Skip to content

AWS Certified Advanced Networking - Specialty

Here you have the best Amazon ANS-C00 practice exam questions

  • Preview the first 5 of 377 questions for free
  • These questions were last updated on May 15, 2026
  • This site is not affiliated with or endorsed by Amazon.
Question 1 of 377

Your organization's corporate website must be available on www.acme.com and acme.com.

How should you configure Amazon Route 53 to meet this requirement?

Answer

Suggested Answer

The suggested answer is A.

To ensure the corporate website is available on both www.acme.com and acme.com, you should configure acme.com with an ALIAS record targeting the Elastic Load Balancer (ELB) and www.acme.com also with an ALIAS record targeting the ELB. This configuration takes advantage of the ALIAS record's ability to point to AWS resources, which includes ELBs, while ensuring the root domain and subdomain both route traffic correctly. An ALIAS record can be used at the zone apex (acme.com), which cannot be done with a CNAME record.

Community Votes4 votes
ASuggested
100%
Question 2 of 377

You are building an application in AWS that requires Amazon Elastic MapReduce (Amazon EMR). The application needs to resolve hostnames in your internal, on-premises Active Directory domain. You update your DHCP Options Set in the VPC to point to a pair of Active Directory integrated DNS servers running in your

VPC.

Which action is required to support a successful Amazon EMR cluster launch?

Answer

Suggested Answer

The suggested answer is A.

For successful Amazon EMR cluster launch, it's crucial that the instances within the cluster can resolve not only their internal hostnames but also AWS service endpoints. The application points to Active Directory integrated DNS servers in the VPC for internal domain resolution. However, to ensure AWS service endpoints can still be resolved, adding a conditional forwarder to the Amazon-provided DNS server is necessary. This forwarder will direct the DNS queries for the AWS-specific domains to the Amazon DNS server, facilitating proper DNS resolution for AWS services.

Community Votes3 votes
ASuggested
100%
Question 3 of 377

You have a three-tier web application with separate subnets for Web, Applications, and Database tiers. Your CISO suspects your application will be the target of malicious activity. You are tasked with notifying the security team in the event your application is port scanned by external systems.

Which two AWS Services cloud you leverage to build an automated notification system? (Choose two.)

Answer

Suggested Answer

The suggested answer is B, D.

To build an automated notification system for detecting external port scans on your application within a three-tier web architecture, you should use VPC Flow Logs and AWS Lambda. VPC Flow Logs can capture detailed information about IP traffic reaching your network interfaces, including any suspicious port scan activities. AWS Lambda can then be used to automate the detection and notification process by analyzing the flow log data and triggering alerts to the security team when a port scan is identified. AWS CloudTrail, while useful for auditing AWS account activity, does not directly detect port scans. Similarly, AWS Inspector focuses on vulnerability assessments rather than real-time monitoring for port scans, and an Internet gateway is not relevant for such monitoring tasks.

Community Votes10 votes
BDSuggested
90%
AE
10%
Question 4 of 377

You are designing the network infrastructure for an application server in Amazon VPC. Users will access all the application instances from the Internet and from an on-premises network. The on-premises network is connected to your VPC over an AWS Direct Connect link.

How should you design routing to meet these requirements?

Answer

Suggested Answer

The suggested answer is D.

To ensure users can access the application instances both from the Internet and from an on-premises network connected via AWS Direct Connect, you should configure a single routing table with a default route via the Internet Gateway (IGW) for internet-bound traffic. Specific routes for the on-premises network should be propagated via BGP on the AWS Direct Connect customer router to ensure proper routing. This setup allows the VPC to handle both types of traffic correctly and scales well with the network requirements.

Community Votes3 votes
DSuggested
100%
Question 5 of 377

Your company decides to use Amazon S3 to augment its on-premises data store. Instead of using the company's highly controlled, on-premises Internet gateway, a Direct Connect connection is ordered to provide high bandwidth, low latency access to S3. Since the company does not own a publically routable IPv4 address block, a request was made to AWS for an AWS-owned address for a Public Virtual Interface (VIF).

The security team is calling this new connection a `backdoor`, and you have been asked to clarify the risk to the company.Which concern from the security team is valid and should be addressed?

Answer

Suggested Answer

The suggested answer is C.

The valid concern that should be addressed is that EC2 instances in the same region with access to the Internet could directly reach the router. It is crucial to understand that once AWS receives a BGP announcement from a customer, all network traffic from AWS destined to the announced prefix will be routed via AWS Direct Connect. This includes traffic from other AWS customers using public or Elastic IP addresses on their Amazon EC2 instances, traffic routed via NAT gateways, AWS Lambda functions making outbound connections, and more. Proper configuration of routers and firewalls is required to manage this traffic according to the company's routing policies.

Community Votes2 votes
AMost voted
50%
CSuggested
50%

372 more questions await

Unlock the full Amazon ANS-C00 question bank

5 of 377 completed1%

Choose your plan

One-time payment · No subscription · No hidden fees

Standard

Quick preparation

$25

30 days access

30 day access to all questions
Instant free updates
Highest passing rate in industry
Printable PDF download
No money-back guarantee
Best Value

Premium

Guaranteed success

$60$35

90 days access

PDF

Printable PDF download

New

Save every question as a PDF for offline study or printing.

90 day access to all questions
Instant free updates
Highest passing rate in industry
Pass guaranteed or money back

100% Money-Back Guarantee

Don't pass? Full refund.

4.9/5

Based on 4,868+ reviews

Trusted by thousands of professionals

Join certified professionals who passed their exams with Examice

Examice helped me pass my AWS certification on the first try! The questions were incredibly similar to the real exam. Comments helped me understand answers I was struggling with.
S
Sarah C.
Cloud Engineer
Great results in a short prep time. Passed on my first attempt.
D
David K.
Network Engineer
I needed to pass an exam for work, and this website delivered. The quality for the price is outstanding, and the support is really good. I passed without issues.
M
Michael R.
Security Analyst
Skeptical at first, but impressed. Every question included clear, detailed explanations.
L
Lisa M.
Solutions Architect
The guarantee gave me confidence to invest in the premium package. Turns out I didn't need it. Passed comfortably. The explanations for each answer were incredibly detailed and helped me grasp security concepts that I'd been struggling with for months.
R
Robert H.
Cybersecurity Consultant
Used Examice for my PMP certification. The questions were well structured and covered all exam domains thoroughly.
J
James T.
IT Manager
After failing my first attempt with other study materials, I switched to Examice and passed confidently on my second attempt.
A
Anna W.
Data Engineer
The premium package was worth it. 90 days of access gave me the flexibility to study when it worked for me, without feeling rushed.
E
Emily J.
DevOps Engineer
Straightforward questions that matched the real exam perfectly. Studied for two weeks and passed with a great score.
K
Karen P.
Systems Administrator

Frequently Asked Questions

Everything you need to know. Contact us for more.

Our Amazon ANS-C00 questions are based on real exam experiences and are continuously updated to match the current exam format. We maintain a +99% pass rate because our questions closely mirror what you'll see on the actual exam.

With our Premium package, you get a 100% money-back guarantee. If you don't pass your exam after studying with our materials, simply contact us with your exam results and we'll refund your purchase. Terms and conditions apply, read our full refund policy to learn more.

Our question bank is updated regularly based on feedback from recent exam takers. We typically review and update our content every week with reports about new questions or changes to the exam format.

Standard package access cannot be extended. However, Premium package gives you 90 days which is typically more than enough time to prepare thoroughly. If you need additional time, you can purchase a new package at any time.

This is a one-time payment with no recurring charges. Once you purchase, you get full access to all exam questions for the duration of your package (30 days for Standard, 90 days for Premium). No hidden fees or automatic renewals.

Pass on your first try

All 377questions · Detailed explanations · Printable PDF · 90 days access

Money-back guaranteeSecure checkout
$35

one-time payment