Skip to content

AWS Certified Advanced Networking - Specialty Practice Questions

Prepare for ANS-C00 with more than an answer.

348 questions in the full set20 sample questionsUpdated Jan 24, 2026

Unlock the full exam and previous versions

  • v1Version 1 239 questions Locked
  • ANS-C00Legacy AWS Certified Advanced Networking - Specialty 348 questions Current
  1. 1

    Your company’s policy requires that all VPCs peer with a “common services: VPC. This VPC contains a fleet of layer 7 proxies and an Internet gateway. No other VPC is allowed to provision an Internet gateway. You configure a new VPC and peer with the common service VPC as required by policy. You launch an Amazon EC2. Windows instance configured to forward all traffic to the layer 7 proxies in the common services VPC. The application on this server should successfully interact with Amazon S3 using its properly configured AWS Identity and Access Management (1AM) role.

    However, Amazon S3 is returning 403 errors to the application.

    Which step should you take to enable access to Amazon S3?

    Show answer details

    Correct answer: B

    B

  2. 2

    You are responsible for several EC2 instances deployed from Amazon AMIs that are required to upload information to an S3 bucket. This information must not traverse the public internet. You must also be able to update the instances.

    Which option is your best solution?

    Show answer details

    Correct answer: D

    D--Explanation:
    A NAT is not required as an S3 endpoint will allow an instance to update. C and D are not possible.

  3. 3

    You have to set up an AWS Direct Connect connection to connect your on-premises to an AWS VPC. Due to budget requirements, you can only provision a single Direct Connect port. You have two border gateway routers at your on-premises data center that can peer with the Direct Connect routers for redundancy.

    Which two design methodologies, in combination, will achieve this connectivity? (Choose two.)

    Show answer details

    Correct answer: C, D

    C,D

    C,D

  4. 4

    A Network Engineer needs to be automatically notified when a certain TCP port is accessed on a fleet of Amazon EC2 instances running in an Amazon VPC.

    Which of the following is the MOST reliable solution?

    Show answer details

    Correct answer: D

    D

  5. 5

    What service is used to store the log files generated by CloudTrail?

    Show answer details

    Correct answer: B

    B--Explanation:
    The AWS CloudTrail uses Amazon's Simple Storage Service (S3) to store log files. It also supports the use of S3 life cycle configuration rules to reduce storage costs.--
    Reference: https://aws.amazon.com/cloudtrail/

  6. 6

    You are architecting your e-business application for PCI compliance. To meet the compliance requirements, you need to monitor web application logs to identify any malicious activity. You also need to monitor for remote attempts to change the network interface of web instances.

    Which two AWS services will be helpful to achieve this goal?

    Show answer details

    Correct answer: B

    Explanation:
    Web application logs are internal to the operating system, so the only way to monitor them with an AWS service is to export them using CloudWatch Logs. AWS CloudTrail monitors the API activity and can be used to watch for particular API calls. The correct answer is the only one that references both these services.

  7. 7

    You can use the _____ command of the AWS Config service CLI to see the compliance state of each resource that AWS Config evaluates for a specific rule.

    Show answer details

    Correct answer: A

    A--Explanation:
    You can use the get-compliance-details-by-config-rule command of the AWS Config CLI to see the compliance state of each resource that AWS Config evaluates for a specific rule.--
    Reference: http://docs.aws.amazon.com/config/latest/developerguide/evaluate-config view-compliance.html

  8. 8

    A user has enabled detailed CloudWatch monitoring with the AWS Simple Notification Service.

    Which of the below mentioned statements helps the user understand detailed monitoring better?

    Show answer details

    Correct answer: C

    C--Explanation:
    CloudWatch is used to monitor AWS as well as the custom services. It provides either basic or detailed monitoring for the supported AWS products. In basic monitoring, a service sends data points to CloudWatch every five minutes, while in detailed monitoring a service sends data points to CloudWatch every minute. The AWS SNS service sends data every 5 minutes. Thus, it supports only the basic monitoring. The user cannot enable detailed monitoring with SNS.--
    Reference: http://docs.aws.amazon.com/AmazonCloudWatch/latest/DeveloperGuide/supported services.html

  9. 9

    What value in a packet dictates the priority of the packet in a QoS enabled network?

    Show answer details

    Correct answer: B

    B--Explanation:
    The Differentiated Services Code Point value, or DSCP, is used to label packets on QoS enabled networks for prioritization.

  10. 10

    An organization processes consumer information submitted through its website. The organization’s security policy requires that personally identifiable information (PH) elements are specifically encrypted at all times and as soon as feasible when received. The front-end Amazon EC2 instances should not have access to decrypted Pll. A single service within the production VPC must decrypt the Pll by leveraging an IAM role.

    Which combination of services will support these requirements? (Choose two.)

    Show answer details

    Correct answer: B, E

    B,E--Explanation:--
    References: noise.getoto.net/tag/aws-kms/">https://noise.getoto.net/tag/aws-kms/

    B,E--Explanation:--
    References: noise.getoto.net/tag/aws-kms/">https://noise.getoto.net/tag/aws-kms/

Create an account to continue.