
AWSCertified Advanced Networking - Specialty
Domain 4Objective 3
Task 4.3: Implement and Maintain Confidentiality of Data and Communications of the Network ANS-C01 Practice Questions (Page 4)
Part of the Content Domain 4: Network Security, Compliance, and Governance domain, which accounts for 24% of the ANS-C01 exam. AWS does not publish an official question count, but from its 170-minute exam (~70–115 total, ~17–28 in this domain), expect 6–9 from this objective — we provide 21 practice questions to prepare you well beyond it. (estimate)
21questions here
5free pages
8concepts
24%of the exam
Questions 16–20
- 16
Which AWS service records API activity in your account, providing an audit log that can be used to detect unauthorized access or data exfiltration attempts?
Select an answer first - 17
A company has a VPC with a public subnet and a private subnet. An EC2 instance in the private subnet needs to access the internet for software updates, but the security team wants to ensure that no inbound traffic from the internet can reach the instance. What should the network engineer configure?
Select an answer first - 18
Which AWS service is used to centrally manage and rotate encryption keys that can be used to encrypt network traffic or other data?
Select an answer first - 19
What is the primary benefit of enabling automatic key rotation for a customer-managed key (CMK) in AWS KMS?
Select an answer first - 20
Which AWS service can be used to monitor and protect applications from web exploits that could lead to data exfiltration, such as SQL injection or cross-site scripting?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by AWS. “ANS-C01” is a trademark of its owner, used for identification only.