
AWSCertified Advanced Networking - Specialty
Domain 4Objective 1
Task 4.1: Implement and Maintain Network Features to Meet Security and Compliance Needs and Requirements ANS-C01 Practice Questions (Page 1)
Part of the Content Domain 4: Network Security, Compliance, and Governance domain, which accounts for 24% of the ANS-C01 exam. AWS does not publish an official question count, but from its 170-minute exam (~70–115 total, ~17–28 in this domain), expect 6–9 from this objective — we provide 28 practice questions to prepare you well beyond it. (estimate)
28questions here
6free pages
10concepts
24%of the exam
Questions 1–5
- 1
When securing a VPC peering connection, which control is used to restrict which instances can communicate over the peering link?
Select an answer first - 2
Which statement correctly describes a difference between security groups and network ACLs in a VPC?
Select an answer first - 3
Which design strategy isolates different application tiers into separate subnets and uses security groups to limit traffic between them?
Select an answer first - 4
A company uses AWS CloudFormation to deploy its VPC. They want to ensure that all security groups created by the stack have a specific tag and that no security group allows inbound SSH from 0.0.0.0/0. What should they do?
Select an answer first - 5
A company has multiple VPCs that need to communicate with each other. They want to use AWS Transit Gateway to centralize connectivity, but they also need to ensure that only specific VPCs can communicate with each other. What should they configure?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by AWS. “ANS-C01” is a trademark of its owner, used for identification only.