AWS Certified Advanced Networking – Specialty (ANS-C01) is still live as of October 2026, but AWS has announced that the certification exam will retire on December 31, 2026. Candidates planning to take the ANS-C01 exam therefore have a limited window. The exam remains 170 minutes, contains 65 questions, costs USD 300, and requires a scaled score of 700 to pass.
AWS describes the target candidate as someone with five or more years of networking experience, including at least two years of cloud and hybrid networking experience. The exam validates the ability to design, implement, manage, and secure AWS and hybrid network architectures at scale.
Domain 1: Network Design is 30%
The largest domain covers global edge services, DNS, load balancing, monitoring/logging requirements, hybrid connectivity, and multi-account/multi-Region/VPC routing architecture.
Design questions frequently combine services. A global application may need CloudFront or Global Accelerator, Route 53, Elastic Load Balancing, VPC routing, Transit Gateway, Direct Connect, VPN, and monitoring in the same architecture.
Edge services and global traffic are explicit design skills
Candidates should understand when a content-distribution network such as CloudFront fits and when a network acceleration service such as Global Accelerator is the stronger option. Application type, protocol, caching, user geography and failover requirements all matter.
A CloudFront model and Global Accelerator comparison are useful because both can improve global experience while operating differently.
DNS design includes public, private, and hybrid use cases
The blueprint expects knowledge of DNS records, TTL, DNSSEC, delegation, zones, logging and Route 53 features such as alias records, health checks, traffic policies and Resolver.
A Route 53 design may need public hosted zones, private hosted zones and hybrid resolver paths at the same time. DNS architecture is therefore tightly connected to VPC and on-premises connectivity.
Load balancing must satisfy availability, scale, and security
Elastic Load Balancing appears in design because the networking specialist needs to match load-balancer behavior with protocol, client, target, health and security requirements. Application Load Balancer, Network Load Balancer and related integration patterns serve different use cases.
An ELB design should be evaluated with target health, cross-zone considerations, TLS, source IP behavior and integration with other edge or security services.
Domain 2: Network Implementation is 26%
This domain covers implementing routing and connectivity between on-premises networks and AWS; routing/connectivity across multiple accounts, Regions and VPCs; complex hybrid and multi-account DNS; and network automation/configuration.
Implementation means more than knowing what a service does. Candidates should understand route propagation, attachment behavior, BGP, tunnel or circuit configuration, Transit Gateway, Direct Connect, VPN, VPC peering and Route 53 Resolver relationships.
Domain 3: Network Management and Operation is 20%
The operations domain covers maintaining routing/connectivity, monitoring and analyzing traffic, troubleshooting connectivity patterns, and optimizing AWS networks for performance, reliability and cost-effectiveness.
This is where VPC Flow Logs, CloudWatch, service metrics, route tables, packet-level evidence and connectivity diagnostics become important. The strongest operational answer is evidence-driven rather than “change the route and see what happens.”
Domain 4: Security, Compliance, and Governance is 24%
The final domain covers security features, audit/validation with monitoring and logging, and confidentiality of network data and communications. Security groups, network ACLs, AWS Network Firewall, WAF/Shield, routing boundaries, IAM, encryption and private connectivity can all contribute.
A VPC security model is strongest when distributed controls, centralized inspection and monitoring are designed together rather than treated as isolated settings.
The exam still uses a compensatory scoring model
AWS states that the exam contains 50 scored questions and 15 unscored questions. The unscored questions are not identified, and the exam is scored as a whole rather than requiring a separate passing score in each domain.
This makes domain weights useful for planning, but it does not justify abandoning a smaller domain. Security and operations questions often overlap with design and implementation scenarios.
The retirement date should change study planning
AWS has said the last day to take the exam is December 31, 2026. Certifications earned before retirement remain active for the standard three-year period, but no new Advanced Networking – Specialty certifications will be issued after the exam retires.
The retirement date makes current-source discipline especially important. ANS-C01 still uses the same four-domain guide in October 2026, and AWS now publishes exam guides as live documentation rather than relying only on static PDFs. Candidates should therefore use the current documentation view for final scope confirmation and treat older course notes as supporting material.
The current AWS certification page states that the exam retires on December 31, 2026, but certifications earned before retirement remain valid for the normal three-year period. That creates a different risk calculation from an ordinary exam: a failed late-December attempt may leave no second opportunity under the same credential.
The 170-minute duration is long enough for complex multi-service scenarios. Networking questions can include route tables, BGP advertisements, DNS behavior, load balancer health, security policy, and cost or failover constraints in one prompt. Candidates should practice reading architecture details without assuming every fact is relevant.
The target-candidate experience requirement explains the exam’s depth. Five or more years in networking and two or more years in cloud/hybrid networking means AWS expects comfort with IP routing, BGP, DNS, VPN, load balancing, packet flow, security controls, and operations before adding AWS-specific abstractions.
Network Design’s global edge task should be learned by traffic type. CloudFront is optimized around content distribution and HTTP(S) acceleration/caching patterns, while Global Accelerator provides static anycast entry points and AWS global-network routing for supported TCP/UDP applications. Route 53 remains the DNS decision layer and can work with either.
DNS design must include negative cases. Private hosted zones can create split-horizon behavior; resolver rules can conflict or fail to forward; DNSSEC applies differently across authoritative and resolver contexts; TTL affects failover speed and caching behavior. The strongest design recognizes that DNS is a distributed system with its own failure modes.
Load-balancer design should begin with protocol and client requirements. Application Load Balancer understands HTTP(S) features such as host/path routing, while Network Load Balancer is suited to high-performance Layer 4 patterns and source-IP preservation requirements. Gateway Load Balancer patterns can integrate network appliances. The exam can test the architectural fit rather than console steps.
Logging and monitoring requirements belong in Domain 1 because observability is part of design. VPC Flow Logs, CloudWatch metrics, load-balancer access logs, Route 53 query logging, Transit Gateway flow logs or other service telemetry should be chosen based on what needs to be detected, audited, or troubleshot.
Hybrid routing design should include failure behavior before implementation. If Direct Connect is primary and VPN is backup, BGP attributes and route preference must produce the intended failover. If both paths advertise the same prefixes without deliberate policy, the actual path can differ from the architecture diagram.
Multi-account networking introduces governance questions as well as routing. Organizations may centralize egress, inspection, DNS, or hybrid connectivity in shared-services accounts, but resource ownership, RAM sharing, Transit Gateway route tables, and deployment automation must preserve clear responsibilities.
Network Implementation’s automation task can include CloudFormation, AWS CDK, APIs, CLI/SDK workflows, and infrastructure-as-code approaches. The exam is not a programming certification, but networking specialists should understand why repeatable templates and automated validation reduce drift in environments with many accounts and Regions.
Hybrid DNS implementation can involve Route 53 Resolver inbound and outbound endpoints, rules, private hosted zones, and on-premises DNS forwarders. The implementation must avoid forwarding loops and make sure private names resolve from the intended networks. DNS reachability depends on security groups, route paths, and resolver configuration together.
Operations includes routine change as well as incident troubleshooting. A BGP maintenance event, route-table change, new VPC attachment, certificate update, or load-balancer target change can alter network behavior. Good operators compare intended change with telemetry and rollback plans instead of treating every change as low risk because it is “only networking.”
Performance optimization can include choosing better entry points, reducing unnecessary cross-Region or cross-AZ traffic, selecting appropriate MTU/jumbo frame behavior, improving DNS decisions, or using Direct Connect/Global Accelerator where business requirements justify them. The best answer balances latency, resilience, complexity, and cost.
Cost-effectiveness matters because network data transfer can be a significant cloud expense. NAT Gateway processing, inter-AZ transfer, inter-Region transfer, Direct Connect usage, Transit Gateway processing, CloudFront egress, and centralized-inspection patterns can shift where costs appear. The exam can ask for a design that meets both technical and financial constraints.
Security-domain questions often combine preventative and detective controls. Security groups and NACLs filter traffic; Network Firewall or third-party appliances provide inspection; WAF protects web requests; Shield addresses DDoS; flow logs and monitoring provide evidence. One control does not replace all others because they operate at different layers.
Confidentiality of network communications can involve TLS, IPsec, MACsec in Direct Connect contexts, private connectivity, certificate management, and encryption requirements. The networking specialist should know where encryption terminates and which segment remains protected across hybrid paths.
Governance can include centralized policy, tagging, resource sharing, account boundaries, service control policies, and logging retention. Networking has a large blast radius, so organizations often separate duties between central network teams and application accounts. ANS-C01 scenarios can reward architectures that scale organizationally as well as technically.
The current exam guide’s in-scope service list is useful as a boundary, but candidates should not memorize it as a flat catalog. Services make sense in categories: VPC and routing, hybrid connectivity, DNS, edge/delivery, load balancing, security, observability, automation, and governance. A category-based model survives product changes better than a service-name list.
Because there are 50 scored and 15 unscored questions, candidates cannot know which items affect the result. Treat every item seriously, make a reasoned choice, and avoid leaving questions unanswered because AWS states that unanswered questions are scored incorrect and there is no penalty for guessing.
An ANS-C01 preparation plan in late 2026 should therefore be realistic about scheduling, retake risk, and available lab time. Within the broader AWS certification path, the technical networking knowledge remains valuable even as this specific credential approaches retirement.