
Simulate the real exam experience with 65 questions and a 170-minute time limit. Practice with AI-verified answers and detailed explanations.
AI-Powered
GPT Pro, Claude Opus, and Gemini Pro cross-check every answer and explanation. See the reasoning for each option, requirement breakdowns, and solution architectures.
A company has two AWS Direct Connect links to its on-premises data center. One Direct Connect link terminates in the us-east-1 Region, and the other Direct Connect link terminates in the af-south-1 Region. The company is using BGP to exchange routes with AWS. The company's on-premises environment needs to be configured to use the us-east-1 link as the primary path to AWS and the af-south-1 link as the secondary (backup) path. A network engineer must configure BGP on the on-premises router to ensure that the us-east-1 link is preferred for all traffic to AWS, and the af-south-1 link is used only if the primary link fails. The solution must use standard BGP attributes and AWS BGP community tags. How should a network engineer configure BGP to ensure that af-south-1 is used as a secondary link to AWS?
Keep your exam routine moving
Get timed mock exams, AI explanations, focused review, and learning insights.
Study period: 2 months
This practice questions help you in understanding the concepts on which you can get the questions in certification exam. Solutions and the explanation is really good. I was able to crack the exam. Thank you.
Study period: 1 month
I reset and completed the roughly 200 questions in the app twice, studying until I fully understood the concepts.
Study period: 2 months
Excellent practice questions. It helped in refreshing a lot a concepts
Study period: 2 months
The questions covered a wide range of patterns, and many similar ones appeared on the actual exam. They helped a lot.
Study period: 3 months
I learned the concepts through Udemy courses and studied the questions and explanations in this app. I also reviewed unfamiliar AWS resources separately. The app was very useful.
Download Cloud Pass and start practicing all AWS Certified Advanced Networking - Specialty (ANS-C01) exam questions.
A company recently implemented a security policy that prohibits developers from launching VPC network infrastructure. The policy states that any time a NAT gateway is launched in a VPC, the company's network security team must immediately receive an alert to terminate the NAT gateway. The network security team needs to implement a solution that can be deployed across AWS accounts with the least possible administrative overhead. The solution also must provide the network security team with a simple way to view compliance history. The solution must be able to detect the creation of a NAT Gateway in any VPC, alert the security team, automatically terminate the resource, and provide a historical record of compliance. The solution must also be easily deployable across multiple AWS accounts with minimal manual effort. Which solution will meet these requirements?
A company is migrating applications from an on-premises data center to AWS, requiring data exchange with an on-premises mainframe. The solution must achieve 4 Gbps transfer speeds for peak traffic and ensure high availability and resiliency against circuit or router failures. Design a highly available, resilient networking solution that supports 4 Gbps and withstands circuit or router failures. Which solution will meet these requirements?
A fintech company has multiple development environments across different AWS accounts, all operating in the us-east-1 Region. These environments host backend services on Amazon EC2 instances within private subnets, which are accessed via a Network Load Balancer (NLB) in a public subnet. For compliance reasons, API access to these services is restricted to a small number of approved third-party vendors. The NLB's security group is configured to only allow inbound TCP traffic on port 443 from a specific set of vendor IP address ranges. The company has a strict policy that whenever a new vendor is onboarded, their IP address range must be added to the NLB's security group in every account. A network engineer must find the most operationally efficient way to centrally manage these vendor IP address ranges across all accounts. The network engineer needs to implement a solution that allows for a single, centralized update of a new vendor's IP address range. This change must then be automatically reflected in the security groups of all relevant accounts without manual intervention in each account. The solution must be highly efficient and scalable. Which solution will meet these requirements in the MOST operationally efficient manner?
A TGW is attached to a DX gateway and 19 VPCs. Two new VPCs (10.0.32.0/21 and 10.0.40.0/21) will be attached. The allowed prefix list has room for only one more entry. Advertise the routes from AWS to on‑premises while staying within the prefix‑list entry limit. What should the engineer do?
A company has a 2 Gbps AWS Direct Connect hosted connection from its office to a VPC in ap-southeast-2 and adds a 5 Gbps hosted connection from a different Direct Connect location in the same Region. The connections terminate at different routers with an iBGP session between them. The network engineer wants the VPC to prioritize the 5 Gbps connection, with failover to the 2 Gbps connection if the 5 Gbps connection fails. Ensure the VPC uses the 5 Gbps Direct Connect connection for traffic to the office, with failover to the 2 Gbps connection when the 5 Gbps connection is down. Which solution will meet these requirements?
An internal website runs behind an internal ALB in a VPC (172.31.0.0/16). A private hosted zone example.com exists in Route 53. An AWS Site-to-Site VPN connects the office network to the VPC. Employees must access https://example.com from the office network. Enable private DNS resolution for example.com from on-premises across the VPN to the VPC’s private hosted zone and ALB. Which combination of steps will meet this requirement? (Choose two.)
An HPC workload needs low‑latency communication with 10 Gbps flows per node and ~100 Gbps aggregate throughput across many Amazon EC2 instances. Design the in‑VPC placement and networking to maximize east‑west performance for the HPC cluster. Which architecture solution will optimize this workload?
Multiple AWS accounts and VPCs in one Region must log all network traffic for EC2 instances and Amazon RDS. Logs will be used for incident investigation, must retain for 12 months, and will be accessed infrequently after 90 days. Required metadata includes vpc-id, subnet-id, and tcp-flags. Provide cost‑optimized network logging with custom fields and long‑term retention. Which solution will meet these requirements at the LOWEST cost?
A media streaming company is deploying a new application on AWS that relies on dynamic multicasting. The application spans five VPCs, all connected to a transit gateway. Amazon EC2 instances in each VPC must dynamically register to receive multicast transmissions. The solution must enable dynamic multicast registration and support multicast traffic across VPCs. How should a network engineer configure the AWS resources to meet these requirements?