ANS-C00 Exam Details

  • Exam Code
    :ANS-C00
  • Exam Name
    :AWS Certified Advanced Networking - Specialty (ANS-C00)
  • Certification
    :Amazon Certifications
  • Vendor
    :Amazon
  • Total Questions
    :414 Q&As
  • Last Updated
    :May 30, 2026

Amazon ANS-C00 Online Questions & Answers

  • Question 131:

    From the following options, select the answer that correctly describes the implementation of the HTTP protocol

    A. By definition, HTTP is a connection-less oriented protocol and therefore utilises TCP
    B. By definition, HTTP is a connection orientated protocol and therefore utilises TCP
    C. By definition, HTTP is a connection-less oriented protocol and therefore utilises UDP
    D. By definition, HTTP can be configured to be either connection or connection-less oriented - by specifying the appropriate HTTP header.

  • Question 132:

    A network engineer must provide additional safeguards to protect encrypted data at Application Load Balancers (ALBs) through the use of a unique random session key. What should the network engineer do to meet this requirement?

    A. Change the ALB security policy to a policy that supports TLS 1.2 protocol only.
    B. Use AWS Key Management Service (AWS KMS) to encrypt session keys.
    C. Associate an AWS WAF web ACL with the ALBs, and create a security rule to enforce forward secrecy (FS).
    D. Change the ALB security policy to a policy that supports forward secrecy (FS).

  • Question 133:

    Accompany has a public domain, company.com, that is hosted by a DNS provider. The company creates a public hosted zone, cloud.company.com, in Amazon Route 53. The company wants to keep all public AWS application DNS records

    under this hosted zone.

    The company recently deployed its first public application behind an Elastic Load Balancer in its AWS environment. The domain name app1.cloud.company.com needs to access the application.

    Which solution will meet these requirements?

    A. On the DNS provider, create A records for cloud under company.com. Point these records to Route 53 name server IP addresses of the public hosted zone. In Route 53, create an ALIAS (A) record for app1 under cloud.company.com. Point this record to the Elastic Load Balancer.
    B. On the DNS provider, create a subdomain for cloud under company.com. Create a CNAME record for app1 under cloud.company.com. Point this record to the Elastic Load Balancer public DNS name. In Route 53, create NS records for cloud.company.com. Point these records to the DNS provider name servers.
    C. On the DNS provider, create NS records for cloud under company.com. Point these records to Route 53 name servers of the public hosted zone. In Route 53, create an ALIAS (A) record for app1 under cloud.company.com. Point this record to the Elastic Load Balancer.
    D. On the DNS provider, create a subdomain for cloud under company.com. Create a CNAME record for app1 under cloud.company.com. Point this record to the Elastic Load Balancer public DNS name. In Route 53, create A records for cloud.company.com. Point these records to the DNS provider name servers.

  • Question 134:

    Fill in the blanks: One of the basic characteristics of security groups for your VPC is that you ______ .

    A. can specify allow rules, but not deny rules
    B. can specify deny rules, but not allow rules
    C. can specify allow rules as well as deny rules
    D. can neither specify allow rules nor deny rules

  • Question 135:

    Your organization has placed a project on hold and has stopped 30 public EC2 instances. These instances use instance store volumes and do not have custom AMIs associated. You are still being charged every month. What is the charge probably for?

    A. AWS charges for dormant accounts.
    B. You have Elastic IPs associated with those instances.
    C. There is a "stopped instance" fee that AWS charges every month.
    D. You are being charged for the EBS volumes.

  • Question 136:

    A Network Engineer needs to create a public virtual interface on the company's AWS Direct Connect connection and only import routes which originated from the same region as the Direct Connect location. What action should accomplish this?

    A. Configure a prefix list on the customer router containing the AWS IP address ranges for the specific region.
    B. Configure a filter on the company's router to only import routes with the 7224:8100 BGP community attribute.
    C. Configure a filter on the company's router to only import routes without a BGP community attribute and a maximum path length of 3.
    D. Configure a filter in the console and only allow routes advertised by AWS without a BGP community attribute and a maximum path length of 3.

  • Question 137:

    Which of the following statements does not describe Jumbo Frames in an AWS VPC environment?

    A. For instances that are collocated inside a placement group, jumbo frames help to achieve the maximum network throughput possible
    B. Jumbo Frames are not supported for traffic that exits the Virtual Private Gateway
    C. Jumbo Frames are not supported for traffic that exits the Internet Gateway
    D. T2.micro instances do not support Jumbo Frames

  • Question 138:

    What service is used to store the log files generated by CloudTrail?

    A. EC2
    B. EBS
    C. S3
    D. VPC

  • Question 139:

    You have a web application (app.mycompany.com) running on an EC2 instance with a single elastic network interface in a subnet in a VPC. Because of a network redesign, you need to move the web application to a different subnet in the same Availability Zone.

    Which of the following migration strategies meets the requirements?

    A. Create an elastic network interface in the new subnet. Attach this interface to the instance, and detach the old interface.
    B. Launch a new instance in the subnet via an AMI created from the instance, and redirect new connections to this new instance using DNS. Decommission the old instance.
    C. Make an API call to change the subnet association of the elastic network interface.
    D. Change the IP addresses manually to another subnet within the server operating system.

  • Question 140:

    Which endpoint is considered to be best practice when analyzing data within a Configuration Stream of AWS Config?

    A. SNS
    B. E-Mail
    C. SQS
    D. Kinesis

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only Amazon exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your ANS-C00 exam preparations and Amazon certification application, do not hesitate to visit our Vcedump.com to find your solutions here.