Skip to content

AWS Certified Advanced Networking - Specialty Practice Questions

Prepare for ANS-C00 with more than an answer.

348 questions in the full set20 sample questionsUpdated Jan 24, 2026

Unlock the full exam and previous versions

  • v1Version 1 239 questions Locked
  • ANS-C00Legacy AWS Certified Advanced Networking - Specialty 348 questions Current
  1. 1

    When an AWS Config rule is triggered a JSON object known as an AWS Config Event is created. This object contains another JSON string in its parameter, which describes the event that triggered the rule.

    Show answer details

    Correct answer: D

    D--Explanation:
    The JSON object for an AWS Config event contains an invoking Event attribute, which describes the event that triggers the evaluation for a rule. If the event is published in response to a resource configuration change, the value for this attribute is a string that contains a JSON configuration Item or a configuration Item Summary (for oversized configuration items). The configuration item represents the state of the resource at the moment that AWS Config detected the change. If the event is published for a periodic evaluation, the value is a string that contains a JSON object. The object includes information about the evaluation that was triggered. For each type of event, a function must parse the string with a JSON parser to be able to evaluate its contents.--
    Reference: http://docs.aws.amazon.com/config/latest/developerguide/evaluate-config develop-rules exa mple-events.html

  2. 2

    You can turn on the AWS Config service from the AWS CLI by running the subscribe command and passing as parameters a valid 1AM role, SNS topic, a n d .

    Show answer details

    Correct answer: A

    A--Explanation:
    You can use the AWS CLI to turn on AWS Config. All it takes is the subscribe command and a few additional parameters. The parameters are -s3-bucket, which specifies the S3 bucket to which AWS Config data will be saved, -sns-topic, which specifies to which SNS topic messages from AWS Config will be sent, and -iam-role, which is an 1AM role containing appropriate permissions for AWS Config to access the resources it monitors.--
    Reference: http://docs.aws.amazon.com/config/latest/developerguide/gs-cli-subscribe.html

  3. 3

    Your company’s policy requires that all VPCs peer with a “common services: VPC. This VPC contains a fleet of layer 7 proxies and an Internet gateway. No other VPC is allowed to provision an Internet gateway. You configure a new VPC and peer with the common service VPC as required by policy. You launch an Amazon EC2. Windows instance configured to forward all traffic to the layer 7 proxies in the common services VPC. The application on this server should successfully interact with Amazon S3 using its properly configured AWS Identity and Access Management (1AM) role.

    However, Amazon S3 is returning 403 errors to the application.

    Which step should you take to enable access to Amazon S3?

    Show answer details

    Correct answer: B

    B

  4. 4

    You are responsible for several EC2 instances deployed from Amazon AMIs that are required to upload information to an S3 bucket. This information must not traverse the public internet. You must also be able to update the instances.

    Which option is your best solution?

    Show answer details

    Correct answer: D

    D--Explanation:
    A NAT is not required as an S3 endpoint will allow an instance to update. C and D are not possible.

  5. 5

    You have to set up an AWS Direct Connect connection to connect your on-premises to an AWS VPC. Due to budget requirements, you can only provision a single Direct Connect port. You have two border gateway routers at your on-premises data center that can peer with the Direct Connect routers for redundancy.

    Which two design methodologies, in combination, will achieve this connectivity? (Choose two.)

    Show answer details

    Correct answer: C, D

    C,D

    C,D

  6. 6

    A Network Engineer needs to be automatically notified when a certain TCP port is accessed on a fleet of Amazon EC2 instances running in an Amazon VPC.

    Which of the following is the MOST reliable solution?

    Show answer details

    Correct answer: D

    D

  7. 7

    What service is used to store the log files generated by CloudTrail?

    Show answer details

    Correct answer: B

    B--Explanation:
    The AWS CloudTrail uses Amazon's Simple Storage Service (S3) to store log files. It also supports the use of S3 life cycle configuration rules to reduce storage costs.--
    Reference: https://aws.amazon.com/cloudtrail/

  8. 8

    You are architecting your e-business application for PCI compliance. To meet the compliance requirements, you need to monitor web application logs to identify any malicious activity. You also need to monitor for remote attempts to change the network interface of web instances.

    Which two AWS services will be helpful to achieve this goal?

    Show answer details

    Correct answer: B

    Explanation:
    Web application logs are internal to the operating system, so the only way to monitor them with an AWS service is to export them using CloudWatch Logs. AWS CloudTrail monitors the API activity and can be used to watch for particular API calls. The correct answer is the only one that references both these services.

  9. 9

    You can use the _____ command of the AWS Config service CLI to see the compliance state of each resource that AWS Config evaluates for a specific rule.

    Show answer details

    Correct answer: A

    A--Explanation:
    You can use the get-compliance-details-by-config-rule command of the AWS Config CLI to see the compliance state of each resource that AWS Config evaluates for a specific rule.--
    Reference: http://docs.aws.amazon.com/config/latest/developerguide/evaluate-config view-compliance.html

  10. 10

    A user has enabled detailed CloudWatch monitoring with the AWS Simple Notification Service.

    Which of the below mentioned statements helps the user understand detailed monitoring better?

    Show answer details

    Correct answer: C

    C--Explanation:
    CloudWatch is used to monitor AWS as well as the custom services. It provides either basic or detailed monitoring for the supported AWS products. In basic monitoring, a service sends data points to CloudWatch every five minutes, while in detailed monitoring a service sends data points to CloudWatch every minute. The AWS SNS service sends data every 5 minutes. Thus, it supports only the basic monitoring. The user cannot enable detailed monitoring with SNS.--
    Reference: http://docs.aws.amazon.com/AmazonCloudWatch/latest/DeveloperGuide/supported services.html

Create an account to continue.