tables, gateways, security controls, DNS, and load balancers.
  4. Diagnose network failures. Determine whether the problem comes from routing, name resolution, filtering, packet size, service quotas, or asymmetric paths.
  5. Compare trade-offs. Choose the solution that meets the requirements without adding unnecessary complexity or cost.

Candidates preparing for more than one AWS credential can Browse all AWS exams and keep separate practice results for each active blueprint.

Do not judge preparation only by the number of questions completed. Review every incorrect response and every correct response that involved guessing. The explanation should help you state why the correct design works, why the other options fail, and which requirement controls the decision.

ANS-C01 Exam Domains and Weightings

Network Design is the largest domain, but the other three together make up 70% of the scored content. Build a balanced plan instead of studying only one strong area. AWS uses a compensatory scoring model, which means candidates pass based on overall performance and do not need a separate passing result in each domain.

Domain 1: Network Design — 30%

Domain 1 measures your ability to choose a network architecture before it is built. It covers edge networking, DNS, load balancing, visibility, hybrid connectivity, and routing across accounts, VPCs, and Regions.

Important topics include:

  • Amazon CloudFront and AWS Global Accelerator for global traffic and performance
  • Public and private Route 53 hosted zones, routing policies, health checks, DNSSEC, and Resolver endpoints
  • Application, Network, and Gateway Load Balancer use cases
  • CloudWatch, flow logs, access logs, Traffic Mirroring, and Reachability Analyzer
  • Direct Connect, Site-to-Site VPN, BGP, IPsec, redundancy, and SD-WAN connectivity
  • VPC peering, Transit Gateway, PrivateLink, VPC sharing, and overlapping CIDR ranges

Scenario clue: when a question mentions many VPCs or many AWS accounts, compare the scalability and management of Transit Gateway with one-to-one VPC peering. When it asks for private access to a service without full network connectivity, consider PrivateLink.

Domain 2: Network Implementation — 26%

Domain 2 moves from architecture choice to configuration. It tests whether you can implement hybrid connectivity, multi-account routing, complex DNS, and network automation.

Study these areas:

  • Physical and logical requirements for Direct Connect
  • Static and dynamic routing, VPN configuration, and BGP behavior
  • Hub-and-spoke designs using Transit Gateway
  • Sharing network resources with AWS Organizations and AWS Resource Access Manager
  • PrivateLink, VPC peering, security boundaries, and third-party network appliances
  • Route 53 delegation, conditional forwarding, Resolver endpoints, DNSSEC, and multi-account DNS
  • AWS CloudFormation, AWS CDK, AWS CLI, SDKs, APIs, and event-driven network automation

Practice questions may describe a correct design but include one missing implementation detail. Read carefully for route propagation, virtual interface type, association, propagation, attachment, DNS forwarding direction, and permissions in another account.

Domain 3: Network Management and Operation — 20%

Domain 3 focuses on maintaining, monitoring, troubleshooting, and improving a running network. You need to understand both network behavior and the AWS tools that reveal it.

Review:

  • BGP over Direct Connect and VPN
  • Virtual interfaces, Direct Connect gateways, Transit Gateway, and route tables
  • Service limits, route limits, bandwidth, and IP address availability
  • CloudWatch metrics and logs, VPC Flow Logs, Traffic Mirroring, and Reachability Analyzer
  • Packet loss, MTU and jumbo-frame problems, routing errors, and unexpected filtering
  • Route 53 availability features, load balancing, and traffic distribution
  • Choosing network interfaces and connectivity options for performance and cost

A good troubleshooting process starts with the expected path, checks name resolution, validates routing in both directions, evaluates stateful and stateless filtering, and then reviews logs and metrics. Avoid choosing a monitoring service before identifying what evidence is required.

Domain 4: Network Security, Compliance, and Governance — 24%

This domain measures whether you can secure traffic, validate controls, collect useful evidence, and protect data in transit.

Key areas include:

  • AWS WAF, AWS Shield, AWS Network Firewall, proxy patterns, and Gateway Load Balancer
  • Security groups, network ACLs, and VPC endpoint policies
  • Inbound, outbound, and inter-VPC traffic inspection
  • Network threat models and compliance-focused architecture
  • VPC Flow Logs, CloudTrail, load-balancer logs, CloudFront logs, and Traffic Mirroring
  • AWS Firewall Manager, CloudWatch alarms, and centralized audit strategies
  • IPsec, TLS, VPN over Direct Connect, DNSSEC, and certificate management with ACM or AWS Private CA

Remember that these controls work at different layers and solve different problems. For example, a security group is not a replacement for AWS WAF, and WAF is not a replacement for network routing or a stateful network firewall.

AWS Services to Prioritize for ANS-C01

The official in-scope list is broader than networking alone, but students can organize preparation around several service groups:

Study groupImportant services and features
VPC networkingAmazon VPC, subnets, route tables, NAT, endpoints, peering, flow logs
Enterprise connectivityAWS Direct Connect, Site-to-Site VPN, Client VPN, Transit Gateway
Private servicesAWS PrivateLink and VPC endpoints
DNS and trafficRoute 53, Route 53 Resolver, CloudFront, Global Accelerator
Load balancingApplication, Network, and Gateway Load Balancers
SecurityNetwork Firewall, WAF, Shield, Firewall Manager, IAM, AWS RAM
MonitoringCloudWatch, CloudTrail, Reachability Analyzer, Traffic Mirroring, Network Manager
Automation and governanceCloudFormation, CLI, AWS Config, Control Tower, Organizations

Do not memorize this as an isolated list. For every service, learn its purpose, supported traffic flow, routing effect, security boundary, logging options, scalability, and common alternatives. AWS notes that the official in-scope service list is non-exhaustive and can change.

Can the ANS-C01 Exam Be Taken Online?

Yes. Before the retirement deadline, ANS-C01 can be taken at a Pearson VUE test center or through Pearson VUE online proctoring, subject to appointment availability.

For an online exam, prepare:

  • A compatible computer with a working webcam and microphone
  • A stable internet connection
  • A private, quiet, well-lit room
  • A clear desk without notes, phones, extra screens, or prohibited items
  • Identification that meets the requirements in your confirmation email

Run the Pearson VUE system test on the same device and network you plan to use. A work-managed computer may block required software, so verify compatibility early. During the session, a proctor monitors you through the webcam and screen-sharing application. Communication with the proctor is required.

AWS says online proctoring is available for its certification exams, but available proctor languages and times can differ. Review the official AWS before-testing information before scheduling.

How to Register for ANS-C01 Before Retirement

  1. Sign in to your AWS Certification Account.
  2. Select the option to schedule a new exam.
  3. Find AWS Certified Advanced Networking – Specialty (ANS-C01).
  4. Continue to Pearson VUE.
  5. Choose a test center or online proctored delivery.
  6. Select an available appointment no later than August 25, 2026.
  7. Check your name, identification requirements, time zone, fee, and appointment details.
  8. Complete payment and save the confirmation email.

AWS normally allows candidates to reschedule up to 24 hours before the appointment, with a maximum of two reschedules per appointment. However, the retirement date remains the final testing deadline. Do not assume that a late canceled or moved appointment will have another available slot.

Focused ANS-C01 Study Plan Before August 25, 2026

Because the exam is close to retirement, a long general study plan is no longer suitable for most current candidates. The following 10-day review is intended for experienced professionals who already know the material.

Day 1: Take a diagnostic test

Complete a mixed, untimed set. Record weaknesses by domain and by skill: design, implementation, troubleshooting, or security. Do not use the result as an official score prediction.

Days 2–3: Review Network Design

Focus on hybrid connectivity, BGP, Direct Connect, VPN, multi-account routing, Transit Gateway, VPC peering, PrivateLink, DNS, and load balancing. Draw traffic paths rather than only reading service summaries.

Days 4–5: Review Network Implementation

Practice configuration logic for Direct Connect, VPN, Transit Gateway route tables, shared resources, Resolver endpoints, DNS delegation, and infrastructure as code.

Day 6: Review Management and Operations

Work through troubleshooting scenarios. Use VPC Flow Logs, CloudWatch, Reachability Analyzer, Traffic Mirroring, route tables, and DNS evidence to locate faults.

Day 7: Review Security and Governance

Compare WAF, Shield, Network Firewall, Gateway Load Balancer, security groups, network ACLs, Firewall Manager, encryption, DNSSEC, and certificate management.

Day 8: Complete a timed mixed test

Use Exam Practice Tests in closed-book conditions. Practice reading long scenarios, marking uncertain items, and maintaining a steady pace.

Day 9: Repair weak areas

Review every mistake from the timed test. Read the relevant official documentation and write one clear rule for each missed concept.

Day 10: Light final review

Review diagrams, comparison notes, and the official domain list. Confirm the appointment, system check, ID, and time zone. Avoid learning large new topics at the last minute.

How to Answer ANS-C01 Scenario Questions

Use a repeatable method:

  1. Read the final request. Determine whether the question asks for a design, implementation, cause, fix, or security control.
  2. Mark the non-negotiable requirements. Look for scale, encryption, bandwidth, availability, cost, central management, and operational effort.
  3. Draw the traffic path mentally. Identify the source, destination, DNS lookup, routes, gateways, inspection point, and return route.
  4. Check both directions. Hybrid and multi-VPC failures often come from missing or asymmetric return paths.
  5. Remove partial solutions. A choice may solve routing but fail security, or solve connectivity but ignore DNS.
  6. Prefer the complete fit. Choose the option that satisfies every stated requirement with reasonable management effort.

Build an error log with four fields: topic, why the answer was wrong, correct design principle, and next review date. Common mistake categories include confusing routing with security, overlooking route propagation, selecting the wrong Direct Connect virtual interface, forgetting DNS forwarding direction, and using a many-to-many network pattern where a service-specific private connection is required.

ANS-C01 Exam-Day Checklist

For online testing

  • Complete the system test in advance.
  • Use the same computer and network tested earlier.
  • Prepare the required identification.
  • Clear the desk and remove extra devices.
  • Make sure nobody enters the room.
  • Join early for check-in and room verification.

For test-center delivery

  • Confirm the address, date, and local appointment time.
  • Review all ID requirements in the confirmation message.
  • Arrive early enough to complete check-in.
  • Store personal items as instructed.

During the exam

  • Maintain a steady pace across 170 minutes.
  • Flag difficult questions instead of spending too long on one scenario.
  • Answer every item because there is no penalty for guessing.
  • Recheck multiple-response and matching questions carefully.
  • Use remaining time to review questions with uncertain routing or DNS details.

AWS says final results are normally posted to the AWS Certification Account within five business days, unless a result is being reviewed for security or technical reasons.

ANS-C01 Frequently Asked Questions

When does ANS-C01 retire?

AWS says August 25, 2026 is the final day to take the AWS Certified Advanced Networking – Specialty exam.

Will an ANS-C01 certification remain valid after retirement?

Yes. AWS states that certifications earned before the exam retires remain active for the standard three-year period.

How many questions are on ANS-C01?

There are 65 questions in total. The current exam guide says 50 affect the score and 15 are unscored.

How long is the ANS-C01 exam?

The exam duration is 170 minutes.

How much does ANS-C01 cost?

AWS lists the exam fee as USD $300. Taxes, exchange rates, and local pricing can affect the amount shown at checkout.

What is the ANS-C01 passing score?

The current exam-specific guide lists 700 on a scale from 100 to 1,000, while AWS’s general scoring policy lists 750 for Specialty exams. Confirm the live ANS-C01 standard with AWS before testing. Neither scaled score should be treated as a raw percentage.

Can I take ANS-C01 online?

Yes, subject to availability before retirement. AWS offers Pearson VUE online proctoring and Pearson VUE test-center delivery for ANS-C01.

Is another AWS certification required first?

No certification is a formal prerequisite. However, AWS says candidates may benefit from first earning an Associate or Professional certification, and the target experience is five or more years in networking with at least two years in cloud and hybrid networking.

What happens if I fail ANS-C01?

AWS’s normal policy requires a 14-calendar-day wait before a retake and payment of the full fee for each attempt. Because ANS-C01 retires on August 25, 2026, a late failed attempt may leave no opportunity to test again.

Are practice tests enough to pass ANS-C01?

Practice tests help reveal weak areas, improve timing, and develop scenario-solving skills. They work best when combined with the official exam guide, AWS documentation, network diagrams, hands-on configuration, and real troubleshooting experience.

Should a beginner rush to take ANS-C01 before retirement?

Usually not. The exam targets experienced networking specialists. A short deadline is suitable for final review, not for replacing years of networking and cloud experience.

Top 15 Most Challenging ANS-C01 Questions

Question 1
Domain: Network Design
A firm is creating a new AWS workload that relies on an Application Load Balancer (ALB). A fresh ALB target group has slow start enabled. EC2 instances are being registered as targets in this group. During testing, the team noticed the targets did not enter slow start. What explains why slow start wasn't applied to the targets?
  • A. The ALB uses round-robin routing for distributing traffic.
  • B. The target group has no healthy targets configured for slow start mode.
  • C. The target group must include EC2 instances of the same instance type.
  • D. The ALB uses the 5-tuple criteria to classify traffic.
Question 2
Domain: Network Management and Operation
A firm operates multiple AWS accounts and VPCs within a single region and must log all network traffic for EC2 and RDS. They need 12 months of retention, with limited access after 90 days, and must view metadata including vpc-id, subnet-id, and tcp-flags. Which approach is cheapest?
  • A. Use VPC flow logs with default fields and store in CloudWatch Logs.
  • B. Enable Traffic Mirroring to a Network Load Balancer and monitor with instances.
  • C. Use VPC flow logs with extra fields and store in S3.
  • D. Use VPC flow logs with extra fields and store in CloudWatch Logs.
Question 3
Domain: Network Security, Compliance, and Governance
You launch an EC2 web server in a subnet with an Internet gateway, and the main route table sends 0.0.0.0/0 to that gateway. The EC2 security group allows inbound TCP port 80 but has no outbound rule. The subnet’s Network ACL allows inbound TCP port 80 but no outbound rule. When you browse the site, there’s no response. What additional step will fix the issue?
  • A. Add an outbound rule in the security group for TCP, port 80.
  • B. Add an outbound rule in the security group for TCP, 1024-65535.
  • C. Add an outbound rule in the Network ACL for TCP, port 80.
  • D. Add an outbound rule in the Network ACL for TCP, 1024-65535
These are the hard ones. There are 564 more. Every question explains why the wrong answers are wrong, with a link to official docs.
Get all 579 questions
Question 4
Domain: Network Implementation
While using a VPC endpoint for S3, initial security group rules restricted access to the region’s S3 API endpoints. The app worked but now experiences timeouts to S3. There is no Internet gateway in the VPC. Which fix requires the least effort?
  • A. Create a Lambda to update SGs based on AmazonIPSpaceChanged notifications.
  • B. Update the VPC route table to send S3 prefix-list traffic to the VPC endpoint.
  • C. Update the app server outbound SG to use the region’s S3 prefix-list.
  • D. Create an additional S3 VPC endpoint in the same route table to handle more connections.
Question 5
Domain: Network Security, Compliance, and Governance
A network engineer must add extra safeguards to protect data encrypted at the edge by an ALB using a unique random session key. What should be done?
  • A. Change the ALB policy to one that supports TLS 1.2 only.
  • B. Use AWS KMS to encrypt session keys.
  • C. Attach an AWS WAF ACL to the ALB and require forward secrecy (FS).
  • D. Change the ALB policy to one that supports forward secrecy (FS).
Question 6
Domain: Network Design
A US-based company operates an application in us-east-1 on proprietary TCP and UDP protocols, with end users running a real-time front-end app on their desktops who know the DNS hostname. They plan global expansion with minimal latency for users worldwide. What AWS setup best fits?
  • A. List service host IPs as A records with latency-based routing and a health check in Route 53.
  • B. Place an ELB in front of the hosts and point an ALIAS record with latency-based routing to the ELB in Route 53.
  • C. Put CloudFront in front of the hosts and point an ALIAS to CloudFront in Route 53.
  • D. Put API Gateway in front of the service and point an ALIAS to API Gateway in Route 53.
Question 7
Domain: Network Management and Operation
A firm wants to analyze TCP traffic to the Internet. The data originates from EC2 instances in the VPC and passes through a NAT gateway. They need source/destination IPs, ports, and the first 8 bytes of TCP payloads, all stored for analysis. Which approach satisfies this?
  • A. Set EC2 instances as VPC traffic mirror sources and forward data from the mirror target to CloudWatch Logs for analysis with CloudWatch Logs Insights.
  • B. Set the NAT gateway as a traffic mirror source and forward data to an OpenSearch Service cluster for analysis with OpenSearch Dashboards.
  • C. Enable VPC Flow Logs on EC2 instances with default format to CloudWatch Logs and analyze with CloudWatch Logs Insights.
  • D. Enable VPC Flow Logs on EC2 instances with a custom format to S3 and analyze with Amazon Athena.
Question 8
Domain: Network Implementation
For Nitro-based EC2 instances, traffic mirroring is set up to a second ASG with an NLB in front. Yet no mirrored traffic reaches the instances behind the NLB. How should you configure mirroring to use the NLB endpoint?
  • A. Choose the NLB as the traffic mirror source and use a UDP listener.
  • B. Choose the NLB as the traffic mirror target with a TCP and a UDP listener.
  • C. Choose the NLB as the traffic mirror target with a TCP listener.
  • D. Choose the NLB as the traffic mirror target with a UDP listener.
Question 9
Domain: Network Design
An organization is swapping a tape backup system for a storage gateway and currently lacks any connection to AWS. They need to begin testing with minimal cost. Which connection option should be used to start quickly and cheaply?
  • A. Use an internet connection.
  • B. Establish an AWS VPN connection.
  • C. Provision a private virtual interface for AWS Direct Connect.
  • D. Provision a Direct Connect public virtual interface.
Question 10
Domain: Network Implementation
A company has a newly established AWS Direct Connect link between its on‑premises data center and AWS. A private virtual interface (VIF) was created on the link, but its status is DOWN despite the physical link showing UP and RUNNING in the console. The ARP entry for the private VIF’s VLAN interface is visible on the customer router. What could cause the private VIF to be DOWN?
  • A. ICMP is blocked on the customer Direct Connect router.
  • B. TCP port 179 is blocked on the customer Direct Connect router.
  • C. The IEEE 802.1Q VLAN ID is misconfigured on the customer Direct Connect router.
  • D. The customer has configured IEEE 802.1ad instead of 802.1Q on the router.
Question 11
Domain: Network Design
A firm intends to migrate mission-critical workloads from an on-premises data center to Amazon EC2. The plan includes a dedicated 10 Gbps AWS Direct Connect path from the data center to a VPC that connects to a transit gateway. The migration must occur over encrypted links between the data center and AWS. Which solution satisfies these requirements while delivering the highest possible throughput?
  • A. Set up a public virtual interface (VIF) on the Direct Connect link and add an AWS Site-to-Site VPN to the transit gateway as a VPN attachment.
  • B. Set up a transit VIF on the Direct Connect link and attach an IPsec VPN to an EC2 instance running third-party VPN software.
  • C. Enable MACsec on the Direct Connect link and attach a transit VIF to a Direct Connect gateway linked to the transit gateway.
  • D. Set up a public virtual interface (VIF) on the Direct Connect link and attach two AWS Site-to-Site VPNs to the transit gateway with ECMP enabled.
Question 12
Domain: Network Implementation
A firm is deploying a non-web application behind an AWS load balancer. All targets are on‑prem servers reachable via AWS Direct Connect. The goal is to pass client source IP addresses through to the final server. How can this be achieved?
  • A. Choose a Network Load Balancer to automatically preserve the source IP.
  • B. Choose a Network Load Balancer and enable the X-Forwarded-For header.
  • C. Choose a Network Load Balancer and enable the ProxyProtocol v2 feature.
  • D. Choose an Application Load Balancer to automatically preserve the source IP in the X-Forwarded-For header.
Question 13
Domain: Network Management and Operation
A company uses Route 53 to host a public zone for example.com. A network engineer recently lowered TTLs to 60 seconds and wants to know if DNS queries to example.com have increased beyond expected levels. Which approach will provide the required query count?
  • A. Create a new CloudTrail trail for Route 53 data events, send logs to CloudWatch Logs, and set up a CloudWatch metric filter to count queries and visualize them.
  • B. Use CloudWatch in the Route 53 namespace and check the DNSQueries metric for the public zone.
  • C. Use CloudWatch in the Route 53 Resolver namespace and check the InboundQueryVolume metric for a specific endpoint.
  • D. Enable logging to CloudWatch for the public hosted zone and set up a CloudWatch metric filter to count queries and graph them.
Question 14
Domain: Network Security, Compliance, and Governance
Your security team has host-based firewall rules on all EC2 instances to block outbound traffic. New rules must be requested for each exception, and until approved you cannot access the instance metadata service. Which firewall rule should you request to allow instance metadata access?
  • A. Inbound; Protocol TCP; Destination [Instance’s EIP]; Destination 169.254.169.254
  • B. Inbound; Protocol TCP; Destination 169.254.169.254; Destination port 80
  • C. Outbound; Protocol TCP; Destination 169.254.169.254; Destination port 80
  • D. Outbound; Protocol TCP; Destination 169.254.169.254; Destination port 443
Question 15
Domain: Network Implementation
A firm connects its VPC resources to a SaaS solution hosted in AWS via PrivateLink, with the SaaS provider’s NLB in front. After adding a new Availability Zone and subnets, deploying an interface VPC endpoint for the SaaS in the new zone fails. What is the root cause?
  • A. The new subnets’ CIDR blocks conflict with the SaaS provider’s CIDR blocks.
  • B. Dns hostname and DNS support flags for the new subnets were not enabled.
  • C. The SaaS provider does not support the new Availability Zone and cross‑zone load balancing isn’t configured for the NLB.
  • D. The new subnets lack a route to the VPC Internet Gateway.
Disclaimer: Edurely is an independent educational platform. We are not affiliated with, authorized by, endorsed by, or in any way officially connected to AWS . Full disclaimer
Edurely
Curated By Edurely Team

The Edurely Team comprises certified professionals and subject matter experts dedicated to delivering accurate, up-to-date exam preparation materials. We rigorously review every resource to ensure it aligns with the latest industry standards and certification objectives to help you succeed.