Summer Special - Limited Time 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: top65certs

Note! Following ANS-C00 Exam is Retired now. Please select the alternative replacement for your Exam Certification. The new exam code is ANS-C01

Verified By IT Certified Experts

CertsTopics.com Certified Safe Files

Up-To-Date Exam Study Material

99.5% High Success Pass Rate

100% Accurate Answers

Instant Downloads

Exam Questions And Answers PDF

Try Demo Before You Buy

Certification Exams with Helpful Questions And Answers

AWS Certified Advanced Networking-Specialty Questions and Answers

Question 1

An organization has ordered a new AWS Direct Connect connection. The AWS Management Console reports that the connection is available and BGP status is up. However, the networking team is not able to reach instances in the VPC using ping on the organization's private IP address

What could cause this connectivity issue? (Choose two.)

Options:

A.

The VGW is not advertising the correct CIDR range back on-premises.

B.

The instance security group does not allow ICMP traffic.

C.

A public virtual interface must be configured for Amazon EC2 connectivity.

D.

The on-premises router is not advertising the correct CIDR range to AWS.

E.

There is a misconfiguration of the bi-directional forwarding detection.

Buy Now
Question 2

Your company decides to use Amazon S3 to augment its on-premises data store. Instead of using the company’s highly controlled, on-premises Internet gateway, a Direct Connect connection is ordered to provide high bandwidth, low latency access to S3. Since the company does not own a publically routable IPv4 address block, a request was made to AWS for an AWS-owned address for a Public Virtual Interface (VIF).

The security team is calling this new connection a “backdoor”, and you have been asked to clarify the risk to the company.

Which concern from the security team is valid and should be addressed?

Options:

A.

AWS advertises its aggregate routes to the Internet allowing anyone on the Internet to reach the router.

B.

Direct Connect customers with a Public VIF in the same region could directly reach the router.

C.

EC2 instances in the same region with access to the Internet could directly reach the router.

D.

The S3 service could reach the router through a pre-configured VPC Endpoint.

Question 3

The Web Application Development team is worried about malicious activity from 200 random IP addresses. Which action will ensure security and scalability from this type of threat?

Options:

A.

Use inbound security group rules to block the IP addresses.

B.

Use inbound network ACL rules to block the IP addresses.

C.

Use AWS WAF to block the IP addresses.

D.

Write iptables rules on the instance to block the IP addresses.