You have two Direct Connect connections and two VPN connections to your network. Site A is VPN 10.1.0.0/24 AS 65000 65000, Site B is VPN 10.1.0.252/30 AS 65000, Site C is DX 10.0.0.0/8 AS 65000 and Site D is DX 10.0.0.0/16 AS 65000 65000 65000. Which site will AWS choose to reach your network?
A. Site A: VPN 10.0.1.0/24 AS 65000 65000
B. Site B: VPN 10.0.1.252/30 AS 65000 65000 65000
C. Site C: DX 10.0.0.0/8 AS 65000
D. Site D: DX 10.0.0.0/16
You have two placement groups in a VPC. What communication speed can be expected between the two placement groups?
A. 5Gbps
B. 10Gbps
C. 20Gbps
D. You cannot communicate between two placement groups.
Your company is working on a transition from IPv4 to IPv6 but is concerned about the security of having public IPv6 addresses attached to instances in a public network. They currently use a NAT to allow outbound traffic for instances. Outbound traffic is required for updates. What are two options to alleviate your company's concerns? (Choose two.)
A. Remove any rules allowing ::/0 inbound in the security group.
B. Block ::/0 inbound in the NACL.
C. Create an egress-only internet gateway.
D. Block 0.0.0.0/0 inbound in the NACL.
When configuring Active/Passive HA on VPN tunnels, choose the two best ways to configure this. (Choose two.)
A. Keep both tunnels up.
B. Configure AS_PATH prepending on one of the paths.
C. Turn off one of the paths until you need it.
D. Configure MED on one of the tunnels.
You are under a DDoS attack and you have added a deny all TCP rule to your NACL, but traffic is still coming. What did you do wrong?
A. You configured the rule number to be too low.
B. A NACL can't protect against a DDoS.
C. The DDoS isn't a TCP attack.
D. You need to add a deny rule outbound also since NACLs are stateful.
You need to find the MTU used by another instance, but tracepath is not working. You know the instance you are trying to tracepath has open security group and NACL rules. Which protocol do you need to allow to access your instance to remedy this?
A. Protocol 6: TCP
B. Protocol 47: GRE
C. Protocol 17: UDP
D. Protocol 1: ICMP
Your company needs an inexpensive solution to host their AD data in the cloud. They do not need all of the features of AD but do need to be able to use it with WorkSpaces. What is the best solution?
A. AD Connector
B. Hosted Microsoft AD
C. Simple AD
D. Deploy an AD server on an M3.large instance
You have a static VPN connecting your data center and your VPC. You currently have 50 routes added to your route table. You want to add more; how should you do this?
A. 50 is the most you can have for any connection.
B. Just add them, you have a maximum of 100 static routes per route table.
C. Set up Direct Connect. A VPN will not support more routes.
D. Convert your VPN to a dynamic VPN and use BGP.
You have just deployed a website that utilizes CloudFront, ELB, and S3 to serve content. When users access your site, they are seeing broken image links. What is most likely the problem?
A. There is no record in Route 53 pointing cdn.yourdomain.com to the CloudFront ALIAS.
B. You need to create Origin Access Identity for CloudFront and add it to your bucket policy.
C. The images in S3 are saved as .png instead of .jpg.
D. There is no rule in your bucket policy allowing public access.
You have just peered two VPCs, and you need to improve performance for instances you plan on deploying. What are two steps you would take to do this? (Choose two.)
A. Create two subnets in the same AZ and create a placement group.
B. Set the MTU of your instances to 1500.
C. Create two subnets in different AZs and create a placement group.
D. Ensure you choose instances that use enhanced networking.
Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only Amazon exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your ANS-C00 exam preparations and Amazon certification application, do not hesitate to visit our Vcedump.com to find your solutions here.