ANS-C00 Exam Details

  • Exam Code
    :ANS-C00
  • Exam Name
    :AWS Certified Advanced Networking - Specialty (ANS-C00)
  • Certification
    :Amazon Certifications
  • Vendor
    :Amazon
  • Total Questions
    :414 Q&As
  • Last Updated
    :May 30, 2026

Amazon ANS-C00 Online Questions & Answers

  • Question 341:

    A user is collecting 1000 records per second. The user wants to send the data to CloudWatch using a custom namespace. Which of the below mentioned options is recommended for this activity?

    A. Aggregate the data with statistics, such as Min, max, Average, Sum and Sample data and send the data to CloudWatch
    B. Send all the data values to CloudWatch in a single command by separating them with a comma. CloudWatch will parse automatically
    C. It is not possible to send all the data in one call. Thus, it should be sent one by one. CloudWatch will aggregate the data automatically
    D. Create one csv file of all the data and send a single file to CloudWatch

  • Question 342:

    A company has an application running on Amazon EC2 instances in a VPC. The application must publish custom metrics to Amazon CloudWatch in the same AWS Region. The metrics include proprietary information. All connectivity must be over private IP addresses.

    Which solution will meet these requirements?

    A. Connect to CloudWatch through a NAT gateway.
    B. Connect to CloudWatch through a gateway endpoint.
    C. Connect to CloudWatch through an internet gateway.
    D. Connect to CloudWatch through an interface endpoint.

  • Question 343:

    Your company has a 1-Gbps AWS Direct Connect connection to AWS. Your company needs to send traffic from on-premises to a VPC owned by a partner company. The connectivity must have minimal latency at the lowest price. Which of the following connectivity options should you choose?

    A. Create a new Direct Connect connection, and set up a new circuit to connect to the partner VPC using a private virtual interface.
    B. Create a new Direct Connect connection, and leverage the existing circuit to connect to the partner VPC.
    C. Create a new private virtual interface, and leverage the existing connection to connect to the partner VPC.
    D. Enable VPC peering and use your VPC as a transitive point to reach the partner VPC.

  • Question 344:

    What is the maximum number of CloudTrails that you can create per AWS region?

    A. 10
    B. 2
    C. 16
    D. 5

  • Question 345:

    Which ports must you allow for HTTP and HTTPS traffic?

    A. 25/465
    B. 21/22
    C. 3389/3306
    D. 80/443

  • Question 346:

    Your company has decided to use AWS WorkSpaces for its hosted desktop solution. Your company has an existing AD of about 57,000 users, and you want to minimize authentication traffic from AWS to your datacenter. Your company has a lot of personnel changes, and it is crucial that these changes are reflected reliably.

    What two steps should you take? (Choose two.)

    A. Deploy Hosted AD in AWS.
    B. Deploy an AD Connector in AWS.
    C. Create a DX connection between the datacenter and AWS.
    D. Create a VPN between the datacenter AWS.

  • Question 347:

    Select the answer/s that correctly state how Jumbo Frames work

    A. Jumbo Frames assist with application disk storage
    B. Jumbo Frames can assist with application performance
    C. Jumbo Frames are supported across Virtual Private Gateway connections
    D. Jumbo Frames are enabled by increasing the MTU size to 9000 kilobytes

  • Question 348:

    A company wants to migrate its production and development applications to the AWS Cloud across multiple VPCs in three AWS Regions: us-east-1 (N. Virginia), eu-west-1 (Ireland), and ap-southeast-1 (Singapore). The company needs a scalable solution that provides connectivity between all three Regions. The solution also must provide private connectivity to the company's on-premises data center in Northern Virginia.

    Data that is transferred from on premises and data that is transferred between Regions must be encrypted in transit. The company requires predictable network performance and must minimize cost.

    The company has initiated a solution by deploying a transit gateway with two route tables in each Region. One route table is for the production environment, and one route table is for the development environment. What else must the company do to meet its requirements with the LOWEST latency?

    A. Deploy an AWS Direct Connect connection in us-east-1 and a public VIF to the on-premises data center. On each transit gateway, create a VPN attachment over the public VIF for the production and development route tables. Create transit gateway peering connections to route traffic between Regions.
    B. Deploy an AWS Direct Connect connection in us-east-1 and a transit VIF to the on-premises data center. Associate all transit gateways and the transit VIF with a different Direct Connect gateway. Create transit gateway peering connections to route traffic between Regions.
    C. Deploy an AWS Direct Connect connection in us-east-1 and a public VIF to the on-premises data center. On each transit gateway, create a VPN attachment over the public VIF for the production and development route tables. Route traffic between Regions through the VPN connections.
    D. Deploy an AWS Direct Connect connection in us-east-1 to the on-premises data center. Create one transit VIF for each transit gateway route table, and associate each transit VIF with a Direct Connect gateway. Associate all transit gateways with the Direct Connect gateway. Create transit gateway peering connections to route traffic between Regions.

  • Question 349:

    A company's IT Security team needs to ensure that all servers within an Amazon VPC can communicate with a list of five approved external IPs only. The team also wants to receive a notification every time any server tries to open a connection with a non-approved endpoint.

    What is the MOST cost-effective solution that meets these requirements?

    A. Add allowed IPs to the network ACL for the application server subnets. Enable VPC Flow Logs with a filter set to ALL. Create an Amazon CloudWatch Logs filter on the VPC Flow Logs log group filtered by REJECT. Create an alarm for this metric to notify the Security team.
    B. Enable Amazon GuardDuty on the account and the specific region. Upload a list of allowed IPs to Amazon S3 and link the S3 object to the GuardDuty trusted IP list. Configure an Amazon CloudWatch Events rule on all GuardDuty findings to trigger an Amazon SNS notification to the Security team.
    C. Add allowed IPs to the network ACL for the application server subnets. Enable VPC Flow Logs with a filter set to REJECT. Set an Amazon CloudWatch Logs filter for the log group on every event. Create an alarm for this metric to notify the Security team.
    D. Enable Amazon GuardDuty on the account and specific region. Upload a list of allowed IPs to Amazon S3 and link the S3 object to the GuardDuty threat IP list. Integrate GuardDuty with a compatible SIEM to report on every alarm from GuardDuty.

  • Question 350:

    In your current role as the corporate network architect - you have decided to replace your existing hardware firewall appliances with a pair of Juniper SRX-Series Services Gateways. You have chosen these as AWS lists these as supportable devices for establishing IPsec connections. With this in mind, select the minimum set of options to ensure that you can establish IPsec connectivity between your on premise private corporate network and your AWS hosted VPC.

    Select which option is NOT required.

    A. Initiate network connections from somewhere within your corporate network, this is required to bring the tunnels UP
    B. Deploy a Customer Gateway within your corporate network
    C. Deploy a Customer Gateway within your VPC
    D. Deploy a Virtual Private Gateway within your VPC

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only Amazon exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your ANS-C00 exam preparations and Amazon certification application, do not hesitate to visit our Vcedump.com to find your solutions here.