Weekend Sale - 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: dm70dm

Note! The ANS-C00 Exam is no longer available. Get in touch with our Live Chat or email us for more information about the ANS-C01 Exam.

ANS-C00 AWS Certified Advanced Networking Specialty Exam Questions and Answers

Questions 4

You need to set up an Amazon Elastic Compute Cloud (EC2) instance for an application that requires the lowest latency and the highest packet-per-second network performance. The application will talk to other servers in a peered VPC.

Which two of the following components should be part of the design? (Select two.)

Options:

A.

Select an instance with support for single root I/O virtualization.

B.

Select an instance that has support for multiple ENIs.

C.

Ensure that the instance supports jumbo frames and set 9001 MTU.

D.

Select an instance with Amazon Elastic Block Store (EBS)-optimization.

E.

Ensure that proper OS drivers are installed.

Buy Now
Questions 5

Your company operates a single AWS account. A common services VPC is deployed to provide shared services, such as network scanning and compliance tools. Each AWS workload uses its own VPC, and each VPC must peer with the common services VPC. You must choose the most efficient and cost effective approach.

Which approach should be used to automate the required VPC peering?

Options:

A.

AWS CloudTrail integration with Amazon CloudWatch Logs to trigger a Lambda function.

B.

An OpsWorks Chef recipe to execute a command-line peering request.

C.

Cfn-init with AWS CloudFormation to execute a command-line peering request.

D.

An AWS CloudFormation template that includes a peering request.

Buy Now
Questions 6

The Payment Card Industry Data Security Standard (PCI DSS) merchants that handle credit card data must use strong cryptography. These merchants must also use security protocols to protect sensitive data during transmission over public networks.

You are migrating your PCI DSS application from on-premises SSL appliance and Apache to a VPC behind Amazon CloudFront.

How should you configure CloudFront to meet this requirement?

Options:

A.

Configure the CloudFront Cache Behavior to require HTTPS and the CloudFront Origin’s Protocol Policy to ‘Match Viewer’.

B.

Configure the CloudFront Cache Behavior to allow TCP connections and to forward all requests to the origin without TLS termination at the edge.

C.

Configure the CloudFront Cache Behavior to require HTTPS and to forward requests to the origin via AWS Direct Connect.

D.

Configure the CloudFront Cache Behavior to redirect HTTP requests to HTTPS and to forward request to the origin via the Amazon private network.

Buy Now
Questions 7

You have multiple Amazon Elastic Compute Cloud (EC2) instances running a web server in a VPC configured with security groups and NACL. You need to ensure layer 7 protocol level logging of all network traffic (ACCEPT/REJECT) on the instances. What should be enabled to complete this task?

Options:

A.

CloudWatch Logs at the VPC level

B.

Packet sniffing at the instance level

C.

VPC flow logs at the subnet level

D.

Packet sniffing at the VPC level

Buy Now
Questions 8

A company uses an Application Load Balancer (ALB) to provide access to a multi-tenant web application for 25 customers The company creates a unique hostname for each customer to use to access the application Hostnames use the format customer-name example.com.

Each customer has a dedicated group of Amazon EC2 instances that run their own version of the web application. When a customer visits customer-name example com, the ALB should route the request to the correct group of EC2 instances The company requires a highly available solution that is easy to maintain

Which solution meets these requirements at the LOWEST cost?

Options:

A.

Create one ALB for all customers Create a listener rule that includes an HTTP header condition to match the URL Add a forward action to route the request to the customer target group Use Amazon Route 53 to create an alias record for each customer-name example com hostname that points to the ALB

B.

Create one ALB for each customer Configure the listener to route requests to the customer target group Configure an NGINX proxy server to manage

connections to each ALB Use Amazon Route 53 to create a CNAME record for each customer-name example com hostname that points to the NGINX proxy server

C.

Create one ALB for ail customers Create a listener rule that includes a Host header condition to match the hostname Add a forward action to route the request to the customer target group Use Amazon Route 53 to create an alias record for each customer-name example com hostname that points to the ALB

D.

Create one ALB for each customer Configure the listener to route requests to the customer target group Create an Amazon CloudFront distribution Add each ALB to the distribution as a custom origin Use Amazon Route 53 to create an alias for each customer-name example com hostname that points to the CloudFront distribution

Buy Now
Questions 9

Your organization runs a popular e-commerce application deployed on AWS that uses autoscaling in conjunction with an Elastic Load balancing (ELB) service with an HTTPS listener. Your security team reports that an exploitable vulnerability has been discovered in the encryption protocol and cipher that your site uses.

Which step should you take to fix this problem?

Options:

A.

Generate new SSL certificates for all web servers and replace current certificates.

B.

Change the security policy on the ELB to disable vulnerable protocols and ciphers.

C.

Generate new SSL certificates and use ELB to front-end the encrypted traffic for all web servers.

D.

Leverage your current configuration management system to update SSL policy on all web servers.

Buy Now
Questions 10

A Network Engineer is provisioning a subnet for a load balancer that will sit in front of a fleet of application servers in a private subnet. There is limited IP space left in the VPC CIDR. The application has few users now but is expected to grow quickly to millions of users.

What design will use the LEAST amount of IP space, while allowing for this growth?

Options:

A.

Use two /29 subnets for an Application Load Balancer in different Availability Zones.

B.

Use one /29 subnet for the Network Load Balancer. Add another VPC CIDR to the VPC to allow for future growth.

C.

Use two /28 subnets for a Network Load Balancer in different Availability Zones.

D.

Use one /28 subnet for an Application Load Balancer. Add another VPC CIDR to the VPC to allow for future growth.

Buy Now
Questions 11

All IP addresses within a 10.0.0.0/16 VPC are fully utilized with application servers across two Availability Zones. The application servers need to send frequent UDP probes to a single central authentication server on the Internet to confirm that is running up-to-date packages. The network is designed for application servers to use a single NAT gateway for internal access. Testing reveals that a few of the servers are unable to communicate with the authentication server.

Options:

A.

The NAT gateway does not support UDP traffic.

B.

The authentication server is not accepting traffic.

C.

The NAT gateway cannot allocate more ports.

D.

The NAT gateway is launched in a private subnet.

Buy Now
Questions 12

Your application is hosted behind an Elastic Load Balancer (ELB) within an autoscaling group. The autoscaling group is configured with a minimum of 2, a maximum of 14, and a desired value of 2. The autoscaling cooldown and the termination policies are set to the default value.

CloudWatch reports that the site typically requires just two servers, but spikes at the start and end of the business day can require eight to ten servers. You receive intermittent reports of timeouts and partially loaded web pages.

Which configuration change should you make to address this issue?

Options:

A.

Configure connection draining on the ELB.

B.

Configure the autoscaling cooldown to 600 seconds.

C.

Configure the termination policy to oldest instance.

D.

Configure a Terminating: Wait lifecycle hook on a scale in event.

Buy Now
Questions 13

A company has established an AWS Direct Connect connection between its customer gateway at its on-premises data center and a virtual private gateway m the AWS Cloud The BGP routing protocol configuration includes the Autonomous System Number {ASN) of 7224 on the AWS end of the connection and the BGP ASN of 65004 on the company end of the connection

The company's IT administrators report that servers that run at the on-premises data center are not able to communicate with the company's web application that runs on a fleet of Amazon EC2 Instances A network engineer performs initial troubleshooting The network engineer finds that the private VIF is operational and that there is a fully established BGP peering session However, the company still cannot route traffic over the private VIF

Which of the following is a possible cause of this connectivity issue?

Options:

A.

Firewall or ACL rules are blocking TCP pod 179 or are blocking high-numbered ephemeral TCP pons

B.

The provider is advertising 50 prefixes for private VIFs

C.

VPC route tables am lacking prefixes that point to the virtual private gateway to which the private VIF is connected

D.

Peer IP addresses for both sides of the BGP peering session are not configured correctly.

Buy Now
Questions 14

A customer has set up multiple VPCs for Dev, Test, Prod, and Management. You need to set up AWS Direct Connect to enable data flow from on-premises to each VPC. The customer has monitoring software running in the Management VPC that collects metrics from the instances in all the other VPCs. Due to budget requirements, data transfer charges should be kept at minimum.

Which design should be recommended?

Options:

A.

Create a total of four private VIFs, one for each VPC owned by the customer, and route traffic between VPCs using the Direct Connect link.

B.

Create a private VIF to the Management VPC, and peer this VPC to all other VPCs.

C.

Create a private VIF to the Management VPC, and peer this VPC to all other VPCs, enable source/destination NAT in the Management VPC.

D.

Create a total of four private VIFs, and enable VPC peering between all VPCs.

Buy Now
Questions 15

A network architect is designing an internet website. It has web, application, and database tiers that will run in AWS. The website uses Amazon DynamoDB.

Which architecture will minimize public exposure of the back-end instances?

Options:

A.

A VPC with public subnets for the NLB, public subnets for the web tier, private subnets for the application tier, and private subnets for DynamoDB.

B.

A VPC with public subnets for the ALB, private subnets for the web tier, and private subnets for the application tier. The application tier connects DynamoDB through a VPC endpoint.

C.

A VPC with public subnets for the ALB, public subnets for the web tier, private subnets for the application tier, and private subnets for DynamoDB.

D.

A VPC with public subnets for the NLB, private subnets for the web tier, and public subnets for the application tier. The application tier connects DynamoDB through a VPC endpoint.

Buy Now
Questions 16

A company uses a newly provisioned 1-Gbps AWS Direct Connect connection to configure a virtual interface for access to Amazon S3

Which configuration values is the network engineer required to provide? (Select TWO.)

Options:

A.

Connection speed

B.

VLAN ID

C.

IP prefixes to advertise

D.

Direct Connect location

E.

Virtual private gateway

Buy Now
Questions 17

You are building an application that provides real-time audio and video services to customers on the Internet. The application requires high throughput. To ensure proper audio and video transmission, minimal latency is required.

Which of the following will improve transmission quality?

Options:

A.

Enable enhanced networking

B.

Select G2 instance types

C.

Enable jumbo frames

D.

Use multiple elastic network interfaces

Buy Now
Questions 18

A company provisions an AWS Direct Connect connection to permit access to Amazon EC2 resources in several Amazon VPCs and to data stored in private Amazon S3 buckets. The Network Engineer needs to configure the company's on-premises router for this Direct Connect connection.

Which of the following actions will require the LEAST amount of configuration overhead on the customer router?

Options:

A.

Configure private virtual interfaces for the VPC resources and for Amazon S3.

B.

Configure private virtual interfaces for the VPC resources and a public virtual interface for Amazon S3.

C.

Configure a private virtual interface to a Direct Connect gateway for the VPC resources and for Amazon S3.

D.

Configure a private virtual interface to a Direct Connect gateway for the VPC resources and a public virtual interface for Amazon S3.

Buy Now
Questions 19

You are deploying an EC2 instance in a private subnet that requires access to the Internet. One of the requirements for this solution is to restrict access to only particular URLs on a whitelist. In addition to the whitelisted URL, the instances should be able to access any Amazon S3 bucket in the same region via any URL.

Which of the following solutions should you deploy? (Select two.)

Options:

A.

Include s3.amazonaws.com in the whitelist.

B.

Create a VPC endpoint for S3.

C.

Run Squid proxy on a NAT instance.

D.

Deploy a NAT gateway into your VPC.

E.

Utilize a security group to restrict access.

Buy Now
Questions 20

You are configuring a virtual interface for access to your VPC on a newly provisioned 1-Gbps AWS Direct Connect connection. Which two configuration values do you need to provide? (Select two.)

Options:

A.

Public AS number

B.

VLAN ID

C.

IP prefixes to advertise

D.

Direct Connect location

E.

Virtual private gateway

Buy Now
Questions 21

You have a global corporate network with 153 individual IP prefixes in your internal routing table. You establish a private virtual interface over AWS Direct Connect to a VPC that has an Internet gateway (IGW). All instances in the VPC must be able to route to the Internet via an IGW and route to the global corporate network via the VGW.

How should you configure your on-premises BGP peer to meet these requirements?

Options:

A.

Configure AS-Prepending on your BGP session

B.

Summarize your prefix announcement to less than 100

C.

Announce a default route to the VPC over the BGP session

D.

Enable route propagation on the VPC route table

Buy Now
Questions 22

Your company has a 1-Gbps AWS Direct Connect connection to AWS. Your company needs to send traffic from on-premises to a VPC owned by a partner company. The connectivity must have minimal latency at the lowest price.

Which of the following connectivity options should you choose?

Options:

A.

Create a new Direct Connect connection, and set up a new circuit to connect to the partner VPC using a private virtual interface.

B.

Create a new Direct Connect connection, and leverage the existing circuit to connect to the partner VPC.

C.

Create a new private virtual interface, and leverage the existing connection to connect to the partner VPC.

D.

Enable VPC peering and use your VPC as a transitive point to reach the partner VPC.

Buy Now
Questions 23

A Network Engineer is troubleshooting a network connectivity issue for an instance within a public subnet that cannot connect to the internet. The first step the Engineer takes is to SSH to the instance via a local bastion within the VPC and runs an ifconfig command to inspect the IP addresses configured on the instance. The output is as follows:

ANS-C00 Question 23

The Engineer notices that the command output does not contain a public IP address. In the AWS Management Console, the public subnet has a route to the internet gateway. The instance also has a public IP address associated with it.

What should the Engineer do next to troubleshoot this situation?

Options:

A.

Configure the public IP on the interface.

B.

Disable source/destination checking for the instance.

C.

Associate an Elastic IP address to the interface.

D.

Evaluate the security groups and the network access control list.

Buy Now
Exam Code: ANS-C00
Exam Name: AWS Certified Advanced Networking Specialty Exam
Last Update: Nov 29, 2023
Questions: 154
dumpsmate guaranteed to pass
24/7 Customer Support

DumpsMate's team of experts is always available to respond your queries on exam preparation. Get professional answers on any topic of the certification syllabus. Our experts will thoroughly satisfy you.

Site Secure

mcafee secure

TESTED 21 Jun 2025