Labour Day Special Limited Time 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: cramtreat

Note! Following ANS-C00 Exam is Retired now. Please select the alternative replacement for your Exam Certification. The new exam code is ANS-C01

ANS-C00 AWS Certified Advanced Networking-Specialty Questions and Answers

Questions 4

An application runs on a fleet of Amazon EC2 instances in a VPC. All instances can reach one another using private IP addresses. The application owner has a new requirement that the domain name received via DHCP should be different for a particular set of instances that are currently in one particular subnet.

What changes should be made to meet this requirement while continuing to support the existing application requirements?

Options:

A.

Modify the existing DHCP option set and specify the different domain name for the specified subnet.

B.

Create a new DHCP option set with the different domain name, associate it with the specified subnet, and re-launch the Amazon EC2 instances.

C.

Create a new subnet, configure the DHCP option set with the different domain name, and re-launch the required instances there.

D.

Create a new peered VPC, configure the DHCP option set with the different domain name, and re-launch the required instances there.

Buy Now
Questions 5

A company uses a newly provisioned 1-Gbps AWS Direct Connect connection to configure a virtual interface for access to Amazon S3

Which configuration values is the network engineer required to provide? (Select TWO.)

Options:

A.

Connection speed

B.

VLAN ID

C.

IP prefixes to advertise

D.

Direct Connect location

E.

Virtual private gateway

Buy Now
Questions 6

Your organization has a newly installed 1-Gbps AWS Direct Connect connection. You order the cross-connect from the Direct Connect location provider to the port on your router in the same facility. To enable the use of your first virtual interface, your router must be configured appropriately.

What are the minimum requirements for your router?

Options:

A.

1-Gbps Multi Mode Fiber Interface, 802.1Q VLAN, Peer IP Address, BGP Session with MD5.

B.

1-Gbps Single Mode Fiber Interface, 802.1Q VLAN, Peer IP Address, BGP Session with MD5.

C.

IPsec Parameters, Pre-Shared key, Peer IP Address, BGP Session with MD5

D.

BGP Session with MD5, 802.1Q VLAN, Route-Map, Prefix List, IPsec encrypted GRE Tunnel

Buy Now
Questions 7

You have been asked to monitor traffic flows on your Amazon EC2 instance. You will be performing deep packet inspection, looking for atypical patterns.

Which tool will enable you to look at this data?

Options:

A.

Wireshark

B.

VPC Flow Logs

C.

AWS CLI

D.

CloudWatch Logs

Buy Now
Questions 8

A company wants to conduct a proof of concept for an SAP HANA application with a hey objective to automate the provisioning of infrastructure and the application. The company operates a hybrid cloud infrastructure with AWS Direct Connect between its data center and VPC. Security policy dictates that all traffic from AWS be routed through on-premises data center firewalls. Security policy also prohibits the use of a VPC internet gateway for internet access The company enforces use of a forward proxy server for all outbound network traffic All resources inside the VPC are able to reach on-premises servers.

All Amazon EC2 Linux instances require package updates over the internet. However, the updates are failing and sending errors.

What would cause these errors?

Options:

A.

Inbound security groups are configured incorrectly on the EC2 instances running in the VPC.

B.

The VPC route table does not have entries for the proxy server in the data center

C.

The EC2 instances are not configured to use the proxy running in the data center for traffic on TCP port 80.

D.

The data center firewall is blocking all traffic sent from the VPC CIDR range destined for 0.0.0.0/0.

Buy Now
Questions 9

A Lambda function needs to access the private address of an Amazon ElastiCache cluster in a VPC. The Lambda function also needs to write messages to Amazon SQS. The Lambda function has been configured to run in a subnet in the VPC.

Which of the following actions meet the requirements? (Select two.)

Options:

A.

The Lambda function needs an IAM role to access Amazon SQS

B.

The Lambda function must route through a NAT gateway or NAT instance in another subnet to access the public SQS API.

C.

The Lambda function must be assigned a public IP address to access the public Amazon SQS API.

D.

The ElastiCache server outbound security group rules must be configured to permit the Lambda function’s security group.

E.

The Lambda function must consume auto-assigned public IP addresses but not elastic IP addresses.

Buy Now
Questions 10

An IT company wants to securely perform an on-off migration of its on-premises VMs to the AWS Cloud by using AWS Server Migration Service {AWS SMS) For the first phase of the migration, the company must migrate 50 development VMs m batches during non-peak times over the next 7 days The VMs are between 2 GB and 5 GB in size The company has 1 Gbps of available bandwidth over the internet

Which network connectivity option meets these requirements MOST cost-effectively?

Options:

A.

Contact an AWS partner to order a hosted VIF

B.

Use the existing internet connection

C.

Order an AWS Direct Connect connection Provision a public VIF

D.

Create a VPN connection to AWS.

Buy Now
Questions 11

A company provisions an AWS Direct Connect connection to permit access to Amazon EC2 resources in several Amazon VPCs and to data stored in private Amazon S3 buckets. The Network Engineer needs to configure the company's on-premises router for this Direct Connect connection.

Which of the following actions will require the LEAST amount of configuration overhead on the customer router?

Options:

A.

Configure private virtual interfaces for the VPC resources and for Amazon S3.

B.

Configure private virtual interfaces for the VPC resources and a public virtual interface for Amazon S3.

C.

Configure a private virtual interface to a Direct Connect gateway for the VPC resources and for Amazon S3.

D.

Configure a private virtual interface to a Direct Connect gateway for the VPC resources and a public virtual interface for Amazon S3.

Buy Now
Questions 12

An organization is replacing a tape backup system with a storage gateway. there is currently no connectivity to AWS. Initial testing is needed.

What connection option should the organization use to get up and running at minimal cost?

Options:

A.

Use an internet connection.

B.

Set up an AWS VPN connection.

C.

Provision an AWS Direct Connection private virtual interface.

D.

Provision a Direct Connect public virtual interface.

Buy Now
Questions 13

A company wants to use thin clients running virtual desktops to replace 500 desktop computers used by its call center employees The company is evaluating Amazon Workspaces as a solution

A network engineer who is testing with a thin client is unable to conned to Amazon Workspaces After entering credentials the network engineer receives the following error:

"An error occurred while launching your Workspace Please try again"

What should the network engineer do to resolve this issue?

Options:

A.

Update the inbound rules on the network ACL on the subnets used for Amazon Workspaces to allow UDP on port 4172 and TCP on port 4172

B.

Update the company's corporate firewall to allow outbound access to UDP on port 4172 and TCP on port 4172 Open inbound ephemeral ports explicitly to allow return communication

C.

Update the inbound rules on the security group assigned to Amazon Workspaces to allow UDP on port 4172 and TCP on port 4172

D.

Update the company's corporate firewall to allow inbound access to UDP on port 4172 and TCP on port 4172 Open outbound ephemeral ports explicitly to allow return communication

Buy Now
Questions 14

DNS name resolution must be provided for services in the following four zones:

company.private.

emea.company.private.

apac.company.private.

amer.company.private.

The contents of these zones is not considered sensitive, however, the zones only need to be used by services hosted in these VPCs, one per geographic region. Each VPC should resolve the names in all zones.

How can you use Amazon route 53 to meet these requirements?

Options:

A.

Create a Route 53 Private Hosted Zone for each of the four zones and associate them with the three VPCs.

B.

Create a single Route 53 Private Hosted Zone for the zone company.private and associate it with the three VPCs.

C.

Create a Route Public Hosted Zone for each of the four zones and configure the VPS DNS Resolver to forward

D.

Create a single Route 53 Public Hosted Zone for the zone company.private and configure the VPS DNS Resolver to forward

Buy Now
Questions 15

You are preparing to launch Amazon WorkSpaces and need to configure the appropriate networking resources. What must be configured to meet this requirement?

Options:

A.

At least two subnets in different Availability Zones.

B.

A dedicated VPC with Active Directory Services.

C.

An IPsec VPN to on-premises Active Directory

D.

Network address translation for outbound traffic.

Buy Now
Questions 16

A network engineer is managing two AWS Direct Connect connections. Each connection has a public virtual interface configured with a private ASN. The engineer wants to configure active/passive routing between the Direct Connect connections to access Amazon public endpoints. What BGP configuration is required for the on-premises equipment? (Select two.)

Options:

A.

Use Local Pref to control outbound traffic.

B.

Use AS Prepending to control inbound traffic.

C.

Use eBGP multi-hop between loopback interfaces.

D.

Use BGP Communities to control outbound traffic.

E.

Advertise more specific prefixes over one Direct Connect connection.

Buy Now
Questions 17

A gaming company is running an online multiplayer game in multiple AWS Regions The company needs traffic from its end users to be routed to the Region that is closest to the end users geographically When maintenance occurs in a Region, traffic must be routed to the next closest Region with no changes to the IP addresses being used as connections by the end users

Which solution will meet these requirements?

Options:

A.

Create an Amazon CloudFront distribution in front of all the Regions

B.

Use an Amazon Route 53 geoproximity routing policy to navigate traffic to the closest Region

C.

Use an Amazon Route 53 geolocation routing policy to navigate traffic to the closest Region

D.

Configure AWS Global Accelerator in front of all the Regions

Buy Now
Questions 18

An organization with a growing e-commerce presence uses the AWS CloudHSM to offload the SSL/TLS processing of its web server fleet. The company leverages Amazon EC2 Auto Scaling for web servers to handle the growth. What architectural approach is optimal to scale the encryption operation?

Options:

A.

Use multiple CloudHSM instances, and load balance them using a Network Load Balancer.

B.

Use multiple CloudHSM instances to the cluster;request to it will automatically load balance.

C.

Enable Auto Scaling on the CloudHSM instance, with similar configuration to the web tier Auto Scaling group.

D.

Use multiple CloudHSM instances, and load balance them using an Application Load Balancer.

Buy Now
Questions 19

Changes made to a security group attached to an Application Load Balancer resulted in connectivity issues for a company's production web application. The Network Engineer needs to lock down permissions for the company's AWS account, automate auditing for any changes, and set up notifications.

What actions should accomplish this?

Options:

A.

Configure IAM user policies to lock down permissions for specific users. Enable AWS CloudTrail to identify API calls from users. Use AWS Config to audit any changes, and configure Amazon SNS to send notifications.

B.

Configure IAM user policies to lock down permissions for specific users. Enable AWS CloudTrail to identify the API calls from users. Configure AWS CodeCommit to audit any changes in configurations, and configure Amazon SNS to send notifications.

C.

Configure IAM user policies to lock down permissions for specific users. Enable AWS CloudTrail to identify the API calls from users. Configure Amazon Macie to use machine learning to identify any configuration changes, and configure Amazon SNS to send notifications.

D.

Configure IAM role policies to lock down permissions for specific users. Configure Amazon GuardDuty to audit and monitor configuration changes, and configure Amazon SNS to send notifications.

Buy Now
Questions 20

Your organization requires strict adherence to a change control process for its Amazon Elastic Compute Cloud (EC2) and VPC environments. The organization uses AWS CloudFormation as the AWS service to control and implement changes. Which combination of three services provides an alert for changes made outside of AWS CloudFormation? (Select three.)

Options:

A.

AWS Config

B.

AWS Simple Notification Service

C.

AWS CloudWatch metrics

D.

AWS Lambda

E.

AWS CloudFormation

F.

AWS Identify and Access Management

Buy Now
Questions 21

A computing team is evaluating whether to place a high performance computing (HPC) application in AWS. The team is concerned about application performance and wants to know what options are available to increase networking performance.

Which of the following changes would increase performance for this application? (Choose two.)

Options:

A.

Place the application across many smaller instances to achieve higher total throughput.

B.

Increase the MTU of the VPC to 9001.

C.

Enable an MTU of 9001 in the application's operating system.

D.

Enable enhanced networking on the instances.

E.

Deploy the application in two Availability Zones and insert them in one placement group.

Buy Now
Questions 22

The Web Application Development team is worried about malicious activity from 200 random IP addresses. Which action will ensure security and scalability from this type of threat?

Options:

A.

Use inbound security group rules to block the IP addresses.

B.

Use inbound network ACL rules to block the IP addresses.

C.

Use AWS WAF to block the IP addresses.

D.

Write iptables rules on the instance to block the IP addresses.

Buy Now
Exam Code: ANS-C00
Exam Name: AWS Certified Advanced Networking-Specialty
Last Update: Apr 14, 2023
Questions: 154