ANS-C01 Exam Questions
305 real ANS-C01 exam questions with expert-verified answers and explanations. Page 3 of 7.
- Question #101Design and Implement Hybrid Connectivity
You use a VPN to extend your corporate network into a VPC. Instances in the VPC are able to resolve resource records in an Amazon Route 53 private hosted zone. Your on-premises DNS...
Route 53 Resolver EndpointsHybrid DNS resolutionPrivate Hosted ZonesVPN Gateway - Question #102
A company is migrating an existing application to a new AWS account. The company will deploy the application in a single AWS Region by using one VPC and multiple Availability Zones...
Network Load BalancerTLS passthroughSession stickinessApplication SSL certificates - Question #103Network Design
A company is developing an application in which IoT devices will report measurements to the AWS Cloud. The application will have millions of end users. The company observes that th...
Network Load BalancerEC2 Auto ScalingStatic IP addressingIoT connectivity - Question #104Design and implement network solutions
A company has deployed a new web application on Amazon EC2 instances behind an Application Load Balancer (ALB). The instances are in an Amazon EC2 Auto Scaling group. Enterprise cu...
AWS Global AcceleratorGlobal Application PerformanceStatic IP AddressesEdge Networking - Question #105Network Design
A company has hundreds of VPCs on AWS. All the VPCs access the public endpoints of Amazon S3 and AWS Systems Manager through NAT gateways. All the traffic from the VPCs to Amazon S...
VPC Interface EndpointsAWS PrivateLinkShared Services VPCCentralized Networking - Question #106Design and Implement Amazon VPC Connectivity Solutions
A company manages resources across VPCs in multiple AWS Regions. The company needs to connect to the resources by using its internal domain name. A network engineer needs to apply...
Route 53 Private Hosted ZonesCross-Region DNSVPC DNS Association - Question #107Design and implement hybrid AWS network architectures
An insurance company is planning the migration of workloads from its on-premises data center to the AWS Cloud. The company requires end-to-end domain name resolution. Bi-directiona...
AWS Route 53Hybrid DNSOn-premises DNS integrationVPC DNS - Question #108Manage and Optimize Network Performance
A global company runs business applications in the us-east-1 Region inside a VPC. One of the company's regional offices in London uses a virtual private gateway for an AWS Site-to-...
Site-to-Site VPNTransit GatewayNetwork LatencyHybrid Connectivity - Question #109Implement Hybrid Connectivity
A company has a hybrid cloud environment. The company's data center is connected to the AWS Cloud by an AWS Direct Connect connection. The AWS environment includes VPCs that are co...
VPC EndpointsRoute 53 ResolverHybrid DNSAmazon SQS - Question #110Network Security, Compliance, and Governance
A company's network engineer builds and tests network designs for VPCs in a development account. The company needs to monitor the changes that are made to network resources and mus...
AWS ConfigConfiguration ManagementNetwork SecurityCompliance - Question #111Hybrid Connectivity
A company is migrating an application from on premises to AWS. The company will host the application on Amazon EC2 instances that are deployed in a single VPC. During the migration...
Hybrid DNSSite-to-Site VPNRoute 53 ResolverConditional Forwarding - Question #112
A company is hosting an application on Amazon EC2 instances behind an Application Load Balancer. The instances are in an Amazon EC2 Auto Scaling group. Because of a recent change t...
AWS ConfigSecurity GroupComplianceRemediation - Question #113Network Design
A company is deploying third-party firewall appliances for traffic inspection and NAT capabilities in its VPC. The VPC is configured with private subnets and public subnets. The co...
Gateway Load Balancerthird-party network appliancesVPC routingtraffic inspection - Question #114
A company's AWS architecture consists of several VPCs. The VPCs include a shared services VPC and several application VPCs. The company has established network connectivity from al...
Route 53 ResolverHybrid DNSDNS ForwardingPrivate Hosted Zones - Question #115Network Management and Operation
A company has been using an outdated application layer protocol for communication among applications. The company decides not to use this protocol anymore and must migrate all appl...
VPC Flow LogsAmazon AthenaNetwork MonitoringApplication Migration - Question #116
A company has deployed its AWS environment in a single AWS Region. The environment consists of a few hundred application VPCs, a shared services VPC, and a VPN connection to the co...
Transit Gateway routingTGW route tablesVPC network architectureHybrid connectivity - Question #117Hybrid Connectivity
A company has an AWS Site-to-Site VPN connection between its existing VPC and on-premises network. The default DHCP options set is associated with the VPC. The company has an appli...
Hybrid DNSRoute 53 ResolverOn-premises integrationDNS forwarding - Question #118Network Security, Compliance, and Governance
A company has several production applications across different accounts in the AWS Cloud. The company operates from the us-east-1 Region only. Only certain partner companies can ac...
Prefix ListsAWS Resource Access Manager (RAM)Security GroupsMulti-Account Networking - Question #119Design Network Solutions
A company uses a 1 Gbps AWS Direct Connect connection to connect its AWS environment to its on-premises data center. The connection provides employees with access to an application...
AWS Direct ConnectHybrid network designNetwork resiliencyBandwidth scaling - Question #120Troubleshoot Network Issues
A company has a global network and is using transit gateways to connect AWS Regions together. The company finds that two Amazon EC2 instances in different Regions are unable to com...
AWS Transit GatewayMulti-Region ConnectivityNetwork TroubleshootingAWS Network Manager - Question #121
A company needs to transfer data between its VPC and its on-premises data center. The data must travel through a connection that has dedicated bandwidth. The data also must be encr...
Direct Connect Hosted ConnectionSite-to-Site VPNDirect Connect Public VIFHybrid Cloud Connectivity - Question #122Hybrid Connectivity
A company's security guidelines state that all outbound traffic from a VPC to the company's on- premises data center must pass through a security appliance. The security appliance...
EC2 enhanced networkingEC2 placement groupsNetwork performanceHybrid connectivity - Question #123Design for Complex Network Architectures
A company's application team is unable to launch new resources into its VPC. A network engineer discovers that the VPC has run out of usable IP addresses. The VPC CIDR block is 172...
VPC CIDR extensionPrivate IP addressingSecondary VPC CIDRIP address management - Question #124
A financial trading company is using Amazon EC2 instances to run its trading platform. Part of the company's trading platform includes a third-party pricing service that the EC2 in...
AWS Traffic MirroringNetwork troubleshootingVPC traffic captureCross-account monitoring - Question #125
A company's network engineer is configuring an AWS Site-to-Site VPN connection between a transit gateway and the company's on-premises network. The Site-to-Site VPN connection is c...
AWS Site-to-Site VPNTransit GatewayBGP routingAsymmetric routing - Question #126
A company runs an application on Amazon EC2 instances. A network engineer implements a NAT gateway in the application's VPC to replace self-managed NAT instances. After the network...
NAT GatewayCloudWatch metricsTroubleshootingConnection timeout - Question #127Design and Implement Hybrid Network Architectures
A software-as-a-service (SaaS) company is migrating its private SaaS application to AWS. The company has hundreds of customers that connect to multiple data centers by using VPN tu...
AWS PrivateLinkHybrid NetworkingSite-to-Site VPNSaaS Architecture - Question #128Design and Implement Network Security
A company's existing AWS environment contains public application servers that run on Amazon EC2 instances. The application servers run in a VPC subnet. Each server is associated wi...
AWS GLBVPC routingNetwork traffic inspectionThird-party firewalls - Question #129Network Management and Operations
A company has an AWS Site-to-Site VPN connection between its office and its VPC. Users report occasional failure of the connection to the application that is hosted inside the VPC....
AWS Site-to-Site VPNIKE sessionDPDVPN troubleshooting - Question #130Design and Implement Hybrid Network Architectures
A network engineer is designing a hybrid networking environment that will connect a company's corporate network to the company's AWS environment. The AWS environment consists of 30...
AWS Direct ConnectDirect Connect redundancyHybrid network designCentralized network filtering - Question #131
A company uses an AWS Direct Connect private VIF with a link aggregation group (LAG) that consists of two 10 Gbps connections. The company's security team has implemented a new req...
Direct Connect MACsecLAGMACsec configuration - Question #132Network Security
A company recently implemented a security policy that prohibits developers from launching VPC network infrastructure. The policy states that any time a NAT gateway is launched in a...
AWS ConfigNAT GatewaySecurity Policy EnforcementCross-account Management - Question #133
A company is running an online game on AWS. The game is played globally and is gaining popularity. Users are reporting problems with the game's responsiveness. Replay rates are dro...
Route 53 latency routingGlobal DNSApplication performance - Question #134Manage and operate network solutions
A network engineer needs to build an encrypted connection between an on-premises data center and a VPC. The network engineer attaches the VPC to a virtual private gateway and sets...
AWS Site-to-Site VPNVPN troubleshootingIPsec rekeyCustomer Gateway device - Question #135Design Network Solutions
A company is growing rapidly. Data transfers between the company's on-premises systems and Amazon EC2 instances that run in VPCs are limited by the throughput of a single AWS Site-...
AWS Site-to-Site VPNTransit GatewayBGPNetwork Scalability - Question #136
A company uses Amazon Route 53 to host a public hosted zone for example.com. A network engineer recently reduced the TTL on several records to 60 seconds. The network engineer want...
Route 53 metricsCloudWatch monitoringDNS query countPublic hosted zones - Question #137
A company is establishing connectivity between its on-premises site and an existing VPC on AWS to meet a new security requirement. According to the new requirement, all public DNS...
Route 53 ResolverHybrid DNSDNS forwardingVPC Endpoints - Question #138Network Design
A network engineer is designing the DNS architecture for a new AWS environment. The environment must be able to resolve DNS names of endpoints on premises, and the on-premises syst...
Route 53 ResolverHybrid DNSMulti-account DNSAWS Resource Access Manager - Question #139
A company wants to migrate its DNS registrar and DNS hosting to Amazon Route 53. The company website receives tens of thousands of visits each day, and the company's current DNS pr...
DNS migrationRoute 53 public hosted zonesZero downtime migrationName server updates - Question #140Implement Network Solutions
A company has an AWS account with four VPCs in the us-east-1 Region. The VPCs consist of a development VPC and three production VPCs that host various workloads. The company has ex...
AWS Transit GatewayTGW Route TablesDirect Connect GatewayNetwork Isolation - Question #141
A network engineer needs to provide dual-stack connectivity between a company's office location and an AWS account. The company's on-premises router supports dual-stack connectivit...
Direct Connect Private VIFsIPv6 Hybrid ConnectivityDirect Connect High Availability - Question #142Configure Network Connectivity and Operations
A company recently started using AWS Client VPN to give its remote users the ability to access resources in multiple peered VPCs and resources in the company's on-premises data cen...
AWS Client VPNVPN routingSplit TunnelingSecurity Groups - Question #143Design and Implement Hybrid Connectivity
A company has set up hybrid connectivity between its VPCs and its on-premises data center. The company has the on-premises.example.com subdomain configured at its DNS server in the...
Route 53 ResolverHybrid DNSOutbound EndpointConditional Forwarding - Question #144Hybrid Connectivity
A company is in the early stage of AWS Cloud adoption. The company has an application that is running in an on-premises data center in Asia. The company needs to deploy new applica...
Site-to-Site VPNTransit GatewayGlobal AcceleratorHybrid Connectivity - Question #145
A company is moving its record-keeping application to the AWS Cloud. All traffic between the company's on-premises data center and AWS must be encrypted at all times and at every t...
AWS Direct ConnectMACsecHybrid networkingNetwork security - Question #146
A network engineer is designing hybrid connectivity with AWS Direct Connect and AWS Transit Gateway. A transit gateway is attached to a Direct Connect gateway and 19 VPCs across di...
AWS Direct ConnectAWS Transit GatewayCIDR summarizationPrefix list management - Question #147Network Design
Two companies are merging. The companies have a large AWS presence with multiple VPCs and are designing connectivity between their AWS networks. Both companies are using AWS Direct...
Transit Gateway peeringVPC Flow LogsCross-account networkingHybrid cloud connectivity - Question #148
A company has a single VPC in the us-east-1 Region. The company is planning to set up a new VPC in the us-east-2 Region. The existing VPC has an AWS Site-to-Site VPN connection to...
Transit GatewayMulti-Region VPCIPv6 networkingSite-to-Site VPN - Question #149DOMAIN_OBJECTIVES_LIST_MISSING
A network engineer is working on a private DNS design to integrate AWS workloads and on- premises resources. The AWS deployment consists of five VPCs in the eu-west-1 Region that c...
Route 53 ResolverHybrid DNSOutbound EndpointsPrivate Hosted Zones - Question #150Optimize network performance
A global film production company uses the AWS Cloud to encode and store its video content before distribution. The company's three global offices are connected to the us-east-1 Reg...
AWS Site-to-Site VPNECMPVPN AccelerationNetwork Throughput