2.0 Network Implementation ANS-C01 Practice Quiz
156 exam-style questions covering 26% of the ANS-C01 exam. Instant feedback on every answer, progress tracking, no signup required.
This domain is part of the AWS Certified Advanced Networking Specialty practice test. Each question is tagged by exam objective and difficulty so you can drill exactly the areas you need.
Sample Questions
A Direct Connect dedicated connection has been ordered and the colocation provider is ready to patch the circuit. What must be supplied to complete the physical handoff?
- A. Provide the LOA-CFA and confirm the port location, cross-connect details, optics, and speed settings
- B. Use a single hosted zone for both internet and split-horizon private records without separation
- C. Disable VPC route propagation and manage every prefix manually at scale
- D. Use ALB access logs as the primary source for VPC-internal east-west traffic analysis
The facility can complete the cross-connect only when the authorization, port assignment, and physical interface details align.
A replication workload will use jumbo frames over Direct Connect. What must be validated before production traffic is moved?
- A. End-to-end MTU compatibility across routers, VIFs, AWS paths, and instances
- B. Skip BFD and rely on default BGP keepalive timers for sub-second failover
- C. Use a single shared CDK app deployed manually for production and dev
- D. Advertise the same prefix from every BGP peer with identical attributes
Large frames work only when every segment in the data path supports the selected MTU.
A company wants two 10 Gbps Direct Connect connections to behave as a single logical bundle. What should the engineer create?
- A. Treat AWS PrivateLink as a layer 3 routed mesh between VPCs
- B. A Direct Connect link aggregation group using compatible dedicated connections
- C. Use AWS Firewall Manager only after each account opts in individually with no central policy
- D. Use ACM-imported certificates without renewal monitoring or alerting
A link aggregation group combines supported Direct Connect circuits for a single logical bundle with greater aggregate capacity.
The AWS Direct Connect port is available, but the customer router does not show link up. What should be checked first?
- A. Use an external CA without ACM Private CA for AWS-native certificate distribution
- B. Cross-connect status, optics, cabling, speed, duplex, and interface state
- C. Use a Site-to-Site VPN as the only path for sustained 10 Gbps throughput
- D. Use AWS PrivateLink to share full IP-level connectivity between two VPCs
A physical link failure is most likely corrected by verifying the facility patch, transceivers, and interface negotiation.
A static VPN route to a newly added on-premises CIDR is missing. What action is required?
- A. Use sticky sessions to compensate for missing identity tokens in API calls
- B. Add the new CIDR to the VPN static routes and update corresponding on-premises routing
- C. Skip CloudFormation drift detection and trust manual change tickets
- D. Use a Direct Connect public VIF to reach a private VPC subnet
Static routing does not learn new prefixes automatically, so each side must include the new destination.
A private virtual interface remains down after the circuit comes up. Which settings should be matched on the customer router?
- A. Place the customer gateway IP inside the VPC CIDR range
- B. Choose subnets without ENA-supported instance types for high packet-per-second workloads
- C. VLAN tag, BGP peer addresses, ASN, authentication if used, and allowed prefixes
- D. Create a public hosted zone to serve only VPC-internal DNS queries
A VIF requires the logical VLAN and BGP parameters to match before route exchange can occur.
A design requires resilience to a colocation facility failure. What implementation meets the requirement?
- A. Use the AWS CLI from a developer laptop as the production deployment automation tool
- B. Use an ALB host-based routing rule to load balance non-HTTP TCP services
- C. Provision redundant Direct Connect connections in separate locations with diverse customer equipment where possible
- D. Use Global Accelerator to reduce data egress charges to on-premises
Facility and equipment diversity reduces the chance that one site or router failure removes all private connectivity.
A hosted connection appears in the customer account but cannot be used yet. What is the required AWS-side step?
- A. Use AS_PATH prepending to make a path more preferred than its peer
- B. Use Route 53 Resolver outbound endpoints inside an isolated subnet without on-prem reachability
- C. Use DNS TTL values as a hybrid routing protocol
- D. Accept the hosted connection and create the required virtual interface
Hosted connectivity is not usable by the customer account until it is accepted and a VIF is configured.
Key Terms in This Domain
- AWS Direct Connect: Dedicated 1/10/100 Gbps physical connection from on-premises to AWS
- VPC peering: One-to-one VPC connection without transitive routing
- BGP: Border Gateway Protocol: exchanges routes over DX/VPN
- AWS Transit Gateway: Hub for connecting VPCs and on-premises networks at scale
- Route 53 routing policies: Simple, weighted, latency, geolocation, geoproximity, multi-value, failover
- Route 53 traffic policies: Versioned DNS routing decision trees with multiple policies
- Route 53 Resolver: Recursive DNS for VPCs (.2 resolver) and hybrid endpoints
- Route 53 Resolver inbound endpoint: Lets on-premises DNS query AWS DNS over Direct Connect/VPN
- Route 53 Resolver outbound endpoint: Forwards VPC DNS queries to on-premises resolvers
- AWS Global Accelerator: Static anycast IPs that route over the AWS global network to nearest endpoint
Link to this quiz
Studying with a group or teaching a class? Send this address or paste the link into your notes, wiki, or course page:
https://quizbuffet.com/aws-advanced-networking-specialty/network-implementation/
<a href="https://quizbuffet.com/aws-advanced-networking-specialty/network-implementation/">AWS Advanced Networking Specialty Network Implementation practice quiz on QuizBuffet</a>
Other ANS-C01 Domains
- 1.0 Network Design
- 3.0 Network Management and Operation
- 4.0 Network Security, Compliance, and Governance
← Back to ANS-C01 practice test overview
Questions are written against the published ANS-C01 objectives and checked for accuracy and balance before they go live. How QuizBuffet writes and reviews its questions.