ANS-C01 Exam Questions
305 real ANS-C01 exam questions with expert-verified answers and explanations. Page 4 of 7.
- Question #151Design Complex Network Solutions
An application team for a startup company is deploying a new multi-tier application into the AWS Cloud. The application will be hosted on a fleet of Amazon EC2 instances that run i...
AWS Global AcceleratorMulti-Region DeploymentTraffic ManagementLow Latency Networking - Question #152Implement Network Solutions
A company is deploying a new stateless web application on AWS. The web application will run on Amazon EC2 instances in private subnets behind an Application Load Balancer. The EC2...
ALB Listener RulesPath-based RoutingIP ConditionALB Target Groups - Question #153
A company deploys a software solution on Amazon EC2 instances that are in a cluster placement group. The solution's UI is a single HTML page. The HTML file size is 1,024 bytes. The...
MTUDon't Fragment flagSite-to-Site VPNPublic internet networking - Question #154Network Design
A company has users who work from home. The company wants to move these users to Amazon WorkSpaces for additional security visibility. The company has deployed WorkSpaces in its ow...
Amazon WorkSpacesGateway Load BalancerTraffic inspectionCross-VPC networking - Question #155Implement Network Security
A company plans to run a computationally intensive data processing application on AWS. The data is highly sensitive. The VPC must have no direct internet access, and the company ha...
NACL rulesSite-to-Site VPNVPC networkingNetwork troubleshooting - Question #156Design and Implement Hybrid Connectivity
A company needs to temporarily scale out capacity for an on-premises application and wants to deploy new servers on Amazon EC2 instances. A network engineer must design the network...
AWS Site-to-Site VPNVPC Private SubnetsCustom Route TablesHybrid Cloud Connectivity - Question #157Network Design
A company is deploying a web application into two AWS Regions. The company has one VPC in each Region. Each VPC has three Amazon EC2 instances as web servers behind an Application...
Route 53Latency-Based RoutingMulti-Region ArchitectureDNS Failover - Question #158Secure AWS Networks
A consulting company manages AWS accounts for its customers. One of the company's customers needs to add intrusion prevention for its environment without having to re-architect the...
AWS Network FirewallIntrusion Prevention SystemVPC peeringNetwork Firewall deployment models - Question #159Hybrid Connectivity
A company hosts its IT infrastructure in an on-premises data center. The company wants to migrate the infrastructure to the AWS Cloud in phases. A network engineer wants to set up...
Site-to-Site VPNTransit GatewayVPN bandwidth aggregationHybrid connectivity - Question #160Manage and Operate Network Solutions
A company has business operations in the United States and in Europe. The company's public applications are running on AWS and use three transit gateways. The transit gateways are...
Transit Gateway routingNetwork troubleshootingTransit Gateway Network ManagerRoute Analyzer - Question #161Design and Implement Hybrid Connectivity
A marketing company is using hybrid infrastructure through AWS Direct Connect links and a software-defined wide area network (SD-WAN) overlay to connect its branch offices. The com...
AWS Transit GatewayTGW ConnectSD-WAN integrationHybrid Cloud Networking - Question #162
A company is running a hybrid cloud environment. The company has multiple AWS accounts as part of an organization in AWS Organizations. The company needs a solution to manage a lis...
AWS Prefix ListsHybrid NetworkingCross-account sharingNetwork Access Control - Question #163Design and Implement Network Security
A company's application is deployed on Amazon EC2 instances in a single VPC in an AWS Region. The EC2 instances are running in two Availability Zones. The company decides to use a...
GWLBTraffic inspectionHigh availabilityCross-zone load balancing - Question #164Design Network Solutions
A company has developed a new web application on AWS. The application runs on Amazon Elastic Container Service (Amazon ECS) on AWS Fargate behind an Application Load Balancer (ALB)...
Amazon CloudFrontCDN cachingLatency optimizationHTTPS encryption - Question #165Implement AWS Hybrid Connectivity
A company deploys an internal website behind an Application Load Balancer (ALB) in a VPC. The VPC has a CIDR block of 172.31.0.0/16. The company creates a private hosted zone for t...
Route 53 Private Hosted ZoneRoute 53 Resolver Inbound EndpointHybrid DNSDNS Conditional Forwarding - Question #166
A company is deploying AWS Cloud WAN with edge locations in the us-east-1 Region and the ap-southeast-2 Region. Individual AWS Cloud WAN segments are configured for the development...
AWS Cloud WANCloud WAN policiesAttachment acceptanceTag-based policies - Question #167Design Network Solutions for Complex Hybrid Scenarios
A company is migrating applications from a data center to AWS. Many of the applications will need to exchange data with the company's on-premises mainframe. The company needs to ac...
AWS Direct ConnectHybrid connectivityHigh availabilityNetwork resiliency - Question #168Design and Implement Hybrid Connectivity
A company has 10 web server Amazon EC2 instances that run in an Auto Scaling group in a production VPC. The company has 10 other web servers that run in an on-premises data center....
ALBSession StickinessHybrid Load BalancingALB Target Groups - Question #169Design and Implement Hybrid IT Network Architectures
A company has an AWS environment that includes multiple VPCs that are connected by a transit gateway. The company has decided to use AWS Site-to-Site VPN to establish connectivity...
AWS Site-to-Site VPNDynamic VPN endpointIKEv2VPN certificate authentication - Question #170Design Network Solutions for AWS
A company's AWS environment has two VPCs. VPC A has a CIDR block of 192.168.0.0/16. VPC B has a CIDR block of 10.0.0.0/16. Each VPC is deployed in a separate AWS Region. The compan...
AWS Client VPNVPC PeeringCross-Region ConnectivityRoute Tables - Question #171
A company uses Amazon Route 53 to register a public domain, example.com, in an AWS account. A central services group manages the account. The company wants to create a subdomain, t...
Route 53 delegationSubdomain configurationNS record configurationCross-account DNS - Question #172Design and Implement AWS Network Architectures
An IoT company collects data from thousands of sensors that are deployed in the Unites States and South Asia. The sensors use a proprietary communication protocol that is built on...
AWS Global AcceleratorMulti-region deploymentNetwork Load BalancerUDP connectivity - Question #173
A company has an application that runs on a fleet of Amazon EC2 instances. A new company regulation mandates that all network traffic to and from the EC2 instances must be sent to...
Centralized Traffic InspectionVPC RoutingNetwork Load BalancerEC2 Auto Scaling - Question #174Official Exam Domains (pick EXACTLY one):
A company has two AWS Direct Connect links. One Direct Connect link terminates in the us-east- 1 Region, and the other Direct Connect link terminates in the af-south-1 Region. The...
AWS Direct ConnectBGP communitiesRoute preference - Question #175Design Network Solutions
A team of infrastructure engineers wants to automate the deployment of Application Load Balancer (ALB) components by using the AWS Cloud Development Kit (AWS CDK). The CDK applicat...
AWS CDKApplication Load BalancerMulti-account architectureInfrastructure automation - Question #176
A company has critical VPC workloads that connect to an on-premises data center through two redundant active-passive AWS Direct Connect connections. However, a recent outage on one...
Direct Connect BFDBGP failoverHybrid connectivityNetwork redundancy - Question #177Design Hybrid Connectivity
A European car manufacturer wants to migrate its customer-facing services and its analytics platform from two on-premises data centers to the AWS Cloud. The company has a 50-mile (...
Direct Connect GatewayTransit GatewayHybrid Network DesignMulti-Region Networking - Question #178Manage and Optimize Network Operations
A company wants to analyze TCP traffic to the internet. The traffic originates from Amazon EC2 instances in the company's VPC. The EC2 instances initiate connections through a NAT...
VPC Traffic MirroringVPC Flow LogsDeep Packet InspectionNAT Gateway - Question #179VPC Connectivity
A company has three VPCs in a single AWS Region. Each VPC contains 15 Amazon EC2 instances, and no connectivity exists between the VPCs. The company is deploying a new application...
AWS Transit GatewayVPC peeringMulti-VPC networkingNetwork throughput - Question #180
A network engineer needs to deploy an AWS Network Firewall firewall into an existing AWS environment. The environment consists of the following: - A transit gateway with all VPCs a...
AWS Network Firewall deploymentAWS Transit Gateway routingTraffic Inspection ArchitectureSuricata rule configuration - Question #181
A company is using a shared services VPC with two domain controllers. The domain controllers are deployed in the company's private subnets. The company is deploying a new applicati...
Transit Gateway troubleshootingVPC routing troubleshootingVPC Flow LogsAWS Network Manager route analysis - Question #182Network Security
A company has an order processing system that needs to keep credit card numbers encrypted. The company's customer-facing application runs as an Amazon Elastic Container Service (Am...
AWS Certificate Manager (ACM)Application Load Balancer (ALB)AWS Key Management Service (KMS)Field-level encryption - Question #183Design and implement AWS network architectures
A company has deployed a multi-VPC environment in the AWS Cloud. The company uses a transit gateway to connect all the VPCs together. In the past, the company has experienced a los...
VPC Reachability AnalyzerNetwork troubleshootingSecurity GroupsNACLs - Question #184
A company hosts a web application that runs on a fleet of Amazon EC2 instances behind an Application Load Balancer (ALB). The instances are in an Auto Scaling group. The company us...
AWS WAF loggingAmazon AthenaKinesis Data Firehose - Question #185Design and implement monitoring, optimization, and troubleshooting of network connectivity
A real estate company is using Amazon Workspaces to provide corporate managed desktop service to its real estate agents around the world. These Workspaces are deployed in seven VPC...
Route 53 query loggingDNS monitoringKinesis Data FirehoseCentralized logging - Question #186Design and Implement Network Monitoring and Optimization
A network engineer needs to design the architecture for a high performance computing (HPC) workload. Amazon EC2 instances will require 10 Gbps flows and an aggregate throughput of...
HPC workload designEC2 placement groupsNetwork performance optimizationLow-latency networking - Question #187Secure AWS Networks
A company uses multiple AWS accounts and VPCs in a single AWS Region. The company must log all network traffic for Amazon EC2 instances and Amazon RDS databases. The company will u...
VPC Flow LogsS3 StorageNetwork MonitoringCost Optimization - Question #188
A network engineer is evaluating a network setup for a global retail company. The company has an AWS Direct Connect connection between its on-premises data center and the AWS Cloud...
Direct ConnectTransit GatewayTransit Gateway PeeringHybrid Networking - Question #189
A company has a 2 Gbps AWS Direct Connect hosted connection from the company's office to a VPC in the ap-southeast-2 Region. A network engineer adds a 5 Gbps Direct Connect hosted...
AWS Direct ConnectBGP routingRoute preferenceFailover - Question #190Secure and Optimize Network Solutions
An ecommerce company needs to implement additional security controls on all its domain names that are hosted in Amazon Route 53. The company's new policy requires data authenticati...
Route 53 DNSSECDNSSEC KSKDNSSEC DS recordCloudWatch Alarms - Question #191Design for New Solutions
A financial company that is located in the us-east-1 Region needs to establish secure connectivity to AWS. The company has two on-premises data centers, each located within the sam...
AWS Direct ConnectDirect Connect VIFsSite-to-Site VPNHybrid Cloud Networking - Question #192Hybrid Connectivity
A global company is designing a hybrid architecture to privately access AWS resources in the us- west-2 Region. The company's existing architecture includes a VPC that uses RFC 191...
- Question #193Network Security
A company is migrating critical applications to AWS. The company has multiple accounts and VPCs that are connected by a transit gateway. A network engineer must design a solution t...
- Question #194Hybrid Connectivity
A company has an on-premises data center in the United States. The data center is connected to AWS by an AWS Direct Connect connection. The data center has a private VIF that is co...
- Question #195Network Management and Operation
A company has a new AWS Direct Connect connection between its on-premises data center and the AWS Cloud. The company has created a new private VIF on this connection. However, the...
- Question #196Network Implementation
AnyCompany has acquired Example Corp. AnyCompany's infrastructure is all on premises, and Example Corp's infrastructure is completely in the AWS Cloud. The companies are using AWS...
- Question #197Network Management and Operation
A company recently experienced an IP address exhaustion event in its VPCs. The event affected service capacity. The VPCs hold two or more subnets in different Availability Zones. A...
- Question #198Hybrid Connectivity
A company has a hybrid IT setup that includes services that run in an on-premises data center and in the AWS Cloud. The company is using AWS Direct Connect to connect its data cent...
- Question #199Network Security, Compliance, and Governance
A company is developing a new application that is deployed in multiple VPCs across multiple AWS Regions. The VPCs are connected through AWS Transit Gateway. The VPCs contain privat...
AWS Network FirewallNetwork Firewall loggingTraffic auditingSecurity logging - Question #200Network Design
A company has set up a NAT gateway in a single Availability Zone (AZ1) in a VPC (VPC1) to access the internet from Amazon EC2 workloads in the VPC. The EC2 workloads are running in...
NAT GatewayHigh AvailabilityVPC NetworkingRedundancy