Exam Details

  • Exam Code
    :ANS-C01
  • Exam Name
    :AWS Certified Advanced Networking - Specialty (ANS-C01)
  • Certification
    :Amazon Certifications
  • Vendor
    :Amazon
  • Total Questions
    :240 Q&As
  • Last Updated
    :Apr 24, 2025

Amazon Amazon Certifications ANS-C01 Questions & Answers

  • Question 211:

    A company has deployed an AWS Network Firewall firewall into a VPC. A network engineer needs to implement a solution to deliver NetworkFirewall flow logs to the company's Amazon OpenSearch Service (Amazon Elasticsearch Service) cluster in the shortest possible time.Which solution will meet these requirements?

    A. Create an Amazon S3 bucket. Create an AWS Lambda function to load logs into the Amazon OpenSearch Service (Amazon ElasticsearchService) cluster. Enable Amazon Simple Notification Service (Amazon SNS) notifications on the S3 bucket to invoke the Lambda function.Configure flow logs for the firewall. Set the S3 bucket as the destination.

    B. Create an Amazon Kinesis Data Firehose delivery stream that includes the Amazon OpenSearch Service (Amazon Elasticsearch Service)cluster as the destination. Configure flow logs for the firewall Set the Kinesis Data Firehose delivery stream as the destination for theNetwork Firewall flow logs.

    C. Configure flow logs for the firewall. Set the Amazon OpenSearch Service (Amazon Elasticsearch Service) cluster as the destination forthe Network Firewall flow logs.

    D. Create an Amazon Kinesis data stream that includes the Amazon OpenSearch Service (Amazon Elasticsearch Service) cluster as thedestination. Configure flow logs for the firewall. Set the Kinesis data stream as the destination for the Network Firewall flow logs.

  • Question 212:

    A banking company is successfully operating its public mobile banking stack on AWS. The mobile banking stack is deployed in a VPC thatincludes private subnets and public subnets. The company is using IPv4 networking and has not deployed or supported IPv6 in theenvironment. The company has decided to adopt a third-party service provider's API and must integrate the API with the existing environment.The service provider's API requires the use of IPv6.A network engineer must turn on IPv6 connectivity for the existing workload that is deployed in a private subnet. The company does not wantto permit IPv6 traffic from the public internet and mandates that the company's servers must initiate all IPv6 connectivity. The networkengineer turns on IPv6 in the VPC and in the private subnets.Which solution will meet these requirements?

    A. Create an internet gateway and a NAT gateway in the VPC. Add a route to the existing subnet route tables to point IPv6 traffic to theNAT gateway.

    B. Create an internet gateway and a NAT instance in the VPC. Add a route to the existing subnet route tables to point IPv6 traffic to theNAT instance.

    C. Create an egress-only Internet gateway in the VPAdd a route to the existing subnet route tables to point IPv6 traffic to the egress-onlyinternet gateway.

    D. Create an egress-only internet gateway in the VPC. Configure a security group that denies all inbound traffic. Associate the securitygroup with the egress-only internet gateway.

  • Question 213:

    A retail company is running its service on AWS. The company's architecture includes Application Load Balancers (ALBs) in public subnets. TheALB target groups are configured to send traffic to backend Amazon EC2 instances in private subnets. These backend EC2 instances can callexternally hosted services over the internet by using a NAT gateway.The company has noticed in its billing that NAT gateway usage has increased significantly. A network engineer needs to find out the source ofthis increased usage.Which options can the network engineer use to investigate the traffic through the NAT gateway? (Choose two.)

    A. Enable VPC flow logs on the NAT gateway's elastic network interface. Publish the logs to a log group in Amazon CloudWatch Logs. UseCloudWatch Logs Insights to query and analyze the logs.

    B. Enable NAT gateway access logs. Publish the logs to a log group in Amazon CloudWatch Logs. Use CloudWatch Logs Insights to queryand analyze the logs.

    C. Configure Traffic Mirroring on the NAT gateway's elastic network interface. Send the traffic to an additional EC2 instance. Use tools suchas tcpdump and Wireshark to query and analyze the mirrored traffic.

    D. Enable VPC flow logs on the NAT gateway's elastic network interface. Publish the logs to an Amazon S3 bucket. Create a custom tablefor the S3 bucket in Amazon Athena to describe the log structure. Use Athena to query and analyze the logs.

    E. Enable NAT gateway access logs. Publish the logs to an Amazon S3 bucket. Create a custom table for the S3 bucket in Amazon Athenato describe the log structure. Use Athena to query and analyze the logs.

  • Question 214:

    A network engineer is designing the architecture for a healthcare company's workload that is moving to the AWS Cloud. All data to and fromthe on-premises environment must be encrypted in transit. All traffic also must be inspected in the cloud before the traffic is allowed to leavethe cloud and travel to the on-premises environment or to the internet.The company will expose components of the workload to the internet so that patients can reserve appointments. The architecture must securethese components and protect them against DDoS attacks. The architecture also must provide protection against financial liability for servicesthat scale out during a DDoS event.Which combination of steps should the network engineer take to meet all these requirements for the workload? (Choose three.)

    A. Use Traffic Mirroring to copy all traffic to a fleet of traffic capture appliances.

    B. Set up AWS WAF on all network components.

    C. Configure an AWS Lambda function to create Deny rules in security groups to block malicious IP addresses.

    D. Use AWS Direct Connect with MACsec support for connectivity to the cloud.

    E. Use Gateway Load Balancers to insert third-party firewalls for inline traffic inspection.

    F. Configure AWS Shield Advanced and ensure that it is configured on all public assets.

  • Question 215:

    A software-as-a-service (SaaS) provider hosts its solution on Amazon EC2 instances within a VPC in the AWS Cloud. All of the provider'scustomers also have their environments in the AWS Cloud.A recent design meeting revealed that the customers have IP address overlap with the provider's AWS deployment. The customers have statedthat they will not share their internal IP addresses and that they do not want to connect to the provider's SaaS service over the internet.Which combination of steps is part of a solution that meets these requirements? (Choose two.)

    A. Deploy the SaaS service endpoint behind a Network Load Balancer.

    B. Configure an endpoint service, and grant the customers permission to create a connection to the endpoint service.

    C. Deploy the SaaS service endpoint behind an Application Load Balancer.

    D. Configure a VPC peering connection to the customer VPCs. Route traffic through NAT gateways.

    E. Deploy an AWS Transit Gateway, and connect the SaaS VPC to it. Share the transit gateway with the customers. Configure routing on thetransit gateway.

  • Question 216:

    A company uses a 4 Gbps AWS Direct Connect dedicated connection with a link aggregation group (LAG) bundle to connect to five VPCs thatare deployed in the us-east-1 Region. Each VPC serves a different business unit and uses its own private VIF for connectivity to the on-premises environment. Users are reporting slowness when they access resources that are hosted on AWS.A network engineer finds that there are sudden increases in throughput and that the Direct Connect connection becomes saturated at thesame time for about an hour each business day. The company wants to know which business unit is causing the sudden increase inthroughput. The network engineer must find out this information and implement a solution to resolve the problem.Which solution will meet these requirements?

    A. Review the Amazon CloudWatch metrics for VirtualInterfaceBpsEgress and VirtualInterfaceBpsIngress to determine which VIF issending the highest throughput during the period in which slowness is observed. Create a new 10 Gbps dedicated connection. Shift trafficfrom the existing dedicated connection to the new dedicated connection.

    B. Review the Amazon CloudWatch metrics for VirtualInterfaceBpsEgress and VirtualInterfaceBpsIngress to determine which VIF issending the highest throughput during the period in which slowness is observed. Upgrade the bandwidth of the existing dedicatedconnection to 10 Gbps.

    C. Review the Amazon CloudWatch metrics for ConnectionBpsIngress and ConnectionPpsEgress to determine which VIF is sending thehighest throughput during the period in which slowness is observed. Upgrade the existing dedicated connection to a 5 Gbps hostedconnection.

    D. Review the Amazon CloudWatch metrics for ConnectionBpsIngress and ConnectionPpsEgress to determine which VIF is sending thehighest throughput during the period in which slowness is observed. Create a new 10 Gbps dedicated connection. Shift traffic from theexisting dedicated connection to the new dedicated connection.

  • Question 217:

    A global delivery company is modernizing its fleet management system. The company has several business units. Each business unit designsand maintains applications that are hosted in its own AWS account in separate application VPCs in the same AWS Region. Each businessunit's applications are designed to get data from a central shared services VPC.The company wants the network connectivity architecture to provide granular security controls. The architecture also must be able to scale asmore business units consume data from the central shared services VPC in the future.Which solution will meet these requirements in the MOST secure manner?

    A. Create a central transit gateway. Create a VPC attachment to each application VPC. Provide full mesh connectivity between all theVPCs by using the transit gateway.

    B. Create VPC peering connections between the central shared services VPC and each application VPC in each business unit's AWSaccount.

    C. Create VPC endpoint services powered by AWS PrivateLink in the central shared services VPCreate VPC endpoints in each applicationVPC.

    D. Create a central transit VPC with a VPN appliance from AWS Marketplace. Create a VPN attachment from each VPC to the transit VPC.Provide full mesh connectivity among all the VPCs.

  • Question 218:

    A company has developed an application on AWS that will track inventory levels of vending machines and initiate the restocking processautomatically. The company plans to integrate this application with vending machines and deploy the vending machines in several marketsaround the world. The application resides in a VPC in the us-east-1 Region. The application consists of an Amazon Elastic Container Service(Amazon ECS) cluster behind an Application Load Balancer (ALB). The communication from the vending machines to the application happensover HTTPS.The company is planning to use an AWS Global Accelerator accelerator and configure static IP addresses of the accelerator in the vendingmachines for application endpoint access. The application must be accessible only through the accelerator and not through a directconnection over the internet to the ALB endpoint.Which solution will meet these requirements?

    A. Configure the ALB in a private subnet of the VPC. Attach an internet gateway without adding routes in the subnet route tables to pointto the internet gateway. Configure the accelerator with endpoint groups that include the ALB endpoint. Configure the ALB's security groupto only allow inbound traffic from the internet on the ALB listener port.

    B. Configure the ALB in a private subnet of the VPC. Configure the accelerator with endpoint groups that include the ALB endpoint.Configure the ALB's security group to only allow inbound traffic from the internet on the ALB listener port.

    C. Configure the ALB in a public subnet of the VPAttach an internet gateway. Add routes in the subnet route tables to point to the internetgateway. Configure the accelerator with endpoint groups that include the ALB endpoint. Configure the ALB's security group to only allowinbound traffic from the accelerator's IP addresses on the ALB listener port.

    D. Configure the ALB in a private subnet of the VPC. Attach an internet gateway. Add routes in the subnet route tables to point to theinternet gateway. Configure the accelerator with endpoint groups that include the ALB endpoint. Configure the ALB's security group to onlyallow inbound traffic from the accelerator's IP addresses on the ALB listener port.

  • Question 219:

    A company is deploying a new application in the AWS Cloud. The company wants a highly available web server that will sit behind an ElasticLoad Balancer. The load balancer will route requests to multiple target groups based on the URL in the request. All traffic must use HTTPS.TLS processing must be offloaded to the load balancer. The web server must know the user's IP address so that the company can keepaccurate logs for security purposes.Which solution will meet these requirements?

    A. Deploy an Application Load Balancer with an HTTPS listener. Use path-based routing rules to forward the traffic to the correct targetgroup. Include the X-Forwarded-For request header with traffic to the targets.

    B. Deploy an Application Load Balancer with an HTTPS listener for each domain. Use host-based routing rules to forward the traffic to thecorrect target group for each domain. Include the X-Forwarded-For request header with traffic to the targets.

    C. Deploy a Network Load Balancer with a TLS listener. Use path-based routing rules to forward the traffic to the correct target group.Configure client IP address preservation for traffic to the targets.

    D. Deploy a Network Load Balancer with a TLS listener for each domain. Use host-based routing rules to forward the traffic to the correcttarget group for each domain. Configure client IP address preservation for traffic to the targets.

  • Question 220:

    A company is planning to create a service that requires encryption in transit. The traffic must not be decrypted between the client and thebackend of the service. The company will implement the service by using the gRPC protocol over TCP port 443. The service will scale up tothousands of simultaneous connections. The backend of the service will be hosted on an Amazon Elastic Kubernetes Service (Amazon EKS)duster with the Kubernetes Cluster Autoscaler and the Horizontal Pod Autoscaler configured. The company needs to use mutual TLS for two-way authentication between the client and the backend.Which solution will meet these requirements?

    A. Install the AWS Load Balancer Controller for Kubernetes. Using that controller, configure a Network Load Balancer with a TCP listeneron port 443 to forward traffic to the IP addresses of the backend service Pods.

    B. Install the AWS Load Balancer Controller for Kubernetes. Using that controller, configure an Application Load Balancer with an HTTPSlistener on port 443 to forward traffic to the IP addresses of the backend service Pods.

    C. Create a target group. Add the EKS managed node group's Auto Scaling group as a target Create an Application Load Balancer with anHTTPS listener on port 443 to forward traffic to the target group.

    D. Create a target group. Add the EKS managed node group's Auto Scaling group as a target. Create a Network Load Balancer with a TLSlistener on port 443 to forward traffic to the target group.

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only Amazon exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your ANS-C01 exam preparations and Amazon certification application, do not hesitate to visit our Vcedump.com to find your solutions here.