Important Amazon ANS-C01 Exam Questions

CertPrep Amazon ANS-C01 Exam Questions
Get Full Version

Amazon AWS Certified Advanced Networking - Specialty ANS-C01 Exam

Attempt the Amazon Specialty practice test and solve real exam-like ANS-C01 questions to prepare efficiently and increase your chances of success. Our Amazon ANS-C01 practice questions match the actual AWS Certified Advanced Networking - Specialty exam format, helping you enhance confidence and improve performance. With our ANS-C01 practice exam software, you can analyze your performance, identify weak areas, and work on them effectively to boost your final Amazon Specialty exam score.

Vendor: Amazon
Exam Name: AWS Certified Advanced Networking - Specialty
Registration Code: ANS-C01
Related Certification: Amazon Specialty Certification
Exam Audience: AWS networking specialist,

Total Questions

291

Last Updated

08-08-2026

Exam Duration

170 MINUTES

Upgrade to Premium

GET FULL PDF

Question: 1

A company's existing AWS environment contains public application servers that run on Amazon EC2 instances. The application servers run in a VPC subnet. Each server is associated with an Elastic IP address.

The company has a new requirement for firewall inspection of all traffic from the internet before the traffic reaches any EC2 instances. A security engineer has deployed and configured a Gateway Load Balancer (GLB) in a standalone VPC with a fleet of third-party firewalls.

How should a network engineer update the environment to ensure that the traffic travels across the fleet of firewalls?

Question: 2

A company has configured an AWS Cloud WAN core network with edge locations in the us-east-1 Region and the us-west-1 Region. Each edge location has two segments: development and staging. The segments use the default core network policy.

The company has attached VPCs to the core network. A development VPC is attached to the development segment in us-east-1 and is configured to use the 10.0.0.0/16 CIDR block. A staging VPC is attached to the staging segment in us-west-1 and is configured to use the 10.5.0.0/16 CIDR block. The company has updated the route tables for both VPCs with a route that directs any traffic for 0.0.0.0/0 to the core network.

The company's network team needs to establish communication between the two VPCs by using the AWS Cloud WAN core network. The network team is not receiving a response during tests of communication between the VPCs. The network team has verified that security groups and network ACLs are not blocking the traffic.

What should the network team do to establish this communication?

Question: 3

A company recently started using AWS Client VPN to give its remote users the ability to access resources in multiple peered VPCs and resources in the company's on-premises data center. The Client VPN endpoint route table has a single entry of 0.0.0.0/0. The Client VPN endpoint is using a new security group that has no inbound rules and a single outbound rule that allows all traffic to 0.0.0.0/0.

Multiple users report that web search results are showing remote incorrect geographic location information for the users.

Which combination of steps should a network engineer take to resolve this issue with the LEAST amount of service interruption? (Choose three.)

Question: 4

A company is migrating critical applications to AWS. The company has multiple accounts and VPCs that are connected by a transit gateway.

A network engineer must design a solution that performs deep packet inspection for any traffic that leaves a VPC network boundary. All inspected traffic and the actions that are taken on the traffic must be logged in a central log account.

Which solution will meet these requirements with the LEAST administrative overhead?

Question: 5

A network engineer is using AWS Direct Connect connections and MACsec to encrypt data from a corporate data center to the Direct Connect location. The network engineer learns that the MACsec secret key might have been compromised. The network engineer needs to update the connection with an uncompromised secure key.

Which solution will meet this requirement?

Other Amazon Certification Exams

SAP-C02 Exam

AWS Certified Solutions Architect - Professional Exam

DEA-C01 Exam

AWS Certified Data Engineer - Associate

SAA-C03 Exam

AWS Certified Solutions Architect - Associate

CLF-C02 Exam

AWS Certified Cloud Practitioner Exam

AIF-C01 Exam

AWS Certified AI Practitioner

AIP-C01 Exam

AWS Certified Generative AI Developer - Professional