Summer Sale - Limited Time 55% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: 5763r953

Welcome To DumpsPedia

ANS-C00 Sample Questions Answers

Questions 4

A network engineer has configured a private hosted zone using Amazon Route 53. The engineer needs to configure health checks for record sets within the zone that are associated with instances.

How can the engineer meet the requirements?

Options:

A.

Configure a Route 53 health check to a private IP associated with the instances inside the VPC to be checked.

B.

Configure a Route 53 health check pointing to an Amazon SNS topic that notifies an Amazon CloudWatch alarm when the Amazon EC2 StatusCheckFailed metric fails.

C.

Create a CloudWatch metric that checks the status of the EC2 StatusCheckFailed metric, add an alarm to the metric, and then create a health check that is based on the state of the alarm.

D.

Create a CloudWatch alarm for the StatusCheckFailed metric and choose Recover this instance, selecting a threshold value of 1.

Buy Now
Questions 5

A company's network engineer needs to evaluate and monitor DNS traffic The company uses Amazon Route 53 as the DNS service for its public hosted zone All DNS queries must be captured for future analysis.

What should the network engineer do to meet these requirements?

Options:

A.

Use AWS WAF to log information to Amazon CloudWatch Logs about the queries that Route 53 receives

B.

Use VPC Flow Logs to log information to Amazon CloudWatch Logs Insights about the queries that Route 53 receives

C.

Use Route 53 query logging to log information to Amazon CloudWatch Logs about the queries that Route 53 receives

D.

Use AWS CloudTrail to log information to Amazon CloudWatch Logs Insights about the queries that Route 53 receives

Buy Now
Questions 6

A computing team is evaluating whether to place a high performance computing (HPC) application in AWS. The team is concerned about application performance and wants to know what options are available to increase networking performance.

Which of the following changes would increase performance for this application? (Choose two.)

Options:

A.

Place the application across many smaller instances to achieve higher total throughput.

B.

Increase the MTU of the VPC to 9001.

C.

Enable an MTU of 9001 in the application's operating system.

D.

Enable enhanced networking on the instances.

E.

Deploy the application in two Availability Zones and insert them in one placement group.

Buy Now
Questions 7

A legacy, on-premises web application cannot be load balances effectively. There are both planned and unplanned events that cause usage spikes to millions of concurrent users. The existing infrastructure cannot handle the usage spikes. The CIO has mandated that the application be moved to the cloud to avoid further disruptions, with the additional requirement that source IP addresses be unaltered to support network traffic-monitoring needs. Which of the following designs will meet these requirements?

Options:

A.

Use an Auto Scaling group of Amazon EC2 instances behind a Classic Load Balancer.

B.

Use an Auto Scaling group of EC2 instances in a target group behind an Application Load Balancer.

C.

Use an Auto Scaling group of EC2 instances in a target group behind a Classic Load Balancer.

D.

Use an Auto Scaling group of EC2 instances in a target group behind a Network Load Balancer.

Buy Now
Questions 8

A network engineer is managing two AWS Direct Connect connections. Each connection has a public virtual interface configured with a private ASN. The engineer wants to configure active/passive routing between the Direct Connect connections to access Amazon public endpoints. What BGP configuration is required for the on-premises equipment? (Select two.)

Options:

A.

Use Local Pref to control outbound traffic.

B.

Use AS Prepending to control inbound traffic.

C.

Use eBGP multi-hop between loopback interfaces.

D.

Use BGP Communities to control outbound traffic.

E.

Advertise more specific prefixes over one Direct Connect connection.

Buy Now
Questions 9

A Network Engineer is troubleshooting a network connectivity issue for an instance within a public subnet that cannot connect to the internet. The first step the Engineer takes is to SSH to the instance via a local bastion within the VPC and runs an ifconfig command to inspect the IP addresses configured on the instance. The output is as follows:

The Engineer notices that the command output does not contain a public IP address. In the AWS Management Console, the public subnet has a route to the internet gateway. The instance also has a public IP address associated with it.

What should the Engineer do next to troubleshoot this situation?

Options:

A.

Configure the public IP on the interface.

B.

Disable source/destination checking for the instance.

C.

Associate an Elastic IP address to the interface.

D.

Evaluate the security groups and the network access control list.

Buy Now
Questions 10

A company uses AWS Direct Connect lo connect its corporate network to multiple VPCs in the same AWS account and the same AVVS Region Each VPC uses its own private VIF and its own virtual LAN on the Direct Connect connection The company has grown and will soon surpass the limit of VPCs and private VIFs for each connection

What is the MOST scalable way to add VPCs with on-premises connectivity?

Options:

A.

Provision a new Direct Connect connection to handle the additional VPCs Use the new connection to connect additional VPCs.

B.

Create virtual private gateways for each VPC that is over the service quota Use AWS Site-to-Site VPN to connect the virtual private gateways to the corporate network

C.

Create a Direct Connect gateway, and add virtual private gateway associations to the VPCs. Configure a private VIF to connect to the corporate network

D.

Create a transit gateway and attach the VPCs Create a Direct Connect gateway, and associate it with the transit gateway Create a transit VIF to the Direct Connect gateway

Buy Now
Questions 11

A Systems Administrator is designing a hybrid DNS solution with spilt-view. The apex-domain “example.com” should be served through name servers across multiple top-level domains (TLDs). The name server for subdomain “dev.example.com” should reside on-premises. The administrator has decided to use Amazon Route 53 to achieve this scenario.

What procedurals steps must be taken to implement the solution?

Options:

A.

Use a Route 53 public hosted zone for example.com and a private hosted zone for dev.example.com

B.

Use a Route 53 public and private hosted zone for example.com and perform subdomain delegation for dev.example.com

C.

Use a Route 53 public hosted zone for example.com and perform subdomain delegation for dev.example.com

D.

Use a Route 53 private hosted zone for example.com and perform subdomain delegation for dev.example.com

Buy Now
Questions 12

An organization will be expanding its current network design. When fully built out, there will be 99 VPCs spread across 11 AWS accounts (9 VPCs per account). There is currently an AWS Direct Connect connection into one account with 9 VPCs, each with a virtual network interface (VIF) per VPC.

Which of the following designs will minimize cost while allowing the organization to expand?

Options:

A.

Order 10 new Direct Connect connections, one from each of the accounts that will be provisioned. Create private VIFs in each account. Attach one private VIF per VPC.

B.

Create a public VIF on the Direct Connect connection. Leverage the public VIF to create a VPN connection to each VPC.

C.

Create hosted private VIFs in the existing account. Connect a private VIF to an AWS Direct Connect gateway in each account. Connect the gateway in each account to the VPCs.

D.

Create a transit VPC in the existing account that consists of two routers in separate Availability Zones. Connect each VPC to the two routers in the transit VPC by using VPN.

Buy Now
Questions 13

A multinational organization has applications deployed in three different AWS regions. These applications must securely communicate with each other by VPN. According to the organization’s security team, the VPN must meet the following requirements:

  • AES 128-bit encryption
  • SHA-1 hashing
  • User access via SSL VPN
  • PFS using DH Group 2
  • Ability to maintain/rotate keys and passwords
  • Certificate-based authentication

Which solution should you recommend so that the organization meets the requirements?

Options:

A.

AWS hardware VPN between the virtual private gateway and customer gateway

B.

A third-party VPN solution deployed from AWS Marketplace

C.

A private MPLS solution from an international carrier

D.

AWS hardware VPN between the virtual private gateways in each region

Buy Now
Questions 14

A company hosts several applications in the AWS Cloud across multiple VPCs that are connected to a transit gateway Redundant AWS Direct Connect connections and a Direct Connect gateway provide private network connectivity lo the company's on-premises environment

During a maintenance window, the networking team adds eight VPCs The application management team notices that there is no reachability between the newly created VPCs and the on-premises environment Connectivity between all VPCs through the transit gateway is working as expected.

Which of the following are possible causes of the connectivity issues? (Choose TWO)

Options:

A.

The prefixes that are advertised from the Direct Connect gateway to the on-premises router are shorter than the CIDR blocks of the newly created VPCs

B.

The route tables for the newly created A. VPCs do not have the routes to the on-premises environment that point to the transit gateway attachment

C.

The on-premises route tables do not contain the exact CIDR blocks of the newly created VPCs

D.

The route tables (or the newly created VPCs have only summary routes for (he on-premises environment (fiat point to the transit gateway attachment.

E.

The prefixes that are advertised from the Direct Connect gateway to the on-premises router do not contain the CIDR blocks of the newly created VPCs

Buy Now
Questions 15

You are preparing to launch Amazon WorkSpaces and need to configure the appropriate networking resources. What must be configured to meet this requirement?

Options:

A.

At least two subnets in different Availability Zones.

B.

A dedicated VPC with Active Directory Services.

C.

An IPsec VPN to on-premises Active Directory

D.

Network address translation for outbound traffic.

Buy Now
Questions 16

An organization has created a web application inside a VPC and wants to make it available to 200 client VPCs. The client VPCs are in the same region but are owned by other business units within the organization.

What is the best way to meet this requirement, without making the application publicly available?

Options:

A.

Configure the application as an AWS PrivateLink-powered service, and have the client VPCs connect to the endpoint service by using an interface VPC endpoint.

B.

Enable VPC peering between the web application VPC and all client VPCs.

C.

Deploy the web application behind an internet-facing Application Load Balancer and control which clients have access by using security groups.

D.

Deploy the web application behind an internal Application Load Balancer and control which clients have access by using security groups.

Buy Now
Questions 17

A space exploration firm possesses a collection of telescopes that take many photographs and data of the night sky. The pictures and data are processed on an AWS Fargate application that is allocated to a target group by an Application Load Balancer (ALB). The program is accessible at https://space.example.com.

Additionally, scientists demand a custom-built application that is hosted on many Amazon EC2 instances inside an Auto Scaling group. This application will be accessible at the following link: https://space.example.com/meteor. The firm need a system that can grow automatically from a low number of requests overnight to a high volume of demands during a future meteor shower.

What is the MOST OPTIMAL option that satisfies these requirements?

Options:

A.

Update the existing target group with the new EC2 instances. Update the application's ALB by adding a listener rule that redirects /meteor to the newly added EC2 instances.

B.

Create a new target group. Configure the Auto Scaling group of the EC2 instances to use the target group Update the ALB by adding a listener rule that redirects /meteor to the new target group.

C.

Create a Network Load Balancer (NLB). Configure the NLB to listen on two ports. Configure a target group for one port to deliver all IP traffic to the Auto Scaling group to process the custom images. Configure a target group for the second port to deliver all IP traffic to Fargate Use path-based routing in the ALB to route traffic for the URL prefix /meteor to the first target group. Route all other paths to the second target group.

D.

Place the ALB behind an Amazon CloudFront distribution. Create a Lambda@Edge function that parses the request URI and adds the path-pattern header with the IP addresses of the EC2 instances to any request for /meteor. Add a listener rule to the ALB that looks for the HTTP header and uses the IP addresses of the EC2 instances to forward the traffic.

Buy Now
Questions 18

You currently use a single security group assigned to all nodes in a clustered NoSQL database. Only your cluster members in one region must be able to connect to each other. This security group uses a self-referencing rule using the cluster security group’s group-id to make it easier to add or remove nodes from the cluster. You need to make this database comply with out-of-region disaster recovery requirements and ensure that the network traffic between the nodes is encrypted when travelling between regions. How should you enable secure cluster communication while deploying additional cluster members in another AWS region?

Options:

A.

Create an IPsec VPN between AWS regions, use private IP addresses to route traffic, and create cluster security group rules that reference each other’s security group-id in each region.

B.

Create an IPsec VPN between AWS regions, use private IP addresses to route traffic, and create cluster security group CIDR-based rules that correspond with the VPC CIDR in the other region.

C.

Use public IP addresses and TLS to securely communicate between cluster nodes in each AWS region, and create cluster security group CIDR-based rules that correspond with the VPC CIDR in the other region.

D.

Use public IP addresses and TLS to securely communicate between cluster nodes in each AWS region, and create cluster security group rules that reference each other’s security group-id in each region.

Questions 19

A Network Engineer is provisioning a subnet for a load balancer that will sit in front of a fleet of application servers in a private subnet. There is limited IP space left in the VPC CIDR. The application has few users now but is expected to grow quickly to millions of users.

What design will use the LEAST amount of IP space, while allowing for this growth?

Options:

A.

Use two /29 subnets for an Application Load Balancer in different Availability Zones.

B.

Use one /29 subnet for the Network Load Balancer. Add another VPC CIDR to the VPC to allow for future growth.

C.

Use two /28 subnets for a Network Load Balancer in different Availability Zones.

D.

Use one /28 subnet for an Application Load Balancer. Add another VPC CIDR to the VPC to allow for future growth.

Buy Now
Questions 20

An organization processes consumer information submitted through its website. The organization’s security policy requires that personally identifiable information (PII) elements are specifically encrypted at all times and as soon as feasible when received. The front-end Amazon EC2 instances should not have access to decrypted PII. A single service within the production VPC must decrypt the PII by leveraging an iAM role.

Which combination of services will support these requirement? (Select two.)

Options:

A.

Amazon Aurora in a private subnet

B.

Amazon CloudFront using AWS Lambda@Edge

C.

Customer-managed MySQL with Transparent Data Encryption

D.

Application Load Balancer using HTTPS listeners and targets

E.

AWS Key Management Services

Questions 21

An organization is replacing a tape backup system with a storage gateway. there is currently no connectivity to AWS. Initial testing is needed.

What connection option should the organization use to get up and running at minimal cost?

Options:

A.

Use an internet connection.

B.

Set up an AWS VPN connection.

C.

Provision an AWS Direct Connection private virtual interface.

D.

Provision a Direct Connect public virtual interface.

Buy Now
Questions 22

The Security department has mandated that all outbound traffic from a VPC toward an on-premises datacenter must go through a security appliance that runs on an Amazon EC2 instance.

Which of the following maximizes network performance on AWS? (Choose two.)

Options:

A.

Support for the enhanced networking drivers

B.

Support for sending traffic over the Direct Connect connection

C.

The instance sizes and families supported by the security appliance

D.

Support for placement groups within the VPC

E.

Security appliance support for multiple elastic network interfaces

Buy Now
Status:
Expired , and Replaced By
Exam Code: ANS-C00
Exam Name: AWS Certified Advanced Networking Specialty Exam
Last Update: Apr 14, 2023
Questions: 154
$72  $159.99
$54  $119.99
$45  $99.99
buy now ANS-C00