ANS-C01 Practice Exam: AWS Certified Advanced Networking - Specialty
VPCs, Transit Gateway, Direct Connect, DNS, hybrid pain — the hardest acronym soup AWS offers.
What you'll be tested on
- Network Design
- Network Implementation
- Network Management and Operation
- Network Security
Sample ANS-C01 questions
A company is planning to create a service that requires encryption in transit. The traffic must not be decrypted between the client and the backend of the service. The company will implement the service by using the gRPC protocol over TCP port 443. The service will scale up to thousands of simultaneous connections. The backend of the service will be hosted on an Amazon Elastic Kubernetes Service (Amazon EKS) duster with the Kubernetes Cluster Autoscaler and the Horizontal Pod Autoscaler configured. The company needs to use mutual TLS for two-way authentication between the client and the backend. Which solution will meet these requirements?
- Install the AWS Load Balancer Controller for Kubernetes. Using that controller, configure a Network Load Balancer with a TCP listener on port 443 to forward traffic to the IP addresses of the backend service Pods.
- Install the AWS Load Balancer Controller for Kubernetes. Using that controller, configure an Application Load Balancer with an HTTPS listener on port 443 to forward traffic to the IP addresses of the backend service Pods.
- Create a target group. Add the EKS managed node group's Auto Scaling group as a target Create an Application Load Balancer with an HTTPS listener on port 443 to forward traffic to the target group.
- Create a target group. Add the EKS managed node group’s Auto Scaling group as a target. Create a Network Load Balancer with a TLS listener on port 443 to forward traffic to the target group.
Show answer
A — Install the AWS Load Balancer Controller for Kubernetes. Using that controller, configure a Network Load Balancer with a TCP listener on port 443 to forward traffic to the IP addresses of the backend service Pods.Mutual TLS requires end-to-end encryption with no decryption between client and backend, so the load balancer must pass TLS through untouched. A Network Load Balancer with a TCP listener on port 443 operates at layer 4 and forwards the encrypted stream directly to the pod IPs, and the AWS Load Balancer Controller keeps targets in sync as the Cluster Autoscaler and Horizontal Pod Autoscaler scale pods. An Application Load Balancer HTTPS listener terminates TLS, breaking mTLS and end-to-end encryption, so B and C fail. D uses an NLB TLS listener, which also terminates TLS at the load balancer and does not support mutual TLS passthrough.
A company is deploying a new application in the AWS Cloud. The company wants a highly available web server that will sit behind an Elastic Load Balancer. The load balancer will route requests to multiple target groups based on the URL in the request. All traffic must use HTTPS. TLS processing must be offloaded to the load balancer. The web server must know the user’s IP address so that the company can keep accurate logs for security purposes. Which solution will meet these requirements?
- Deploy an Application Load Balancer with an HTTPS listener. Use path-based routing rules to forward the traffic to the correct target group. Include the X-Forwarded-For request header with traffic to the targets.
- Deploy an Application Load Balancer with an HTTPS listener for each domain. Use host-based routing rules to forward the traffic to the correct target group for each domain. Include the X-Forwarded-For request header with traffic to the targets.
- Deploy a Network Load Balancer with a TLS listener. Use path-based routing rules to forward the traffic to the correct target group. Configure client IP address preservation for traffic to the targets.
- Deploy a Network Load Balancer with a TLS listener for each domain. Use host-based routing rules to forward the traffic to the correct target group for each domain. Configure client IP address preservation for traffic to the targets.
Show answer
A — Deploy an Application Load Balancer with an HTTPS listener. Use path-based routing rules to forward the traffic to the correct target group. Include the X-Forwarded-For request header with traffic to the targets.Routing based on the URL is a layer 7 feature that only an Application Load Balancer supports, using path-based rules. An HTTPS listener on the ALB terminates TLS, offloading TLS processing as required. The ALB automatically adds the X-Forwarded-For header, preserving the client's IP address for the web server logs. Option B adds a separate listener per domain, which is unnecessary because a single ALB supports multiple certificates via SNI. Options C and D use a Network Load Balancer, which operates at layer 4 and cannot perform path-based or host-based routing, so they cannot route requests to multiple target groups by URL.
A company has developed an application on AWS that will track inventory levels of vending machines and initiate the restocking process automatically. The company plans to integrate this application with vending machines and deploy the vending machines in several markets around the world. The application resides in a VPC in the us-east-1 Region. The application consists of an Amazon Elastic Container Service (Amazon ECS) cluster behind an Application Load Balancer (ALB). The communication from the vending machines to the application happens over HTTPS. The company is planning to use an AWS Global Accelerator accelerator and configure static IP addresses of the accelerator in the vending machines for application endpoint access. The application must be accessible only through the accelerator and not through a direct connection over the internet to the ALB endpoint. Which solution will meet these requirements?
- Configure the ALB in a private subnet of the VPC. Attach an internet gateway without adding routes in the subnet route tables to point to the internet gateway. Configure the accelerator with endpoint groups that include the ALB endpoint. Configure the ALB’s security group to only allow inbound traffic from the internet on the ALB listener port.
- Configure the ALB in a private subnet of the VPC. Configure the accelerator with endpoint groups that include the ALB endpoint. Configure the ALB's security group to only allow inbound traffic from the internet on the ALB listener port.
- Configure the ALB in a public subnet of the VPAttach an internet gateway. Add routes in the subnet route tables to point to the internet gateway. Configure the accelerator with endpoint groups that include the ALB endpoint. Configure the ALB's security group to only allow inbound traffic from the accelerator's IP addresses on the ALB listener port.
- Configure the ALB in a private subnet of the VPC. Attach an internet gateway. Add routes in the subnet route tables to point to the internet gateway. Configure the accelerator with endpoint groups that include the ALB endpoint. Configure the ALB's security group to only allow inbound traffic from the accelerator's IP addresses on the ALB listener port.
Show answer
A — Configure the ALB in a private subnet of the VPC. Attach an internet gateway without adding routes in the subnet route tables to point to the internet gateway. Configure the accelerator with endpoint groups that include the ALB endpoint. Configure the ALB’s security group to only allow inbound traffic from the internet on the ALB listener port.For AWS Global Accelerator to front an internal Application Load Balancer, the ALB must sit in private subnets and the VPC must have an internet gateway attached, even though the private subnet route tables never route to it. Because the ALB has no public route, clients cannot reach it directly over the internet; they can only reach it through the accelerator's static IPs. The security group must allow inbound traffic on the listener port so accelerator traffic can pass. Option B omits the required attached internet gateway. Options C and D either place the ALB in public subnets or add routes to the gateway, both of which expose the ALB directly, and filtering by accelerator IPs is not feasible.
Access plans
| Access | Price |
|---|---|
| 3 months | |
| 1 year | |
| Lifetime |
Free preview inside — try 5 questions before you pay anything.
FAQ
How many practice questions are in this ANS-C01 bank?
306 questions covering the current ANS-C01 AWS Certified Advanced Networking - Specialty syllabus, every one with the correct answer and an explanation.How long is the real ANS-C01 exam?
The official ANS-C01 exam gives you 170 minutes. Our timed exam mode uses the same limit so the pace feels familiar.What does ANS-C01 access cost?
Plans start at $3.99 for 3 months. One payment, no subscription — and far cheaper than retaking the real exam.