4.0 Network Security, Compliance, and Governance ANS-C01 Practice Quiz

144 exam-style questions covering 24% of the ANS-C01 exam. Instant feedback on every answer, progress tracking, no signup required.

This domain is part of the AWS Certified Advanced Networking Specialty practice test. Each question is tagged by exam objective and difficulty so you can drill exactly the areas you need.

Sample Questions

A public application behind an ALB receives HTTP floods and SQL injection attempts. Which control should be placed at the edge or load balancer path?
  • A. AWS WAF with managed rules, rate-based rules, and logging for the web ACL
  • B. S3 Lifecycle expiration for access logs
  • C. VPC peering between the internet and the application VPC
  • D. An IAM password policy for application users only

AWS WAF can inspect HTTP requests, block common web exploits, rate-limit abusive clients, and provide rule-level logs.

A public API needs throttling and request validation before traffic reaches private services. Which service combination is appropriate?
  • A. Amazon API Gateway with authorizers, throttling, AWS WAF, and private integration as needed
  • B. An ALB target group stickiness setting
  • C. Security group egress rules on database instances only
  • D. A Route 53 private hosted zone for the public hostname

API Gateway and AWS WAF can enforce web request controls while keeping backend services private.

A gaming service uses UDP on custom ports and is exposed through public endpoints. The team needs DDoS protection beyond web-layer rules. What should be enabled?
  • A. Transit Gateway route propagation without inspection
  • B. AWS Shield Advanced with appropriate protected resources and response runbooks
  • C. An ALB target group stickiness setting
  • D. Security group egress rules on database instances only

Shield Advanced adds enhanced DDoS detection, mitigation support, and operational protections for eligible public resources.

A compliance rule requires TLS and approved ciphers for inbound HTTPS. Which setting should be maintained?
  • A. NAT gateway routing for inbound clients
  • B. Load balancer listener TLS security policies and ACM certificates that meet the compliance baseline
  • C. S3 Lifecycle expiration for access logs
  • D. VPC peering between the internet and the application VPC

Listener security policies and certificates determine the inbound TLS versions, ciphers, and server identity.

A workload should access only approved external domains over HTTP and HTTPS. What design supports this?
  • A. S3 object lock on firewall logs only
  • B. Egress proxy or firewall policy with domain-aware controls and logging
  • C. VPC peering to an external SaaS provider
  • D. A public hosted zone with lower TTL values

Domain-aware egress controls can restrict destinations while providing evidence for review.

Inbound internet traffic must pass through centralized inspection before reaching application VPCs. What architecture fits?
  • A. A Route 53 private hosted zone for the public hostname
  • B. NAT gateway routing for inbound clients
  • C. Ingress routing through a perimeter VPC using AWS Network Firewall or Gateway Load Balancer appliances
  • D. S3 Lifecycle expiration for access logs

A perimeter inspection layer can enforce policy before traffic reaches application subnets.

A network firewall must inspect inbound traffic before it reaches a three-tier application. What must route tables enforce?
  • A. An IAM password policy for application users only
  • B. Transit Gateway route propagation without inspection
  • C. Routes from ingress subnets to inspection endpoints before application subnet targets
  • D. An ALB target group stickiness setting

Inspection is effective only when route tables make the firewall part of the inbound traffic path.

An internet-facing ALB should not be reachable directly except through CloudFront and AWS WAF. What should be configured?
  • A. VPC peering between the internet and the application VPC
  • B. An IAM password policy for application users only
  • C. Transit Gateway route propagation without inspection
  • D. Origin access controls such as security group restrictions, custom headers, or AWS-managed prefix lists as applicable

Direct origin access must be constrained so clients cannot bypass edge inspection and filtering controls.

Key Terms in This Domain

Link to this quiz

Studying with a group or teaching a class? Send this address or paste the link into your notes, wiki, or course page:

https://quizbuffet.com/aws-advanced-networking-specialty/network-security-compliance-and-governance/

<a href="https://quizbuffet.com/aws-advanced-networking-specialty/network-security-compliance-and-governance/">AWS Advanced Networking Specialty Network Security, Compliance, and Governance practice quiz on QuizBuffet</a>

Other ANS-C01 Domains

← Back to ANS-C01 practice test overview

Questions are written against the published ANS-C01 objectives and checked for accuracy and balance before they go live. How QuizBuffet writes and reviews its questions.