Skip to content

Advanced Networking - Specialty Practice Questions

Prepare for ANS-C01 with more than an answer.

239 questions in the full set17 sample questionsUpdated Jul 16, 2026

Unlock the full exam and previous versions

  • v1Version 1 239 questions Current
  • ANS-C00Legacy AWS Certified Advanced Networking - Specialty 348 questions Locked
Exam fee
$300 USD
Level
Specialty
Valid for
3 years
Domains covered on the exam 4
  1. Network Design30%
  2. Network Implementation26%
  3. Network Management and Operation20%
  4. Network Security, Compliance, and Governance24%
  1. 1

    A healthcare provider requires a dedicated network connection between their on-premises data center and AWS to transfer sensitive patient records. Compliance regulations mandate that all data must be encrypted at Layer 2 using a dedicated encryption key that the customer controls. The connection must support speeds of at least 10 Gbps. Which solution meets these requirements?

    Show answer details

    Correct answer: B

    MACsec (IEEE 802.1AE) provides Layer 2 encryption. AWS Direct Connect supports MACsec on 10 Gbps and 100 Gbps Dedicated connections at select locations. This meets the Layer 2 encryption and speed requirements. VPNs operate at Layer 3 (IPsec).

  2. 2

    A company operates a hybrid environment with a complex DNS structure. They have an on-premises Microsoft DNS server for the corp.local domain and several VPCs in AWS using Route 53 Private Hosted Zones for aws.corp.local. The company needs to enable bi-directional DNS resolution between on-premises and AWS. Specifically, on-premises servers must resolve aws.corp.local, and AWS instances must resolve corp.local. Which set of configurations is required?

    Show answer details

    Correct answer: A

    This is the standard pattern for bi-directional hybrid DNS. Inbound Endpoints allow on-premises to query AWS (Route 53). Outbound Endpoints allow AWS to query on-premises. The Resolver Rule directs the specific domain traffic through the outbound endpoint.

  3. 3

    A media company uses AWS CloudFront to deliver content globally. They want to ensure that users in Europe are routed to a specific version of their application hosted in the eu-central-1 Region, while users in North America are routed to the us-east-1 Region. They also need to perform A/B testing by routing 10% of European traffic to a beta stack in eu-west-1. Which Route 53 routing policy configuration should be used?

    Show answer details

    Correct answer: B

    Route 53 Traffic Flow allows for complex, nested routing policies. Combining Geolocation (for the continental split) and Weighted routing (for the A/B test within Europe) in a visual policy is the most effective way to manage this requirement.

  4. 4

    An enterprise has a centralized auditing account that needs to collect VPC Flow Logs from 50 different AWS accounts within their AWS Organization. The auditing team requires the logs to be stored in a single S3 bucket in the auditing account, partitioned by account ID and date. What is the most efficient way to configure this?

    Show answer details

    Correct answer: B

    VPC Flow Logs can publish directly to an S3 bucket in a different account. This avoids the overhead of CloudWatch Logs or Lambda. The bucket policy must allow the log delivery service and the source accounts to write to the bucket. Hive-compatible partitions (account/date) are supported natively.

  5. 5

    A company is migrating a legacy application to AWS. The application uses hardcoded IP addresses for connectivity between the application tier and the database tier. The migration plan involves moving the application tier to AWS first, while the database remains on-premises. The on-premises network is 10.0.0.0/16. The application expects the database at 10.0.5.50. You need to enable the AWS application instances to connect to the on-premises database using the hardcoded IP. What should you do?

    Show answer details

    Correct answer: C

    The constraint is the hardcoded destination IP in the application code. If the application runs in a VPC with a non-overlapping CIDR (e.g., 192.168.x.x), it can simply send packets to 10.0.5.50. The VPC route table needs a route for 10.0.0.0/16 pointing to the VGW/TGW to reach on-premises. The hardcoded IP is only a problem if the VPC itself uses that IP range (overlapping CIDR), which would cause the local route to drop the traffic.

  6. 6

    A company is planning to create a service that requires encryption in transit. The traffic must not be decrypted between the client and the backend of the service. The company will implement the service by using the gRPC protocol over TCP port 443. The service will scale up to thousands of simultaneous connections. The backend of the service will be hosted on an Amazon Elastic Kubernetes Service (Amazon EKS) duster with the Kubernetes Cluster Autoscaler and the Horizontal Pod Autoscaler configured. The company needs to use mutual TLS for two-way authentication between the client and the backend.Which solution will meet these requirements?

    Show answer details

    Correct answer: A

  7. 7

    A company is deploying a new application in the AWS Cloud. The company wants a highly available web server that will sit behind an Elastic Load Balancer. The load balancer will route requests to multiple target groups based on the URL in the request. All traffic must use HTTPS. TLS processing must be offloaded to the load balancer. The web server must know the user’s IP address so that the company can keep accurate logs for security purposes.Which solution will meet these requirements?

    Show answer details

    Correct answer: A

  8. 8

    A company has developed an application on AWS that will track inventory levels of vending machines and initiate the restocking process automatically. The company plans to integrate this application with vending machines and deploy the vending machines in several markets around the world. The application resides in a VPC in the us-east-1 Region. The application consists of an Amazon Elastic Container Service (Amazon ECS) cluster behind an Application Load Balancer (ALB). The communication from the vending machines to the application happens over HTTPS.The company is planning to use an AWS Global Accelerator accelerator and configure static IP addresses of the accelerator in the vending machines for application endpoint access. The application must be accessible only through the accelerator and not through a direct connection over the internet to the ALB endpoint.Which solution will meet these requirements?

    Show answer details

    Correct answer: A

Create an account to continue.