dc dotCreds
AWS Certified Advanced Networking – Specialty Practice Test

AWS Advanced Networking Specialty Practice Test

Start today’s free 10-question AWS Advanced Networking Specialty set with source-backed explanations, local progress, and a fresh rotation every morning.

10 Free Daily Questions Source-backed Explanations 200 Verified Questions

Questions updated at Aug 17, 2026, 11:07 AM CDT

Go Pro - One Time Unlock

Unlock the full ANS-C01 bank

200 verified questions Exam Mode Practice Mode Detailed explanations Weak-area review No subscription - one-time unlock

Get the complete source-backed bank with Interview Questions, the full Study Guide, full Course Notes, detailed explanations, weak-area review, and exam-style practice.

Interview Questions Full Study Guide Full Course Notes Exam Mode Practice Mode Guided Course Detailed explanations Weak-area review No subscription
$4.99 One-time payment
See bundle and PDF options

We will confirm your site email in one quick checkout step.

Why DotCreds?

Practice with explanations that teach.

Source links for every answer Every wrong answer explained Guided Course included Practice and Exam Mode Weak-area tracking Same verified bank across web practice

What you get with free practice

10 Free Questions Daily Fresh set every day from the live bank
Detailed Explanations Learn with clear source-backed answers
Track Your Progress Daily history and performance insights
Upgrade Anytime Unlock the full bank when you are ready
Today's 10 AWS Advanced Networking Specialty questions

Use this AWS Advanced Networking Specialty practice test to review AWS Certified Advanced Networking – Specialty. Questions rotate daily and each answer links back to the source used to write it.

Today’s Set
10 questions
Rotates at 10:00 AM local time
Progress
0/10
Answered on this page
Accuracy
0%
Loading countdown…

200 verified questions are in the live bank. Free daily questions are selected from a rotating sample set. Unlock Pro to access the full question bank.

Preparing today’s free questions... Ordering the final locked-bank set before showing the practice cards.
Question 1 of 10
Objective Task 3.3: Optimize AWS networks for performance, reliability, and cost-effectiveness 3. Network Management and Operation (20%)

A software vendor is redesigning its AWS network. A non-cacheable, latency-sensitive application serves users globally from healthy endpoints in multiple Regions. The change must minimize operational overhead and avoid manual failover steps. Reduce internet-path variability and improve failover while keeping the application protocol unchanged. Which design should the network specialist recommend?

Concept tested:
Question 2 of 10
Objective Task 3.1: Maintain routing and connectivity on AWS and hybrid networks 3. Network Management and Operation (20%)

A company has redundant Direct Connect VIFs and wants to validate failover during a maintenance window without physically disconnecting a circuit. Which AWS feature is designed for this test?

Concept tested:
Question 3 of 10
Objective Task 4.1: Implement and maintain network features to meet security and compliance needs and requirements 4. Network Security, Compliance, and Governance (24%)

A very aggressive WAF rate-based rule stops an HTTP flood almost immediately. The team notices Shield Advanced recorded less attack detail than expected. Which tradeoff is documented?

Concept tested:
Question 4 of 10
Objective Task 2.3: Implement complex hybrid and multi-account DNS architectures 2. Network Implementation (26%)

A research university is redesigning its AWS network. Internet users and VPC workloads query the same FQDN, but VPC workloads must receive private load-balancer addresses. The change must minimize operational overhead and avoid manual failover steps. Return different answers based on whether the query is resolved inside the associated VPC. Which design should the network specialist recommend?

Concept tested:
Question 5 of 10
Objective Task 1.1: Design a solution that incorporates edge network services to optimize user performance and traffic management for global architectures 1. Network Design (30%)

A global payments company is redesigning its AWS network. Users worldwide download cacheable images, JavaScript, and software artifacts from an HTTP origin. The change must minimize operational overhead and avoid manual failover steps. Reduce latency and origin load by serving cacheable content from edge locations. Which design should the network specialist recommend?

Concept tested:
Question 6 of 10
Objective Task 4.3: Implement and maintain confidentiality of data and communications of the network 4. Network Security, Compliance, and Governance (24%)

A government contractor is redesigning its AWS network. A company requires Layer 2 encryption on the physical Direct Connect segment and is evaluating MACsec. The change must minimize operational overhead and avoid manual failover steps. Choose a design that matches Direct Connect MACsec support boundaries. Which design should the network specialist recommend?

Concept tested:
Question 7 of 10
Objective Task 2.4: Automate and configure network infrastructure 2. Network Implementation (26%)

A healthcare SaaS provider is redesigning its AWS network. A central network team wants automated remediation when managed network resources drift from approved infrastructure definitions. The change must minimize operational overhead and avoid manual failover steps. Automate detection and correction while retaining a declarative source of truth and reviewable changes. Which design should the network specialist recommend?

Concept tested:
Question 8 of 10
Objective Task 1.2: Design DNS solutions that meet public, private, and hybrid requirements 1. Network Design (30%)

An insurance provider is redesigning its AWS network. An application has active endpoints in two Regions and must direct users away from an unhealthy primary while keeping DNS-based traffic management. The change must minimize operational overhead and avoid manual failover steps. Provide DNS-level health-aware failover with a controlled primary and secondary relationship. Which design should the network specialist recommend?

Concept tested:
Question 9 of 10
Objective Task 4.2: Validate and audit security by using network monitoring and logging services 4. Network Security, Compliance, and Governance (24%)

A Traffic Mirroring source produces more packets than the analysis appliance can handle. Which built-in control should be used before scaling the appliance?

Concept tested:
Question 10 of 10
Objective Task 2.1: Implement routing and connectivity between on-premises networks and the AWS Cloud 2. Network Implementation (26%)

A private IP VPN over Direct Connect is attached to Transit Gateway. The architect wants some VPC-to-on-premises flows encrypted and other flows to use the underlying Direct Connect path unencrypted. Does the architecture allow separate routing for the VPN and Direct Connect attachments?

Concept tested:
Locked preview

You are viewing today’s free 10. Unlock 190 more questions.

Unlock full bank
Daily sample Rotating practice Free daily questions are selected from a rotating sample set.
Pro bank Full access Unlock Pro to access the full question bank, Exam Mode, Practice Mode, and random tests.
ANS-C01 Pro $4.99 one-time

Unlock all 200 AWS Advanced Networking Specialty questions, explanations, review tools, and exam-style practice.

50 Exam Practice Test $1.99 one-time

A 50-question ANS-C01 PDF for short review sessions. Questions come first, then the answer review and explanations later in the file.

AWS Access Bundle $6.99/month

AWS practitioner, architect, and machine learning practice in one monthly unlock.

What’s includedAWS AI Practitioner, AWS Cloud Practitioner, AWS Developer Associate, AWS Advanced Networking Specialty, AWS Security Specialty, AWS ML Engineer Associate, AWS SAA-C03

Choose an unlock option to continue. We will confirm your site email in one quick checkout step.

Secure checkout powered by Stripe. Source-backed questions. Not brain dumps. Checkout stays on this page and unlocks the same Pro builder on this practice page.

Purchase options

Unlock the full ANS-C01 bank.

Get the full bank, Exam Mode, Practice Mode, question sets, random tests, readiness tracking, saved box scores, and review tools for this exam.

The PDF versions keep questions first and move the answer review, explanations, and distractor notes to the back of the file.

200 verified exam-style questions Every choice explained Exam Mode and Practice Mode Question sets and random tests Readiness score and trends Previous test box scores

You've answered 0/10 questions in today's set.

Locked: 190 more questions in the full bank.

Locked: exam simulation mode, practice mode, readiness tracking, and saved review history.

Checkout stays on this page, so you can keep practicing, unlock the full bank, and start Exam Mode or Practice Mode when you are ready.

Cheat Sheets

7-day score keeper

Answer questions today and this will become a rolling 7-day scorecard.

Local history
Optional progress sync

Keep today’s practice moving

Guest progress saves automatically on this device. Add an email later when you want a magic link that keeps your daily ANS-C01 practice in sync across browsers.

Guest progress saves on this device automatically

Guest progress is available without an account.

Source-backed answer review

The free daily AWS Advanced Networking Specialty set includes crawlable question text, answer choices, correct answer labels, objective mapping, and source links. Only the first SEO card includes answer explanations and any extra learning features. Pro-only bank questions stay locked; this section mirrors only the 10 free daily questions already shown on this page.

Question 1 A software vendor is redesigning its AWS network. A non-cacheable, latency-sensitive application serves users globally from healthy endpoints in multiple Regions. The change must minimize operational overhead and avoid manual failover steps. Reduce internet-path variability and improve failover while keeping the application protocol unchanged. Which design should the network specialist recommend?

Answer choices

  1. A. Use AWS Global Accelerator in front of the Regional endpoints.
  2. B. Route all users through one NAT gateway in the primary Region.
  3. C. Use CloudFront solely to cache the non-cacheable application responses.
  4. D. Increase Route 53 TTL to keep users on one Region longer.

Correct answer

Use AWS Global Accelerator in front of the Regional endpoints.

Global Accelerator moves client traffic onto the AWS global network near users and steers it to healthy endpoints, which is appropriate for non-cacheable global applications. Source basis: Global Accelerator uses static anycast IP addresses from the AWS edge network and routes traffic to healthy endpoints over the AWS global network. The remaining options either solve a different layer of the problem, introduce an avoidable failure/management condition, or rely on behavior that the cited AWS service does not provide.

Wrong-answer review

  • B. Route all users through one NAT gateway in the primary Region.: Incorrect. A single Regional NAT gateway adds concentration and does not provide global ingress optimization.
  • C. Use CloudFront solely to cache the non-cacheable application responses.: Incorrect. Caching is ineffective when responses are intentionally non-cacheable.
  • D. Increase Route 53 TTL to keep users on one Region longer.: Incorrect. A long DNS TTL slows routing changes and does not improve the network path.

Extra learning features

Why candidates miss this

The term ‘latency-sensitive’ is tempting because it’s a common concern. However, the question doesn’t require the learner to define ‘latency-sensitive.’ The decisive clue is ‘non-cacheable,’ which directly points to the need for a solution like Global Accelerator that avoids the caching problem. Likely wrong answer: Use CloudFront solely to cache the non-cacheable application responses. Review focus: How AWS Global Accelerator works

Interview question

Q: Global Accelerator moves client traffic onto the AWS global network near users and steers it to healthy endpoints, which is appropriate for non-cacheable global applications. The key is that it’s designed for applications that don’t benefit from caching, and it uses static anycast IP addresses to provide consistent access points. This allows for rapid failover and minimizes latency by routing traffic to the closest available endpoint, which is crucial for latency-sensitive applications. The architecture is designed to handle dynamic routing and automatically adapt to network changes, ensuring high availability and performance. This is a fundamental difference from simply relying on DNS resolution, which can introduce delays and inconsistencies. Strong answer: Global Accelerator uses static anycast IP addresses from the AWS edge network and routes traffic to healthy endpoints over the AWS global network.

  • anycast IP addresses
  • healthy endpoints
  • AWS global network
  • latency-sensitive applications
  • failover

Caution: Do not restate the multiple-choice stem or ask the learner merely to name a product, rule, or term.

Objective/domain: 3. Network Management and Operation (20%)

Source: How AWS Global Accelerator works

Question 2 A company has redundant Direct Connect VIFs and wants to validate failover during a maintenance window without physically disconnecting a circuit. Which AWS feature is designed for this test?

Answer choices

  1. A. Reachability Analyzer against the Direct Connect router.
  2. B. Direct Connect Resiliency Toolkit failover testing.
  3. C. Route 53 health-check inversion.
  4. D. VPC Traffic Mirroring on the VIF.

Correct answer

Direct Connect Resiliency Toolkit failover testing.

Objective/domain: 3. Network Management and Operation (20%)

Source: Direct Connect Failover Test

Question 3 A very aggressive WAF rate-based rule stops an HTTP flood almost immediately. The team notices Shield Advanced recorded less attack detail than expected. Which tradeoff is documented?

Answer choices

  1. A. WAF rate-based rules disable all Shield Advanced protections permanently.
  2. B. Shield Advanced ignores all traffic that passes through a web ACL.
  3. C. Rate-based rules operate only on TCP SYN packets and never HTTP requests.
  4. D. A fast rate-based rule can block the flood before Shield Advanced observes enough traffic to fully detect the event, favoring prevention over visibility.

Correct answer

A fast rate-based rule can block the flood before Shield Advanced observes enough traffic to fully detect the event, favoring prevention over visibility.

Objective/domain: 4. Network Security, Compliance, and Governance (24%)

Source: Protecting the application layer with AWS WAF web ACLs and Shield Advanced

Question 4 A research university is redesigning its AWS network. Internet users and VPC workloads query the same FQDN, but VPC workloads must receive private load-balancer addresses. The change must minimize operational overhead and avoid manual failover steps. Return different answers based on whether the query is resolved inside the associated VPC. Which design should the network specialist recommend?

Answer choices

  1. A. Use a Route 53 public hosted zone and a same-name private hosted zone associated with the VPCs.
  2. B. Use two same-name public hosted zones and depend on resolver order.
  3. C. Put private RFC1918 records in the public hosted zone.
  4. D. Use a network ACL to rewrite public DNS answers for VPC clients.

Correct answer

Use a Route 53 public hosted zone and a same-name private hosted zone associated with the VPCs.

Objective/domain: 2. Network Implementation (26%)

Source: Considerations when working with a private hosted zone

Question 5 A global payments company is redesigning its AWS network. Users worldwide download cacheable images, JavaScript, and software artifacts from an HTTP origin. The change must minimize operational overhead and avoid manual failover steps. Reduce latency and origin load by serving cacheable content from edge locations. Which design should the network specialist recommend?

Answer choices

  1. A. Use an Amazon CloudFront distribution with appropriate cache behaviors.
  2. B. Use AWS Global Accelerator with the HTTP origin as the only endpoint.
  3. C. Use Route 53 latency-based routing directly to the origin.
  4. D. Place the origin behind a Network Load Balancer only.

Correct answer

Use an Amazon CloudFront distribution with appropriate cache behaviors.

Objective/domain: 1. Network Design (30%)

Source: What is Amazon CloudFront?

Question 6 A government contractor is redesigning its AWS network. A company requires Layer 2 encryption on the physical Direct Connect segment and is evaluating MACsec. The change must minimize operational overhead and avoid manual failover steps. Choose a design that matches Direct Connect MACsec support boundaries. Which design should the network specialist recommend?

Answer choices

  1. A. Use MACsec on a supported dedicated Direct Connect connection or supported LAG and configure matching CKN/CAK material on both ends.
  2. B. Use MACsec as a replacement for end-to-end application TLS across all network segments.
  3. C. Enable MACsec on a public VIF without verifying whether the underlying physical connection supports it.
  4. D. Assume MACsec is supported on every hosted Direct Connect connection.

Correct answer

Use MACsec on a supported dedicated Direct Connect connection or supported LAG and configure matching CKN/CAK material on both ends.

Objective/domain: 4. Network Security, Compliance, and Governance (24%)

Source: MAC Security in Direct Connect

Question 7 A healthcare SaaS provider is redesigning its AWS network. A central network team wants automated remediation when managed network resources drift from approved infrastructure definitions. The change must minimize operational overhead and avoid manual failover steps. Automate detection and correction while retaining a declarative source of truth and reviewable changes. Which design should the network specialist recommend?

Answer choices

  1. A. Use infrastructure as code as the source of truth, detect drift/events, and invoke controlled automation to reconcile approved configuration.
  2. B. Allow event handlers to create arbitrary network resources with no template or policy boundary.
  3. C. Disable drift detection and rely on weekly manual comparisons.
  4. D. Hardcode VPC, subnet, and account identifiers inside every remediation function.

Correct answer

Use infrastructure as code as the source of truth, detect drift/events, and invoke controlled automation to reconcile approved configuration.

Objective/domain: 2. Network Implementation (26%)

Source: CloudFormation best practices

Question 8 An insurance provider is redesigning its AWS network. An application has active endpoints in two Regions and must direct users away from an unhealthy primary while keeping DNS-based traffic management. The change must minimize operational overhead and avoid manual failover steps. Provide DNS-level health-aware failover with a controlled primary and secondary relationship. Which design should the network specialist recommend?

Answer choices

  1. A. Use Route 53 failover records associated with health checks for the application endpoints.
  2. B. Use a private hosted zone without health checks for public internet clients.
  3. C. Use a security group to change DNS answers when the primary fails.
  4. D. Use Route 53 simple records with very long TTLs.

Correct answer

Use Route 53 failover records associated with health checks for the application endpoints.

Objective/domain: 1. Network Design (30%)

Source: How Amazon Route 53 chooses records when health checking is configured

Question 9 A Traffic Mirroring source produces more packets than the analysis appliance can handle. Which built-in control should be used before scaling the appliance?

Answer choices

  1. A. Reduce the VPC route-table MTU.
  2. B. Change the source ENI security group to deny the traffic after it has been mirrored.
  3. C. Narrow the traffic mirror filter so only relevant protocols, ports, or address ranges are mirrored.
  4. D. Lower the DNS TTL of the mirror target.

Correct answer

Narrow the traffic mirror filter so only relevant protocols, ports, or address ranges are mirrored.

Objective/domain: 4. Network Security, Compliance, and Governance (24%)

Source: What is Traffic Mirroring?

Question 10 A private IP VPN over Direct Connect is attached to Transit Gateway. The architect wants some VPC-to-on-premises flows encrypted and other flows to use the underlying Direct Connect path unencrypted. Does the architecture allow separate routing for the VPN and Direct Connect attachments?

Answer choices

  1. A. No. Creating the private IP VPN forces every Transit Gateway route over IPsec.
  2. B. No. A transit VIF is disabled as soon as the VPN attachment is created.
  3. C. Yes. The VPN attachment route table can be the same as or different from the underlying Direct Connect attachment route table, allowing encrypted and unencrypted routing choices.
  4. D. Yes, but only by using a public VIF for the unencrypted traffic.

Correct answer

Yes. The VPN attachment route table can be the same as or different from the underlying Direct Connect attachment route table, allowing encrypted and unencrypted routing choices.

Objective/domain: 2. Network Implementation (26%)

Source: Private IP AWS Site-to-Site VPN with Direct Connect

Where to go after the daily web set

How are AWS Advanced Networking Specialty questions generated?

dotCreds builds AWS Advanced Networking Specialty practice questions from public exam objectives and AWS certification and documentation references. The questions are written for realistic study practice, not copied from exam dumps.

How are explanations sourced?

Each question includes an explanation and, when available, a source link back to the provider documentation or reference used to validate the answer. That keeps the practice tied to study material you can actually review.

What score do I get?

The page tracks today's answered count and accuracy for the 10-question daily set, then saves a 7-day score history on this device so you can see your recent practice trend.

Why use this site?

The site is the fastest way to start AWS Advanced Networking Specialty practice without installing anything. It is built for daily recall, quick weak-topic discovery, and source-backed explanations you can review immediately.