Free ANS-C01 Practice Test Questions and Answers (2026) | Cert Empire Practice Questions
Free preview: 20 questions.
Amazon ANS C01
Q: 1
A company's network engineer must implement a cloud-based networking environment for a
network operations team to centrally manage. Other teams will use the environment. Each team
must be able to deploy infrastructure to the environment and must be able to manage its own
resources. The environment must feature IPv4 and IPv6 support and must provide internet
connectivity in a dual-stack configuration.
The company has an organization in AWS Organizations that contains a workload account for the
teams. The network engineer creates a new networking account in the organization.
Which combination of steps should the network engineer take next to meet the requirements?
(Select THREE.)
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 2
A company is migrating an existing application to a new AWS account. The company will deploy the
application in a single AWS Region by using one VPC and multiple Availability Zones. The application
will run on Amazon EC2 instances. Each Availability Zone will have several EC2 instances. The EC2
instances will be deployed in private subnets.
The company's clients will connect to the application by using a web browser with the HTTPS
protocol. Inbound connections must be distributed across the Availability Zones and EC2 instances.
All connections from the same client session must be connected to the same EC2 instance. The
company must provide end-to-end encryption for all connections between the clients and the
application by using the application SSL certificate.
Which solution will meet these requirements?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 3
A company wants to improve visibility into its AWS environment. The AWS environment consists of
multiple VPCs that are connected to a transit gateway. The transit gateway connects to an on-
premises data center through an AWS Direct Connect gateway and a pair of redundant Direct
Connect connections that use transit VIFs. The company must receive notification each time a new
route is advertised to AWS from on premises over Direct Connect.
What should a network engineer do to meet these requirements?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 4
A company has several AWS Site-to-Site VPN connections between an on-premises customer
gateway and a transit gateway. The company's application uses IPv4 to communicate through the
VPN connections.
The company has updated the VPC to be dual stack and wants to transition to using IPv6-only for new
workloads. When the company tries to communicate through the existing VPN connections, IPv6
traffic fails.
Which solution will provide IPv6 support with the LEAST operational overhead?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 5
A company is moving its record-keeping application to the AWS Cloud. All traffic between the
company's on-premises data center and AWS must be encrypted at all times and at every transit
device during the migration.
The application will reside across multiple Availability Zones in a single AWS Region. The application
will use existing 10 Gbps AWS Direct Connect dedicated connections with a MACsec capable port. A
network engineer must ensure that the Direct Connect connection is secured accordingly at every
transit device.
The network engineer creates a Connection Key Name and Connectivity Association Key (CKN/CAK)
pair for the MACsec secret key.
Which combination of additional steps should the network engineer take to meet the requirements?
(Choose two.)
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 6
A company has an application that runs on a fleet of Amazon EC2 instances. A new company
regulation mandates that all network traffic to and from the EC2 instances must be sent to a
centralized third-party EC2 appliance for content inspection.
Which solution will meet these requirements?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 7
A company has critical VPC workloads that connect to an on-premises data center through two
redundant active-passive AWS Direct Connect connections. However, a recent outage on one Direct
Connect connection revealed that it takes more than a minute for traffic to fail over to the secondary
Direct Connect connection. The company wants to reduce the failover time from minutes to seconds.
Which solution will provide the LARGEST reduction in the BGP failover time?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 8
A company is migrating its containerized application to AWS. For the architecture the company will
have an ingress VPC with a Network Load Balancer (NLB) to distribute the traffic to front-end pods in
an Amazon Elastic Kubernetes Service (Amazon EKS) cluster. The front end of the application will
determine which user is requesting access and will send traffic to 1 of 10 services VPCs. Each services
VPC will include an NLB that distributes traffic to the services pods in an EKS cluster.
The company is concerned about overall cost. User traffic will be responsible for more than 10 TB of
data transfer from the ingress VPC to services VPCs every month. A network engineer needs to
recommend how to design the communication between the VPCs.
Which solution will meet these requirements at the LOWEST cost?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 9
A team of infrastructure engineers wants to automate the deployment of Application Load Balancer
(ALB) components by using the AWS Cloud Development Kit (AWS CDK). The CDK application must
deploy an infrastructure stack that is reusable and consistent across multiple environments, AWS
Regions, and AWS accounts.
The lead network architect on the project has already bootstrapped the target accounts. The lead
network architect also has deployed core network components such as VPCs and Amazon Route 53
private hosted zones across the multiple environments and Regions. The infrastructure engineers
must design the ALB components in the CDK application to use the existing core network
components.
Which combination of steps will meet this requirement with the LEAST manual effort between
environment deployments? (Choose two.)
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 10
A company hosts a web application that runs on a fleet of Amazon EC2 instances behind an
Application Load Balancer (ALB). The instances are in an Auto Scaling group. The company uses an
Amazon CloudFront distribution with the ALB as an origin.
The application recently experienced an attack. In response, the company associated an AWS WAF
web ACL with the CloudFront distribution. The company needs to use Amazon Athena to analyze
application attacks that AWS WAF detects.
Which solution will meet this requirement?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 11
A company has an AWS account with four VPCs in the us-east-1 Region. The VPCs consist of a
development VPC and three production VPCs that host various workloads.
The company has extended its on-premises data center to AWS with AWS Direct Connect by using a
Direct Connect gateway. The company now wants to establish connectivity to its production VPCs and
development VPC from on premises. The production VPCs are allowed to route data to each other.
However, the development VPC must be isolated from the production VPCs. No data can flow
between the development VPC and the production VPCs.
In preparation to implement this solution, a network engineer creates a transit gateway with a single
transit gateway route table. Default route table association and default route table propagation are
turned off. The network engineer attaches the production VPCs. the development VPC. and the
Direct Connect gateway to the transit gateway. For each VPC route table, the network engineer adds
a route to 0.0.0.0/0 with the transit gateway as the next destination.
Which combination of steps should the network engineer take next to complete this solution? (Select
THREE.)
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 12
A financial company that is located in the us-east-1 Region needs to establish secure connectivity to
AWS. The company has two on-premises data centers, each located within the same Region. The
company's network team needs to establish hybrid connectivity to its AWS environment with reliable
and consistent connectivity.
The connection must provide access to the company's private resources inside its AWS environment.
The resources are located in the us-east-1 and us-west-2 Regions. The connection must allow
resources from the corporate networks to send large amounts of data to Amazon S3 over the same
connection. To meet compliance requirements, the connection must be highly available and must
provide encryption for all packets that are sent between the on-premises location and any services
on AWS.
Which combination of steps should the network team take to meet these requirements? (Choose
two.)
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 13
A software-as-a-service (SaaS) company is migrating its private SaaS application to AWS. The
company has hundreds of customers that connect to multiple data centers by using VPN tunnels. As
the number of customers has grown, the company has experienced more difficulty in its effort to
manage routing and segmentation of customers with complex NAT rules.
After the migration to AWS is complete, the company's AWS customers must be able to access the
SaaS application directly from their VPCs. Meanwhile, the company's on-premises customers still
must be able to connect through IPsec encrypted tunnels.
Which solution will meet these requirements?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 14
A company recently experienced an IP address exhaustion event in its VPCs. The event affected
service capacity. The VPCs hold two or more subnets in different Availability Zones.
A network engineer needs to develop a solution that monitors IP address usage across resources in
the VPCs. The company needs to receive notification about possible issues so that the company can
act before an incident happens.
Which solution will meet these requirements with the LEAST operational overhead?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 15
A company's security guidelines state that all outbound traffic from a VPC to the company's on-
premises data center must pass through a security appliance. The security appliance runs on an
Amazon EC2 instance. A network engineer needs to improve the network performance between the
on-premises data center and the security appliance.
Which actions should the network engineer take to meet these requirements? (Choose two.)
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 16
A company has agreed to collaborate with a partner for a research project. The company has multiple
VPCs in the us-east-1 Region that use CIDR blocks within 10.10.0.0/16. The VPCs are connected by a
transit gateway that is named TGW-C in us-east-1. TGW-C has an Autonomous System Number (ASN)
configuration value of 64520.
The partner has multiple VPCs in us-east-1 that use CIDR blocks within 172.16.0.0/16. The VPCs are
connected by a transit gateway that is named TGW-P in us-east-1. TGW-P has an ASN configuration
value of 64530.
A network engineer needs to establish network connectivity between the company's VPCs and the
partner's VPCs in us-east-1.
Which solution will meet these requirements with MINIMUM changes to both networks?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 17
A company is running an online game on AWS. The game is played globally and is gaining popularity.
Users are reporting problems with the game's responsiveness. Replay rates are dropping, and the
company is losing subscribers. Game servers are located in the us-west-2 Region and use an Elastic
Load Balancer to distribute client traffic.
The company has decided to deploy game servers to 11 additional AWS Regions to reduce the round-
trip times of network traffic to game clients. A network engineer must design a DNS solution that
uses Amazon Route 53 to ensure that user traffic is delivered to game servers with an optimal
response time.
What should the network engineer do to meet these requirements?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 18
A company's application is deployed on Amazon EC2 instances in a single VPC in an AWS Region. The
EC2 instances are running in two Availability Zones. The company decides to use a fleet of traffic
inspection instances from AWS Marketplace to inspect traffic between the VPC and the internet. The
company is performing tests before the company deploys the architecture into production.
The fleet is located in a shared inspection VPC behind a Gateway Load Balancer (GWLB). To minimize
the cost of the solution, the company deployed only one inspection instance in each Availability Zone
that the application uses.
During tests, a network engineer notices that traffic inspection works as expected when the network
is stable. However, during maintenance of the inspection instances, the internet sessions time out for
some application instances. The application instances are not able to establish new sessions.
Which combination of steps will remediate these issues? (Choose two.)
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 19
A network engineer is designing hybrid connectivity with AWS Direct Connect and AWS Transit
Gateway. A transit gateway is attached to a Direct Connect gateway and 19 VPCs across different AWS
accounts. Two new VPCs are being attached to the transit gateway. The IP address administrator has
assigned 10.0.32.0/21 to the first VPC and 10.0.40.0/21 to the second VPC. The prefix list has one
CIDR block remaining before the prefix list reaches the quota for the maximum number of entries.
What should the network engineer do to advertise the routes from AWS to on premises to meet
these requirements?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 20
A company needs to temporarily scale out capacity for an on-premises application and wants to
deploy new servers on Amazon EC2 instances. A network engineer must design the networking
solution for the connectivity and for the application on AWS.
The EC2 instances need to share data with the existing servers in the on-premises data center. The
servers must not be accessible from the internet. All traffic to the internet must route through the
firewall in the on-premises data center. The servers must be able to access a third-party web
application.
Which configuration will meet these requirements?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Question 1 of 20