dc dotCreds
AWS Certified Advanced Networking – Specialty Practice Test

AWS Advanced Networking Specialty Practice Test

Start today’s free 10-question AWS Advanced Networking Specialty set with source-backed explanations, local progress, and a fresh rotation every morning.

10 Free Daily Questions Source-backed Explanations 200 Verified Questions

Questions updated at Aug 23, 2026, 8:12 PM CDT

Go Pro - One Time Unlock

Unlock the full ANS-C01 bank

200 verified questions Exam Mode Practice Mode Detailed explanations Weak-area review No subscription - one-time unlock

Get the complete source-backed bank with Interview Questions, the full Study Guide, full Course Notes, detailed explanations, weak-area review, and exam-style practice.

Interview Questions Full Study Guide Full Course Notes Exam Mode Practice Mode Guided Course Detailed explanations Weak-area review No subscription
$4.99 One-time payment
See bundle and PDF options

We will confirm your site email in one quick checkout step.

Why DotCreds?

Practice with explanations that teach.

Source links for every answer Every wrong answer explained Guided Course included Practice and Exam Mode Weak-area tracking Same verified bank across web practice

What you get with free practice

10 Free Questions Daily Fresh set every day from the live bank
Detailed Explanations Learn with clear source-backed answers
Track Your Progress Daily history and performance insights
Upgrade Anytime Unlock the full bank when you are ready
Today's 10 AWS Advanced Networking Specialty questions

Use this AWS Advanced Networking Specialty practice test to review AWS Certified Advanced Networking – Specialty. Questions rotate daily and each answer links back to the source used to write it.

Today’s Set
10 questions
Rotates at 10:00 AM local time
Progress
0/10
Answered on this page
Accuracy
0%
Loading countdown…

200 verified questions are in the live bank. Free daily questions are selected from a rotating sample set. Unlock Pro to access the full question bank.

Preparing today’s free questions... Ordering the final locked-bank set before showing the practice cards.
Question 1 of 10
Objective Task 4.1: Implement and maintain network features to meet security and compliance needs and requirements 4. Network Security, Compliance, and Governance (24%)

A centralized inspection VPC receives east-west traffic through Transit Gateway and uses stateful Network Firewall endpoints. Forward traffic crosses one firewall AZ, but return traffic can arrive through another path. What design requirement is being violated?

Concept tested:
Question 2 of 10
Objective Task 2.1: Implement routing and connectivity between on-premises networks and the AWS Cloud 2. Network Implementation (26%)

A Site-to-Site VPN connection has two AWS-provided tunnels, but the customer router is configured for only one. The business wants maintenance on one AWS tunnel endpoint to avoid an outage. What should be changed?

Concept tested:
Question 3 of 10
Objective Task 3.3: Optimize AWS networks for performance, reliability, and cost-effectiveness 3. Network Management and Operation (20%)

A standard Global Accelerator has two endpoints in one endpoint group. The operator wants 90% of that Region's accelerator traffic to one endpoint and 10% to the other. Which control applies inside the endpoint group?

Concept tested:
Question 4 of 10
Objective Task 1.6: Design a routing strategy and connectivity architecture that include multiple AWS accounts, AWS Regions, and VPCs to support different connectivity patterns 1. Network Design (30%)

A VPC attachment is associated with Transit Gateway route table A. Its routes are propagated into route table B for other attachments to learn. Does propagation also change the VPC attachment's association to table B?

Concept tested:
Question 5 of 10
Objective Task 4.3: Implement and maintain confidentiality of data and communications of the network 4. Network Security, Compliance, and Governance (24%)

A multinational manufacturer is redesigning its AWS network. An HTTPS application needs managed certificate deployment at the load balancer and Layer 7 routing after decryption. The change must minimize operational overhead and avoid manual failover steps. Terminate client TLS at the load balancer and route HTTP requests by application rules. Which design should the network specialist recommend?

Concept tested:
Question 6 of 10
Objective Task 2.2: Implement routing and connectivity across multiple AWS accounts, Regions, and VPCs to support different connectivity patterns 2. Network Implementation (26%)

A marketplace operator is redesigning its AWS network. Two non-overlapping VPCs are peered. The peering connection is active, but instances still cannot exchange private IPv4 traffic. The change must minimize operational overhead and avoid manual failover steps. Complete the minimum routing configuration for bidirectional peering connectivity. Which design should the network specialist recommend?

Concept tested:
Question 7 of 10
Objective Task 3.2: Monitor and analyze network traffic to troubleshoot and optimize connectivity patterns 3. Network Management and Operation (20%)

A new Large Bandwidth Site-to-Site VPN tunnel is configured at 5 Gbps. The team assumes the larger bandwidth option also raises the tunnel MTU above 1500 bytes. Is that assumption correct?

Concept tested:
Question 8 of 10
Objective Task 1.3: Design solutions that integrate load balancing to meet high availability, scalability, and security requirements 1. Network Design (30%)

An ALB listener has multiple path rules plus a default rule. A request does not match any configured path condition. What happens?

Concept tested:
Question 9 of 10
Objective Task 4.2: Validate and audit security by using network monitoring and logging services 4. Network Security, Compliance, and Governance (24%)

A Traffic Mirroring source produces more packets than the analysis appliance can handle. Which built-in control should be used before scaling the appliance?

Concept tested:
Question 10 of 10
Objective Task 2.4: Automate and configure network infrastructure 2. Network Implementation (26%)

A healthcare SaaS provider is redesigning its AWS network. A central network team wants automated remediation when managed network resources drift from approved infrastructure definitions. The change must minimize operational overhead and avoid manual failover steps. Automate detection and correction while retaining a declarative source of truth and reviewable changes. Which design should the network specialist recommend?

Concept tested:
Locked preview

You are viewing today’s free 10. Unlock 190 more questions.

Unlock full bank
Daily sample Rotating practice Free daily questions are selected from a rotating sample set.
Pro bank Full access Unlock Pro to access the full question bank, Exam Mode, Practice Mode, and random tests.
ANS-C01 Pro $4.99 one-time

50 Exam Practice Test $1.99 one-time

A 50-question ANS-C01 PDF for short review sessions. Questions come first, then the answer review and explanations later in the file.

AWS Security & Networking Bundle $9.99 one-time

Unlock all 3 active AWS Security & Networking Bundle practice banks in one permanent purchase.

What’s includedAWS Security Specialty, AWS Advanced Networking Specialty, AWS SAA-C03
All Access $6.99/month

Unlock every active practice exam, bundle and path experience, Pro course and study content, and included downloads.

What’s includedEvery current and future active practice exam, All active bundle and career-path practice content, Pro course lessons, study content, and supported paid downloads

Choose an unlock option to continue. We will confirm your site email in one quick checkout step.

Secure checkout powered by Stripe. Source-backed questions. Not brain dumps. Checkout stays on this page and unlocks the same Pro builder on this practice page.

Purchase options

Unlock the full ANS-C01 bank.

Get the full bank, Exam Mode, Practice Mode, question sets, random tests, readiness tracking, saved box scores, and review tools for this exam.

The PDF versions keep questions first and move the answer review, explanations, and distractor notes to the back of the file.

200 verified exam-style questions Every choice explained Exam Mode and Practice Mode Question sets and random tests Readiness score and trends Previous test box scores

You've answered 0/10 questions in today's set.

Locked: 190 more questions in the full bank.

Locked: exam simulation mode, practice mode, readiness tracking, and saved review history.

Checkout stays on this page, so you can keep practicing, unlock the full bank, and start Exam Mode or Practice Mode when you are ready.

Cheat Sheets

7-day score keeper

Answer questions today and this will become a rolling 7-day scorecard.

Local history
Optional progress sync

Keep today’s practice moving

Guest progress saves automatically on this device. Add an email later when you want a magic link that keeps your daily ANS-C01 practice in sync across browsers.

Guest progress saves on this device automatically

Guest progress is available without an account.

Source-backed answer review

The free daily AWS Advanced Networking Specialty set includes crawlable question text, answer choices, correct answer labels, objective mapping, and source links. Only the first SEO card includes answer explanations and any extra learning features. Pro-only bank questions stay locked; this section mirrors only the 10 free daily questions already shown on this page.

Question 1 A centralized inspection VPC receives east-west traffic through Transit Gateway and uses stateful Network Firewall endpoints. Forward traffic crosses one firewall AZ, but return traffic can arrive through another path. What design requirement is being violated?

Answer choices

  1. A. Network Firewall requires every flow to be intentionally asymmetric for scale, under the documented operational and governance requirements.
  2. B. Stateful inspection requires symmetric routing so both directions of a flow traverse the corresponding firewall path consistently, for the affected environment.
  3. C. Route 53 must resolve both directions to the same firewall IP, for the described technical objective and its associated operational control requirements, in practice.
  4. D. The firewall must be replaced with a stateless security group, as the recommended implementation across the complete governed service lifecycle.

Correct answer

Stateful inspection requires symmetric routing so both directions of a flow traverse the corresponding firewall path consistently, for the affected environment.

Stateful firewall engines must observe both directions of a connection; centralized routing must preserve symmetric flow paths. The strongest competing option fails because stateful firewall processing depends on seeing both directions of the connection; arbitrary asymmetry breaks state tracking.

Wrong-answer review

  • A. Network Firewall requires every flow to be intentionally asymmetric for scale, under the documented operational and governance requirements.: Incorrect. Stateful firewall processing depends on seeing both directions of the connection; arbitrary asymmetry breaks state tracking.
  • C. Route 53 must resolve both directions to the same firewall IP, for the described technical objective and its associated operational control requirements, in practice.: Incorrect. The problem is IP routing symmetry through stateful inspection, not DNS answer symmetry.
  • D. The firewall must be replaced with a stateless security group, as the recommended implementation across the complete governed service lifecycle.: Incorrect. Security groups do not replace a centralized Network Firewall inspection architecture.

Extra learning features

Why candidates miss this

The distractor ‘Route 53 must resolve both directions to the same firewall IP’ is tempting because it touches on DNS and routing. However, the core issue is the *stateful* inspection requirement, not DNS resolution. The decisive clue is the emphasis on ‘symmetric routing’ in the correct answer, indicating the need for consistent flow paths through the firewall. Likely wrong answer: Route 53 must resolve both directions to the same firewall IP. Review focus: Avoiding asymmetric routing with AWS Network Firewall

Objective/domain: 4. Network Security, Compliance, and Governance (24%)

Source: Avoiding asymmetric routing with AWS Network Firewall

Question 2 A Site-to-Site VPN connection has two AWS-provided tunnels, but the customer router is configured for only one. The business wants maintenance on one AWS tunnel endpoint to avoid an outage. What should be changed?

Answer choices

  1. A. Increase the IKE lifetime on the single configured tunnel, for the described technical objective and its associated operational control requirements, as proposed.
  2. B. Configure both VPN tunnels on the customer gateway and make both eligible to carry traffic, within the described operational context.
  3. C. Create two static routes that both point to the same configured tunnel, as the primary implementation for the described business requirement.
  4. D. Disable tunnel endpoint updates in AWS, within the documented operational, security, ownership, and validation requirements.

Correct answer

Configure both VPN tunnels on the customer gateway and make both eligible to carry traffic, within the described operational context.

Objective/domain: 2. Network Implementation (26%)

Source: Tunnel options for your AWS Site-to-Site VPN connection

Question 3 A standard Global Accelerator has two endpoints in one endpoint group. The operator wants 90% of that Region's accelerator traffic to one endpoint and 10% to the other. Which control applies inside the endpoint group?

Answer choices

  1. A. Set the endpoint-group traffic dial to 90 and 10 simultaneously, for evaluation.
  2. B. Set Route 53 weighted records for the accelerator static IP addresses.
  3. C. Configure endpoint weights, for the described technical objective and its associated operational control requirements.
  4. D. Set different CloudFront cache TTLs for the two endpoints, for the stated requirement.

Correct answer

Configure endpoint weights, for the described technical objective and its associated operational control requirements.

Objective/domain: 3. Network Management and Operation (20%)

Source: How AWS Global Accelerator works

Question 4 A VPC attachment is associated with Transit Gateway route table A. Its routes are propagated into route table B for other attachments to learn. Does propagation also change the VPC attachment's association to table B?

Answer choices

  1. A. Yes. An attachment must be associated with every route table to which it propagates, for the described technical objective and its associated operational control requirements, for this task.
  2. B. Yes, but only for inter-Region peering attachments, for the described technical objective and its associated operational control requirements, within the . network design (30%) context.
  3. C. No. Association and propagation are separate; an attachment is associated with one route table while its routes can propagate to other route tables.
  4. D. No, because Transit Gateway route tables cannot accept propagated routes, for the described technical objective and its associated operational control requirements, for the required . network design (30%) outcome.

Correct answer

No. Association and propagation are separate; an attachment is associated with one route table while its routes can propagate to other route tables.

Objective/domain: 1. Network Design (30%)

Source: What is AWS Transit Gateway for Amazon VPC?

Question 5 A multinational manufacturer is redesigning its AWS network. An HTTPS application needs managed certificate deployment at the load balancer and Layer 7 routing after decryption. The change must minimize operational overhead and avoid manual failover steps. Terminate client TLS at the load balancer and route HTTP requests by application rules. Which design should the network specialist recommend?

Answer choices

  1. A. Configure an HTTPS listener on an Application Load Balancer with an ACM-managed server certificate and an appropriate security policy, in the described situation.
  2. B. Put the ACM certificate on a Route 53 hosted zone, for the described technical objective and its associated operational control requirements, within the proposed design.
  3. C. Use a network ACL to perform TLS decryption before traffic reaches the ALB, within the defined security and accountability boundaries.
  4. D. Use a Gateway Load Balancer to terminate browser TLS and inspect URL paths, as the primary implementation for the described business requirement.

Correct answer

Configure an HTTPS listener on an Application Load Balancer with an ACM-managed server certificate and an appropriate security policy, in the described situation.

Objective/domain: 4. Network Security, Compliance, and Governance (24%)

Source: Create an HTTPS listener for your Application Load Balancer

Question 6 A marketplace operator is redesigning its AWS network. Two non-overlapping VPCs are peered. The peering connection is active, but instances still cannot exchange private IPv4 traffic. The change must minimize operational overhead and avoid manual failover steps. Complete the minimum routing configuration for bidirectional peering connectivity. Which design should the network specialist recommend?

Answer choices

  1. A. Add routes in the relevant subnet route tables in both VPCs that point the peer CIDR to the peering connection, under end-to-end security-and-governance requirements.
  2. B. Enable transitive routing through a third peered VPC, for the described technical objective and its associated operational control requirements, for the stated implementation and support requirements.
  3. C. Add the peer CIDR only to the source VPC route table, as the primary implementation for the described business requirement.
  4. D. Attach the peering connection to a Transit Gateway route table, for the described technical objective and its associated operational control requirements.

Correct answer

Add routes in the relevant subnet route tables in both VPCs that point the peer CIDR to the peering connection, under end-to-end security-and-governance requirements.

Objective/domain: 2. Network Implementation (26%)

Source: VPC peering

Question 7 A new Large Bandwidth Site-to-Site VPN tunnel is configured at 5 Gbps. The team assumes the larger bandwidth option also raises the tunnel MTU above 1500 bytes. Is that assumption correct?

Answer choices

  1. A. Yes. 5 Gbps tunnels automatically support jumbo frames end to end, within the proposed design.
  2. B. Yes, but only when the VPN is attached to a virtual private gateway, within cross-functional operational-accountability boundaries.
  3. C. No. The documented MTU limit remains 1500 bytes for Large Bandwidth Tunnels, for the affected environment.
  4. D. No, because all Site-to-Site VPN tunnels are limited to 576 bytes, in practice.

Correct answer

No. The documented MTU limit remains 1500 bytes for Large Bandwidth Tunnels, for the affected environment.

Objective/domain: 3. Network Management and Operation (20%)

Source: AWS Site-to-Site VPN

Question 8 An ALB listener has multiple path rules plus a default rule. A request does not match any configured path condition. What happens?

Answer choices

  1. A. The request is automatically sent to every target group registered with the ALB, for the specified implementation requirement.
  2. B. The request is handed to Route 53 for a second routing decision, under end-to-end security-and-governance requirements.
  3. C. The ALB converts the request to a Network Load Balancer flow, for the stated security, delivery, and accountability requirements.
  4. D. The listener applies its default rule and forwards, redirects, or returns the configured default action, for the required business outcome.

Correct answer

The listener applies its default rule and forwards, redirects, or returns the configured default action, for the required business outcome.

Objective/domain: 1. Network Design (30%)

Source: What is an Application Load Balancer?

Question 9 A Traffic Mirroring source produces more packets than the analysis appliance can handle. Which built-in control should be used before scaling the appliance?

Answer choices

  1. A. Reduce the VPC route-table MTU, for the required . network security, compliance, and governance (24%) outcome, for this requirement.
  2. B. Change the source ENI security group to deny the traffic after it has been mirrored, under this approach.
  3. C. Narrow the traffic mirror filter so only relevant protocols, ports, or address ranges are mirrored.
  4. D. Lower the DNS TTL of the mirror target, for the described technical objective and its associated operational control requirements, as described.

Correct answer

Narrow the traffic mirror filter so only relevant protocols, ports, or address ranges are mirrored.

Objective/domain: 4. Network Security, Compliance, and Governance (24%)

Source: What is Traffic Mirroring?

Question 10 A healthcare SaaS provider is redesigning its AWS network. A central network team wants automated remediation when managed network resources drift from approved infrastructure definitions. The change must minimize operational overhead and avoid manual failover steps. Automate detection and correction while retaining a declarative source of truth and reviewable changes. Which design should the network specialist recommend?

Answer choices

  1. A. Use infrastructure as code as the source of truth, detect drift/events, and invoke controlled automation to reconcile approved configuration, for the stated requirement.
  2. B. Allow event handlers to create arbitrary network resources with no template or policy boundary, under the stated technical, operational, and governance constraints.
  3. C. Disable drift detection and rely on weekly manual comparisons, for the described technical objective and its associated operational control requirements.
  4. D. Hardcode VPC, subnet, and account identifiers inside every remediation function, as the primary implementation for the described business requirement.

Correct answer

Use infrastructure as code as the source of truth, detect drift/events, and invoke controlled automation to reconcile approved configuration, for the stated requirement.

Objective/domain: 2. Network Implementation (26%)

Source: CloudFormation best practices

Where to go after the daily web set

How are AWS Advanced Networking Specialty questions generated?

dotCreds builds AWS Advanced Networking Specialty practice questions from public exam objectives and AWS certification and documentation references. The questions are written for realistic study practice, not copied from exam dumps.

How are explanations sourced?

Each question includes an explanation and, when available, a source link back to the provider documentation or reference used to validate the answer. That keeps the practice tied to study material you can actually review.

What score do I get?

The page tracks today's answered count and accuracy for the 10-question daily set, then saves a 7-day score history on this device so you can see your recent practice trend.

Why use this site?

The site is the fastest way to start AWS Advanced Networking Specialty practice without installing anything. It is built for daily recall, quick weak-topic discovery, and source-backed explanations you can review immediately.