4.0 Network Security, Compliance, and Governance ANS-C01 Practice Quiz
144 exam-style questions covering 24% of the ANS-C01 exam. Instant feedback on every answer, progress tracking, no signup required.
This domain is part of the AWS Certified Advanced Networking Specialty practice test. Each question is tagged by exam objective and difficulty so you can drill exactly the areas you need.
Sample Questions
A public application behind an ALB receives HTTP floods and SQL injection attempts. Which control should be placed at the edge or load balancer path?
- A. AWS WAF with managed rules, rate-based rules, and logging for the web ACL
- B. S3 Lifecycle expiration for access logs
- C. VPC peering between the internet and the application VPC
- D. An IAM password policy for application users only
AWS WAF can inspect HTTP requests, block common web exploits, rate-limit abusive clients, and provide rule-level logs.
A public API needs throttling and request validation before traffic reaches private services. Which service combination is appropriate?
- A. Amazon API Gateway with authorizers, throttling, AWS WAF, and private integration as needed
- B. An ALB target group stickiness setting
- C. Security group egress rules on database instances only
- D. A Route 53 private hosted zone for the public hostname
API Gateway and AWS WAF can enforce web request controls while keeping backend services private.
A gaming service uses UDP on custom ports and is exposed through public endpoints. The team needs DDoS protection beyond web-layer rules. What should be enabled?
- A. Transit Gateway route propagation without inspection
- B. AWS Shield Advanced with appropriate protected resources and response runbooks
- C. An ALB target group stickiness setting
- D. Security group egress rules on database instances only
Shield Advanced adds enhanced DDoS detection, mitigation support, and operational protections for eligible public resources.
A compliance rule requires TLS and approved ciphers for inbound HTTPS. Which setting should be maintained?
- A. NAT gateway routing for inbound clients
- B. Load balancer listener TLS security policies and ACM certificates that meet the compliance baseline
- C. S3 Lifecycle expiration for access logs
- D. VPC peering between the internet and the application VPC
Listener security policies and certificates determine the inbound TLS versions, ciphers, and server identity.
A workload should access only approved external domains over HTTP and HTTPS. What design supports this?
- A. S3 object lock on firewall logs only
- B. Egress proxy or firewall policy with domain-aware controls and logging
- C. VPC peering to an external SaaS provider
- D. A public hosted zone with lower TTL values
Domain-aware egress controls can restrict destinations while providing evidence for review.
Inbound internet traffic must pass through centralized inspection before reaching application VPCs. What architecture fits?
- A. A Route 53 private hosted zone for the public hostname
- B. NAT gateway routing for inbound clients
- C. Ingress routing through a perimeter VPC using AWS Network Firewall or Gateway Load Balancer appliances
- D. S3 Lifecycle expiration for access logs
A perimeter inspection layer can enforce policy before traffic reaches application subnets.
A network firewall must inspect inbound traffic before it reaches a three-tier application. What must route tables enforce?
- A. An IAM password policy for application users only
- B. Transit Gateway route propagation without inspection
- C. Routes from ingress subnets to inspection endpoints before application subnet targets
- D. An ALB target group stickiness setting
Inspection is effective only when route tables make the firewall part of the inbound traffic path.
An internet-facing ALB should not be reachable directly except through CloudFront and AWS WAF. What should be configured?
- A. VPC peering between the internet and the application VPC
- B. An IAM password policy for application users only
- C. Transit Gateway route propagation without inspection
- D. Origin access controls such as security group restrictions, custom headers, or AWS-managed prefix lists as applicable
Direct origin access must be constrained so clients cannot bypass edge inspection and filtering controls.
Key Terms in This Domain
- Egress-only Internet Gateway: Outbound-only internet gateway for IPv6 traffic
- Elastic Network Interface (ENI): Virtual NIC with IPs, MAC, and security groups, attachable to EC2
- NAT Gateway: Managed source NAT for outbound IPv4 traffic from private subnets
- Route 53 traffic policies: Versioned DNS routing decision trees with multiple policies
- VPC Reachability Analyzer: Static configuration analysis of network paths between resources
- CloudWatch Logs Insights: Interactive log query language for CloudWatch Logs
- AWS CloudTrail: Records API calls for governance, compliance, and audit
- AWS Network Firewall: Managed stateful firewall, IDS/IPS, and traffic filtering for VPCs
- AWS Firewall Manager: Centrally configure WAF, Shield, security groups, and Network Firewall org-wide
- Amazon VPC: Logically isolated virtual network for AWS resources
Link to this quiz
Studying with a group or teaching a class? Send this address or paste the link into your notes, wiki, or course page:
https://quizbuffet.com/aws-advanced-networking-specialty/network-security-compliance-and-governance/
<a href="https://quizbuffet.com/aws-advanced-networking-specialty/network-security-compliance-and-governance/">AWS Advanced Networking Specialty Network Security, Compliance, and Governance practice quiz on QuizBuffet</a>
Other ANS-C01 Domains
← Back to ANS-C01 practice test overview
Questions are written against the published ANS-C01 objectives and checked for accuracy and balance before they go live. How QuizBuffet writes and reviews its questions.