1.0 Network Design ANS-C01 Practice Quiz
180 exam-style questions covering 30% of the ANS-C01 exam. Instant feedback on every answer, progress tracking, no signup required.
This domain is part of the AWS Certified Advanced Networking Specialty practice test. Each question is tagged by exam objective and difficulty so you can drill exactly the areas you need.
Sample Questions
A company is designing global inbound content distribution design. The requirement is low latency, high availability, and clear operational ownership. Which design should the network specialist recommend?
- A. CloudFront or Global Accelerator selected according to cacheability, protocol, static IP, failover, and origin-protection requirements
- B. Rely on default BGP timers for sub-second failover detection
- C. Use VPC interface endpoints to expose your services to the public internet
- D. Use NAT gateway in every private subnet to maximize redundancy and minimize latency
CloudFront or Global Accelerator selected according to cacheability, protocol, static IP, failover, and origin-protection requirements is appropriate for global inbound content distribution design. It matches the traffic pattern and avoids adding unrelated control planes.
A hybrid and cloud networking team is choosing a pattern for global inbound content distribution design. The constraint is overly broad network reachability between unrelated environments. Which recommendation is most appropriate?
- A. CloudFront or Global Accelerator selected according to cacheability, protocol, static IP, failover, and origin-protection requirements
- B. Use CloudTrail to detect packet-level anomalies in VPC traffic
- C. Use the AWS CLI from a developer laptop as the production deployment automation tool
- D. Use a Route 53 alias record pointing to an on-premises IP
CloudFront or Global Accelerator selected according to cacheability, protocol, static IP, failover, and origin-protection requirements is appropriate for global inbound content distribution design. It keeps the data path aligned with the required scope and failure model.
A proposed architecture for global inbound content distribution design causes overly broad network reachability between unrelated environments. Which change best aligns with the requirement?
- A. Use an ACM public certificate to sign internal mTLS traffic between EC2 instances
- B. CloudFront or Global Accelerator selected according to cacheability, protocol, static IP, failover, and origin-protection requirements
- C. Configure DNSSEC by adding a TXT record only, without DS or KSK setup
- D. Use AWS Organizations as a routing protocol between VPCs
CloudFront or Global Accelerator selected according to cacheability, protocol, static IP, failover, and origin-protection requirements is appropriate for global inbound content distribution design. It addresses the stated availability and operational constraints directly.
An application migration depends on global inbound content distribution design. The target architecture requires controlled failover and predictable traffic paths during impairment. Which design decision is correct?
- A. Disable VPC route propagation and manage every prefix manually at scale
- B. CloudFront or Global Accelerator selected according to cacheability, protocol, static IP, failover, and origin-protection requirements
- C. Use Route 53 weighted records to bypass CloudFront cache invalidation
- D. Replace Reachability Analyzer with manual ping tests from a single jump host
CloudFront or Global Accelerator selected according to cacheability, protocol, static IP, failover, and origin-protection requirements is appropriate for global inbound content distribution design. It reduces unnecessary exposure while preserving the required connectivity behavior.
A multi-account AWS environment must support global outbound content distribution design while meeting low latency, high availability, and clear operational ownership. What should be included in the design?
- A. Disable BGP MD5 authentication on a Direct Connect connection
- B. Controlled egress through NAT gateways, centralized inspection, VPC endpoints, or caching repositories according to destination and security requirements
- C. Use AWS PrivateLink to share full IP-level connectivity between VPCs
- D. Use AWS Config to capture per-packet flow data
controlled egress through NAT gateways, centralized inspection, VPC endpoints, or caching repositories according to destination and security requirements is appropriate for global outbound content distribution design. It uses AWS networking features for the purpose they are designed to serve.
During design review, the team identifies controlled failover and predictable traffic paths during impairment for global inbound content distribution design. Which option provides the most appropriate AWS networking design?
- A. Deploy CloudFront origins as private resources without OAC or signed origins
- B. Use a security group as the authoritative DNS zone
- C. CloudFront or Global Accelerator selected according to cacheability, protocol, static IP, failover, and origin-protection requirements
- D. Disable AWS Shield Standard to reduce baseline latency
CloudFront or Global Accelerator selected according to cacheability, protocol, static IP, failover, and origin-protection requirements is appropriate for global inbound content distribution design. It gives the architecture a supportable control point for scaling and troubleshooting.
A company is designing global outbound content distribution design. The requirement is low latency, high availability, and clear operational ownership. Which design should the network specialist recommend?
- A. Disable health checks to reduce latency to backend targets
- B. Place all NAT gateways in a single AZ for the entire Region
- C. Controlled egress through NAT gateways, centralized inspection, VPC endpoints, or caching repositories according to destination and security requirements
- D. Use sticky sessions to compensate for missing identity tokens in API calls
controlled egress through NAT gateways, centralized inspection, VPC endpoints, or caching repositories according to destination and security requirements is appropriate for global outbound content distribution design. It matches the traffic pattern and avoids adding unrelated control planes.
A multi-account AWS environment must support global inbound content distribution design while meeting low latency, high availability, and clear operational ownership. What should be included in the design?
- A. Use Reachability Analyzer to send synthetic TCP traffic and measure RTT
- B. Use an Application Load Balancer for ultra-low latency UDP gaming traffic
- C. Use a Network Load Balancer in place of CloudFront for global static content
- D. CloudFront or Global Accelerator selected according to cacheability, protocol, static IP, failover, and origin-protection requirements
CloudFront or Global Accelerator selected according to cacheability, protocol, static IP, failover, and origin-protection requirements is appropriate for global inbound content distribution design. It uses AWS networking features for the purpose they are designed to serve.
Key Terms in This Domain
- Gateway Load Balancer: Layer 3/4 ELB using GENEVE for inline third-party network appliances
- Direct Connect Gateway: Globally accessible DX hub linking VIFs to multiple VPCs/Regions
- Transit Gateway Network Manager: Topology, events, and metrics across global AWS networks
- Route 53 traffic policies: Versioned DNS routing decision trees with multiple policies
- AWS Global Accelerator: Static anycast IPs that route over the AWS global network to nearest endpoint
- Network Load Balancer: Layer 4 ELB for ultra-low latency TCP/UDP/TLS, static IPs, PrivateLink
- Classic Load Balancer: Legacy ELB; superseded by ALB/NLB for new designs
- Route table: Set of routes that direct subnet traffic to next-hop targets
- NAT Gateway: Managed source NAT for outbound IPv4 traffic from private subnets
- Egress-only Internet Gateway: Outbound-only internet gateway for IPv6 traffic
Link to this quiz
Studying with a group or teaching a class? Send this address or paste the link into your notes, wiki, or course page:
https://quizbuffet.com/aws-advanced-networking-specialty/network-design/
<a href="https://quizbuffet.com/aws-advanced-networking-specialty/network-design/">AWS Advanced Networking Specialty Network Design practice quiz on QuizBuffet</a>
Other ANS-C01 Domains
- 2.0 Network Implementation
- 3.0 Network Management and Operation
- 4.0 Network Security, Compliance, and Governance
← Back to ANS-C01 practice test overview
Questions are written against the published ANS-C01 objectives and checked for accuracy and balance before they go live. How QuizBuffet writes and reviews its questions.