ANS-C01 Sample Questions & Answers
Designing edge services, DNS and load balancing carries the top share, just ahead of security, compliance and governance, then connecting multiple accounts and hybrid networks, and managing and optimizing network performance day to day.
Launch the full ANS-C01 simulator →Showing 8 of 17 free samples.
- Question 1Intermediate
A company uses a 4 Gbps AWS Direct Connect dedicated connection with a link aggregation group (LAG) bundle to connect to five VPCs that are deployed in the us-east-1 Region. Each VPC serves a different business unit and uses its own private VIF for connectivity to the on-premises environment. Users are reporting slowness when they access resources that are hosted on AWS.A network engineer finds that there are sudden increases in throughput and that the Direct Connect connection becomes saturated at the same time for about an hour each business day. The company wants to know which business unit is causing the sudden increase in throughput. The network engineer must find out this information and implement a solution to resolve the problem.Which solution will meet these requirements?
Show answer & explanation
Correct answer: A
- Question 2IntermediateSelect 2
A software-as-a-service (SaaS) provider hosts its solution on Amazon EC2 instances within a VPC in the AWS Cloud. All of the provider's customers also have their environments in the AWS Cloud.A recent design meeting revealed that the customers have IP address overlap with the provider's AWS deployment. The customers have stated that they will not share their internal IP addresses and that they do not want to connect to the provider's SaaS service over the internet.Which combination of steps is part of a solution that meets these requirements? (Choose two.)
Show answer & explanation
Correct answers: A, B
- Question 3IntermediateSelect 3
A network engineer is designing the architecture for a healthcare company's workload that is moving to the AWS Cloud. All data to and from the on-premises environment must be encrypted in transit. All traffic also must be inspected in the cloud before the traffic is allowed to leave the cloud and travel to the on-premises environment or to the internet.The company will expose components of the workload to the internet so that patients can reserve appointments. The architecture must secure these components and protect them against DDoS attacks. The architecture also must provide protection against financial liability for services that scale out during a DDoS event.Which combination of steps should the network engineer take to meet all these requirements for the workload? (Choose three.)
Show answer & explanation
Correct answers: D, E, F
- Question 4IntermediateSelect 2
A retail company is running its service on AWS. The company’s architecture includes Application Load Balancers (ALBs) in public subnets. The ALB target groups are configured to send traffic to backend Amazon EC2 instances in private subnets. These backend EC2 instances can call externally hosted services over the internet by using a NAT gateway.The company has noticed in its billing that NAT gateway usage has increased significantly. A network engineer needs to find out the source of this increased usage.Which options can the network engineer use to investigate the traffic through the NAT gateway? (Choose two.)
Show answer & explanation
Correct answers: A, D
- Question 5IntermediateSelect 4
A banking company is successfully operating its public mobile banking stack on AWS. The mobile banking stack is deployed in a VPC that includes private subnets and public subnets. The company is using IPv4 networking and has not deployed or supported IPv6 in the environment. The company has decided to adopt a third-party service provider's API and must integrate the API with the existing environment. The service provider’s API requires the use of IPv6.A network engineer must turn on IPv6 connectivity for the existing workload that is deployed in a private subnet. The company does not want to permit IPv6 traffic from the public internet and mandates that the company's servers must initiate all IPv6 connectivity. The network engineer turns on IPv6 in the VPC and in the private subnets.Which solution will meet these requirements?
Show answer & explanation
Correct answers: B, D, E, G
- Question 6Intermediate
A company has deployed an AWS Network Firewall firewall into a VPC. A network engineer needs to implement a solution to deliver Network Firewall flow logs to the company’s Amazon OpenSearch Service (Amazon Elasticsearch Service) cluster in the shortest possible time.Which solution will meet these requirements?
Show answer & explanation
Correct answer: C
- Question 7Advanced
Network Design · Design a routing strategy and connectivity architecture between on-premises networks and the AWS Cloud
A multinational financial corporation is designing a high-frequency trading platform on AWS. The architecture requires a multicast-enabled network to distribute market data feeds to hundreds of subscriber EC2 instances across multiple Availability Zones in the us-east-1 Region. The source of the multicast stream is an on-premises feed connected via AWS Direct Connect. The solution must support IGMPv3 and minimize administrative overhead. Which architecture meets these requirements?
Show answer & explanation
Correct answer: C
AWS Transit Gateway supports multicast, but native Direct Connect attachments do not directly support multicast ingress. To ingest multicast from on-premises, you must use a Transit Gateway Connect attachment (GRE) over the Direct Connect transport. The Connect attachment can be associated with the multicast domain, allowing the multicast source to be on-premises.
- Question 8Intermediate
Network Management and Operation · Troubleshoot connectivity issues that are caused by network misconfiguration
A network engineer is troubleshooting a connectivity issue between an EC2 instance in a private subnet and an Amazon S3 bucket. The VPC has a Gateway VPC Endpoint for S3 configured. The route table associated with the subnet has a route to the Gateway Endpoint (pl-xxxxxxxx). However, the application on the EC2 instance times out when attempting to download an object. The Network ACLs allow all traffic. Which of the following is the MOST likely cause of the issue?
Show answer & explanation
Correct answer: C
Even with a Gateway Endpoint and correct routing, Security Groups are stateful and must explicitly allow outbound traffic. If the outbound rules restrict traffic (e.g., only allowing internal VPC CIDR), traffic to the S3 public IP ranges (represented by the prefix list) will be dropped. The destination in the security group rule must be the S3 prefix list ID.
Ready for the real thing?
The full ANS-C01 simulator has every exam-style question, timed mode, and instant scoring.