// amazon · ans-c01
amazon

// aws certified advanced networking - specialty ans-c01

ANS-C01

Master complex AWS networking architectures with expert-led ANS-C01 practice questions and deep-dive technical explanations for cloud engineers.

272
questions
65
in exam
170m
duration
Choose your mode
at a glance

What you get

PDF US$331Sub US$30/mopass 750 (scaled 100–1000)

Free practice questions are available without payment; anyone can start practicing at no cost.

access options

PDF bank or platform subscription?

Two separate purchases: a one-time PDF for ANS-C01, or a monthly subscription for online practice and simulators across the platform. A subscription does not include the PDF download.

option / 01 · pdf file

Full question bank PDF

US$331· one-time
  • Full question bank as a print-ready PDF
  • Lifetime access to this exam only
  • Domain-tagged questions with explanations
  • Separate from online practice — buy once

option / 02 · subscription

All exams · practice & simulator

US$29.99· per month
  • Practice & exam simulator on every bank
  • All current and future exams included
  • Personal analytics and retention tools
  • Cancel anytime — no per-exam upsells
Subscribe for platform access
sample · 1 of 272Shuffle

See what's in the bank.

multiNetwork Designmedium

15 votes · last validated recently

A company has started using AWS Cloud WAN with one edge location in the us-east-1 Region. The company has a production segment and a security segment in AWS Cloud WAN. The company also has a default core network policy.

The company has created a production VPC for the production workload. The company has created an outbound inspection VPC to inspect internet-bound traffic from the production VPC. The company has attached the production VPC to the production segment and has attached the outbound inspection VPC to the security segment. The company has also created an AWS Network Firewall firewall in the outbound inspection VPC to inspect internet-based traffic.

The company has updated a route table for the production VPC to send all internet-bound traffic to the AWS Cloud WAN core network. The company has updated a route table for the outbound inspection VPC to ensure that Network Firewall inspects any outgoing traffic and incoming traffic.

During testing, an Amazon EC2 instance in the production VPC cannot reach the internet. The company checks the Network Firewall rules and confirms that the rules are not blocking the traffic.

Which combination of steps will meet these requirements? (Choose two.)
A
Update the core network policy to configure segment sharing. Share the production segment with the security segment.
100%
B
Update the core network policy to create a static route for the security segment. Specify 0.0.0.0/0 as the destination CIDR block. Specify the outbound inspection VPC as an attachment.
20%
C
Update the core network policy to create a static route for the production segment. Specify 0.0.0.0/0 as the destination CIDR block. Specify the outbound inspection VPC as an attachment.
80%
D
Update the core network policy to create a static route for the production segment. Specify 10.2.0.0/16 as the destination CIDR block. Specify the outbound inspection VPC as an attachment.
0%
next →
04 · coverage

Exam domains

Network Design30%
71 q
Network Implementation26%
93 q
Network Management and Operation20%
67 q
Network Security, Compliance, and Governance24%
41 q
community questionsview all →

Questions from the community

Top-voted approved contributions for this exam, reviewed before landing in the bank.

// top community questionsview all →
0.0 · 0 reviews

What candidates say

no reviews yet

related

You may also like

More exams based on your interests.

Loading...

272 questions

PDF US$331 one-time·Sub US$30/mo

Practice