ANS-C00 Exam Details

  • Exam Code
    :ANS-C00
  • Exam Name
    :AWS Certified Advanced Networking - Specialty (ANS-C00)
  • Certification
    :Amazon Certifications
  • Vendor
    :Amazon
  • Total Questions
    :414 Q&As
  • Last Updated
    :May 30, 2026

Amazon ANS-C00 Online Questions & Answers

  • Question 191:

    If you have one VPC peered with two VPCs with overlapping CIDRs, which route will be more preferred?

    A. 10.1.0.0/16
    B. 10.0.0.0/8
    C. 10.1.1.5/32
    D. 10.1.1.0/24

  • Question 192:

    You have a website hosted on EC2 that is not serving web pages. You have ensured that the server is running and the site is configured properly. What could be the problem?

    A. Your NACL does not allow port 80 outbound.
    B. Your NACL does not allow ports 1024 - 65535 outbound.
    C. Your NACL does not allow ports 1024 - 65535 inbound. D. Your security group does not allow outbound traffic.

  • Question 193:

    Which two methods can be used to ensure items are distributed only to the correct parties? (Choose two.)

    A. Signed URLs
    B. Signed cookies
    C. Signed biscuits
    D. Signed SSLs

  • Question 194:

    You have created a custom VPC. What are two things you may need to do in order to SSH directly into your instance? (Choose two.)

    A. Enable SSH on the instance
    B. Attach a NAT Gateway
    C. Enable Public IP addresses
    D. Attach an Internet Gateway

  • Question 195:

    What are two ways to influence the direction of Dynamic VPN traffic over multiple links? (Choose two.)

    A. AS_PATH Prepending
    B. BFD
    C. MED
    D. Shouting at it

  • Question 196:

    A company runs its applications on Amazon EC2 instances. A network engineer must deny specific ports for all applications and must allow only approved ports for each application. All outbound traffic from the instances must be allowed. Which solution will meet these requirements?

    A. Create a network ACL for each application to allow the application's approved ports. Associate the network ACL with the appropriate instances. Create a security group that denies the required specific ports. Associate the security group with the appropriate subnets.
    B. Create a security group for each application to allow the application's approved ports. Associate the security group with the appropriate instances. Create a network ACL that denies the required specific ports. Associate the network ACL with the appropriate subnets.
    C. Create a security group for each application to allow the application's approved ports. Associate the security group with the appropriate instances. Create a network ACL that denies the required specific ports inbound and denies all ports outbound. Associate the network ACL with the appropriate subnets.
    D. Create a security group for each application to allow the application's approved ports. Associate the security group with the appropriate instances. Create an additional security group that denies the required specific ports. Associate the additional security group with the appropriate instances.

  • Question 197:

    A company uses multiple AWS accounts within AWS Organizations and has services deployed in a single AWS Region. The instances in a private subnet occasionally download patches from the internet through a NAT gateway. The company recently migrated from VPC peering to AWS Transit Gateway. The cumulative traffic through deployed NAT gateways is less than 1 Gbps. The NAT gateway hourly charge contributes to most of the NAT gateway costs across all inked accounts.

    What should the company do to reduce NAT gateway hourly costs?

    A. Deploy and use NAT gateways in the same Availability Zone as the heavy-traffic resources.
    B. Move to a centralized NAT gateway architecture with NAT gateways deployed in an egress VPC. Use VPC peering to send traffic through the centralized NAT gateways.
    C. Use VPC endpoints to send traffic to AWS services in the same Region.
    D. Move to a centralized NAT gateway architecture with NAT gateways deployed in an egress VPC. Use AWS Transit Gateway to send traffic through the centralized NAT gateways.

  • Question 198:

    You are moving a two-tier application into an Amazon VPC. An Elastic Load Balancing (ELB) load balancer is configured in front of the application tier. The application tier is driven through RESTful interfaces. The data tier uses relational database service (RDS) MySQL. Company policy requires end-to-end encryption of all data in transit.

    What ELB configuration complies with the corporate encryption policy?

    A. Configure the ELB load balancer protocol as HTTP. Configure the application instances for SSL termination. Configure Amazon RDS for SSL, and use REQUIRE SSL grants.
    B. Configure the ELB protocols in TCP mode. Configure the application instances for SSL termination. Configure Amazon RDS for SSL, and use REQUIRE SSL grants.
    C. Configure the ELB load balancer protocol as HTTPS. Offload application instance encryption to the load balancer. Install your SSL certificate on Amazon RDS, and configure SSL.
    D. Configure the ELB protocols in SSL mode. Offload application instance encryption to the load balancer. Install your SSL/TLS certificate on Amazon RDS, and configure SSL.

  • Question 199:

    Your company has a high-availability hybrid solution that utilizes a two Direct Connect connections and a backup VPN connection. For some reason, traffic is preferring the VPN connection instead of the direct connection. You have prepended a longer AS_PATH on the VPN connection, but AWS still prefers it over the Direct Connect connections.

    What might you be able to do to fix this issue?

    A. Advertise a less specific prefix on the VPN.
    B. Remove the prepended AS_PATH.
    C. Reconfigure the VPN as a static VPN instead of dynamic.
    D. Increase the MED on the VPN.

  • Question 200:

    Which is not a valid Route 53 record?

    A. SPF
    B. NAPTR
    C. AAAA
    D. BFD

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only Amazon exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your ANS-C00 exam preparations and Amazon certification application, do not hesitate to visit our Vcedump.com to find your solutions here.