{"id":15272,"date":"2026-09-17T11:24:40","date_gmt":"2026-09-17T11:24:40","guid":{"rendered":"https:\/\/www.examlabs.com\/certification\/?p=15272"},"modified":"2026-09-17T11:24:40","modified_gmt":"2026-09-17T11:24:40","slug":"amazon-aws-certified-advanced-networking-specialty-ans-c01-practice-test-questions-and-exam-dumps-part-4-q61-80","status":"publish","type":"post","link":"https:\/\/www.examlabs.com\/certification\/amazon-aws-certified-advanced-networking-specialty-ans-c01-practice-test-questions-and-exam-dumps-part-4-q61-80\/","title":{"rendered":"Amazon AWS Certified Advanced Networking &#8211; Specialty ANS-C01 Practice Test Questions and Exam Dumps Part 4 Q61-80"},"content":{"rendered":"<h1><\/h1>\n<p><b>View Full <\/b><a href=\"https:\/\/www.examlabs.com\/aws-certified-advanced-networking-specialty-ans-c01-exam-dumps\"><b>Amazon AWS Certified Advanced Networking &#8211; Specialty ANS-C01 Exam Dumps<\/b><\/a><b> and Practice Test Dumps<\/b><\/p>\n<p>&nbsp;<\/p>\n<h3><b>Question 61. Which BGP attribute can be used to influence outbound traffic selection within an autonomous system?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> MED<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Local preference<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> AS_PATH<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Origin<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Local preference<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">BGP local preference is commonly used to influence the path selected for outbound traffic within an autonomous system. A higher local preference is preferred, so network administrators can use it to make one external path more desirable than another. For example, if an organization has two AWS Direct Connect connections and wants traffic leaving its network for AWS to prefer one connection, local preference can help establish that preference. Local preference is propagated within the autonomous system, unlike MED, which is primarily used to communicate a preferred inbound path between neighboring autonomous systems. Understanding BGP attributes is important when designing redundant hybrid AWS connectivity.<\/span><\/p>\n<h3><b>Question 62. A company wants to combine multiple AWS Direct Connect connections into a single logical connection for increased bandwidth and simplified management. Which feature should be used?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Direct Connect Gateway<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Transit Gateway<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Link Aggregation Group (LAG)<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Virtual Private Gateway<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. Link Aggregation Group (LAG)<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">AWS Direct Connect Link Aggregation Group, or LAG, allows multiple dedicated Direct Connect connections to be combined into a single logical interface. This can increase aggregate bandwidth while simplifying configuration because the connections are managed as a group. LAG uses the Link Aggregation Control Protocol and is useful when an organization needs greater throughput than a single connection can provide. The physical connections participating in a LAG must meet AWS requirements, including compatible connection characteristics. LAG does not replace Direct Connect Gateway or Transit Gateway; instead, it operates at the Direct Connect connection aggregation layer and can be incorporated into larger hybrid network architectures.<\/span><\/p>\n<h3><b>Question 63. Which AWS Direct Connect virtual interface type is designed to provide connectivity to resources in a VPC through a virtual private gateway?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Private virtual interface<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Public virtual interface<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Transit virtual interface<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Internet virtual interface<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Private virtual interface<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A private virtual interface, or private VIF, is used with AWS Direct Connect to establish private connectivity between an on-premises network and VPC resources through a virtual private gateway. It uses private IP addressing and BGP to exchange routing information between the customer network and AWS. A public VIF is intended for accessing AWS public services using public IP addresses, while a transit VIF is associated with a Direct Connect gateway and can provide connectivity toward a Transit Gateway architecture. Selecting the appropriate VIF type is important because each type supports a different connectivity model and routing requirement.<\/span><\/p>\n<h3><b>Question 64. A company wants to connect an on-premises network to multiple VPCs through a centralized AWS networking architecture using AWS Transit Gateway. Which Direct Connect component is designed to support this model?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> NAT Gateway<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Direct Connect gateway<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Internet Gateway<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> VPC endpoint<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Direct Connect gateway<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">AWS Direct Connect Gateway provides a scalable way to connect an on-premises network through Direct Connect to multiple VPCs across supported AWS Regions and accounts. When used with an appropriate Direct Connect virtual interface and gateway architecture, it avoids the need to establish a separate physical Direct Connect connection for every VPC. Direct Connect Gateway can also be integrated with Transit Gateway using a transit virtual interface, allowing centralized connectivity to a broader network environment. This design is especially useful for enterprises that operate many VPCs and want to maintain predictable hybrid connectivity while reducing the complexity of individual VPC connections.<\/span><\/p>\n<h3><b>Question 65. Which BGP attribute is primarily used to influence the preferred path for traffic entering an autonomous system from another autonomous system?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Local preference<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> MED<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Weight<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> VLAN ID<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. MED<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Multi-Exit Discriminator, or MED, can be used to communicate a preference about which entry point should be selected when another autonomous system has multiple links to the same network. A lower MED is generally preferred when comparing routes from the same neighboring autonomous system. In hybrid AWS architectures, understanding MED can help administrators reason about how traffic may enter a network when redundant connections exist. MED is different from local preference: local preference is normally used within an autonomous system to influence outbound route selection, while MED can provide neighboring networks with information about a preferred inbound path.<\/span><\/p>\n<h3><b>Question 66. What is a major advantage of using AWS Direct Connect with redundant connections at separate locations?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> It removes the need for BGP<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> It automatically encrypts all application traffic<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> It improves resilience against connection or location failures<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> It eliminates all AWS routing requirements<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. It improves resilience against connection or location failures<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Using redundant Direct Connect connections from separate locations can significantly improve network resilience. If one connection, facility, or Direct Connect location becomes unavailable, traffic can potentially use another available path when routing has been designed appropriately. Organizations commonly combine Direct Connect with another independent connectivity option, such as Site-to-Site VPN, to provide additional redundancy. Redundancy must be designed at multiple layers because simply having two connections does not guarantee effective failover. BGP routing, route advertisements, physical diversity, and application requirements should all be considered when designing a resilient hybrid network between an on-premises environment and AWS.<\/span><\/p>\n<h3><b>Question 67. Which protocol is used by AWS Site-to-Site VPN to establish encrypted tunnels between AWS and a customer network?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> IPSec<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> FTP<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> HTTP<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> SNMP<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. IPSec<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">AWS Site-to-Site VPN uses IP Security, commonly called IPSec, to provide encrypted communication between a customer network and AWS. The VPN connection consists of encrypted tunnels that protect traffic while it travels across the underlying network. Internet Key Exchange, or IKE, is used as part of the process for establishing and managing the cryptographic security associations required by IPSec. Site-to-Site VPN can use static or dynamic routing depending on the architecture and configuration. Understanding IPSec and IKE is important when troubleshooting VPN establishment, tunnel availability, encryption parameters, and routing behavior in hybrid AWS environments.<\/span><\/p>\n<h3><b>Question 68. An organization wants dynamic route exchange between its on-premises router and an AWS Site-to-Site VPN connection. Which routing protocol should it configure?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> OSPF<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> EIGRP<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> RIP<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> BGP<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. BGP<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Border Gateway Protocol, or BGP, can be used with AWS Site-to-Site VPN when dynamic routing is required. Dynamic routing allows the customer gateway and AWS VPN infrastructure to exchange network prefixes automatically instead of relying exclusively on manually configured static routes. This can simplify route management and allow networks to adapt when prefixes change. BGP is particularly useful in larger hybrid environments where multiple networks and redundant VPN connections exist. Administrators can also use BGP attributes and route policies to influence path selection. Proper BGP configuration is essential because tunnel establishment alone does not guarantee that application traffic will follow the intended routing path.<\/span><\/p>\n<h3><b>Question 69. Which Transit Gateway feature allows traffic from different network segments to be isolated using separate routing domains?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Transit Gateway route tables<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Internet Gateway<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> NAT Gateway<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> VPC security groups<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Transit Gateway route tables<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Transit Gateway route tables can be used to create logical routing domains and control how attached networks communicate with one another. An attachment can be associated with a particular Transit Gateway route table, and routes can be propagated into that table based on the architecture. By using multiple route tables, organizations can separate environments such as production, development, security inspection, and shared services. This provides a foundation for network segmentation without requiring a separate Transit Gateway for every environment. The design must carefully consider both route-table associations and route propagation because incorrect configuration can unintentionally allow or prevent communication between network segments.<\/span><\/p>\n<h3><b>Question 70. What is the primary purpose of appliance mode on an AWS Transit Gateway?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> To provide public DNS resolution<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> To help maintain traffic flow symmetry through stateful network appliances<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> To increase the maximum size of an IP packet<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> To replace all VPC route tables<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. To help maintain traffic flow symmetry through stateful network appliances<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Transit Gateway appliance mode is useful when traffic must pass through stateful network appliances such as firewalls or inspection systems. Stateful appliances often require packets belonging to the same flow to traverse the same appliance path so that connection state can be maintained correctly. Appliance mode helps Transit Gateway maintain flow symmetry for traffic involving an inspection VPC. This is particularly valuable in centralized inspection architectures where multiple VPCs send traffic through a shared security environment. Without appropriate traffic symmetry, return traffic could potentially use a different appliance path, causing stateful inspection systems to reject or mishandle connections.<\/span><\/p>\n<h3><b>Question 71. A network engineer needs to send traffic from multiple VPCs through a centralized firewall VPC before reaching other networks. Which design is most appropriate?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Connect every VPC directly to the Internet Gateway<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Use centralized inspection with Transit Gateway and a firewall VPC<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Create only VPC peering connections<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Place a NAT Gateway in every subnet and bypass inspection<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Use centralized inspection with Transit Gateway and a firewall VPC<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A centralized inspection architecture can use AWS Transit Gateway to route traffic from multiple VPCs through a dedicated inspection VPC containing security appliances or AWS Network Firewall. This approach centralizes security controls and can simplify policy management across many application VPCs. Transit Gateway route tables can direct traffic toward the inspection environment before allowing it to reach another network or destination. The architecture must also account for return routing and stateful inspection requirements. Depending on the design, Transit Gateway appliance mode may be relevant for maintaining flow symmetry. This pattern is commonly used in multi-VPC enterprise environments requiring centralized network security inspection.<\/span><\/p>\n<h3><b>Question 72. Which AWS service provides a managed private connectivity mechanism that allows consumers to access services without requiring direct VPC peering?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> AWS PrivateLink<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Amazon Route 53<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> AWS Global Accelerator<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> AWS Shield<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. AWS PrivateLink<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">AWS PrivateLink enables private connectivity between consumers and supported services without requiring the consumer VPC to establish direct VPC peering with the service provider VPC. A service provider can expose a service through an endpoint service, while consumers create interface VPC endpoints to access that service using private connectivity. This model is particularly useful for SaaS providers, shared services, and centralized applications that need to serve workloads across multiple VPCs or accounts. PrivateLink reduces network coupling because the consumer does not need access to the provider&#8217;s underlying network architecture. It also provides a controlled model for private service exposure.<\/span><\/p>\n<h3><b>Question 73. Which Route 53 Resolver component is used when DNS queries from AWS VPCs need to be forwarded to DNS servers located in an on-premises network?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Resolver inbound endpoint<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Resolver outbound endpoint<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Route 53 hosted zone<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> CloudFront distribution<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Resolver outbound endpoint<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A Route 53 Resolver outbound endpoint allows DNS queries originating from AWS VPCs to be forwarded to DNS resolvers outside AWS, such as corporate DNS servers in an on-premises environment. Forwarding rules determine which DNS domains should be sent through the outbound endpoint. This is useful in hybrid DNS architectures where internal corporate domains must continue to be resolved by enterprise DNS infrastructure. An inbound Resolver endpoint serves the opposite direction by allowing DNS queries originating outside AWS to reach DNS names associated with AWS resources. Understanding the direction of DNS traffic is essential when selecting inbound versus outbound Resolver endpoints.<\/span><\/p>\n<h3><b>Question 74. A company wants on-premises DNS servers to resolve private DNS names hosted in AWS. Which Route 53 Resolver feature should be used?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Resolver outbound endpoint<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Resolver inbound endpoint<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Public hosted zone<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> CloudFront origin<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Resolver inbound endpoint<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A Route 53 Resolver inbound endpoint allows DNS queries from networks outside AWS to be sent into the Amazon VPC Resolver. This enables on-premises DNS infrastructure to resolve private AWS DNS names when the appropriate networking and forwarding rules are configured. For example, corporate DNS servers can forward queries for specific AWS private domains to the inbound endpoint. The DNS traffic must have network connectivity to the endpoint, commonly through Direct Connect or Site-to-Site VPN. Inbound and outbound endpoints serve different directions, so selecting the correct one is important when implementing hybrid DNS resolution between AWS and an enterprise network.<\/span><\/p>\n<h3><b>Question 75. Which Route 53 routing policy distributes DNS responses across multiple resources according to configured proportions?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Failover routing<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Geolocation routing<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Weighted routing<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Latency-based routing<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. Weighted routing<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Route 53 weighted routing allows DNS responses to be distributed among multiple resources according to assigned weights. The weights determine the relative proportion of traffic that Route 53 directs toward each associated resource when the records are otherwise eligible to answer. This can be useful for gradual application deployments, traffic distribution, testing, or controlled migration between environments. Weighted routing differs from latency-based routing, which selects an endpoint based on network latency, and failover routing, which uses primary and secondary configurations. Administrators should also consider health checks when appropriate so that unhealthy resources are not unnecessarily returned in DNS responses.<\/span><\/p>\n<h3><b>Question 76. A global application needs users to connect through static anycast IP addresses while AWS routes traffic toward healthy regional application endpoints. Which service is designed for this requirement?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> AWS Global Accelerator<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Amazon Route 53 Resolver<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> AWS Direct Connect<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> AWS Network Firewall<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. AWS Global Accelerator<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">AWS Global Accelerator provides static anycast IP addresses that act as stable entry points for global applications. User traffic enters the AWS global network through an accelerator edge location and is routed toward appropriate regional endpoints based on factors such as health and network performance. This can improve availability and reduce the need to expose different regional addresses to users. Global Accelerator is different from CloudFront, which is primarily designed for content delivery and caching. Global Accelerator can support applications such as APIs and TCP or UDP workloads where stable IP addresses and global network-level traffic management are important.<\/span><\/p>\n<h3><b>Question 77. Which CloudFront feature allows different URL path patterns to use different origins or caching behaviors?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Origin Access Control<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Cache behaviors<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> AWS Shield Advanced<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Route 53 health checks<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Cache behaviors<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">CloudFront cache behaviors allow a distribution to apply different processing rules based on URL path patterns. For example, requests matching <\/span><span style=\"font-weight: 400;\">\/images\/*<\/span><span style=\"font-weight: 400;\"> can be directed to one origin while requests matching <\/span><span style=\"font-weight: 400;\">\/api\/*<\/span><span style=\"font-weight: 400;\"> can be directed to another origin or use different caching and forwarding settings. Cache behaviors can control factors such as allowed HTTP methods, caching policies, origin request policies, and the target origin. This makes them an important part of designing CloudFront distributions for applications with multiple content types or backend services. Careful path-pattern ordering is important because CloudFront evaluates behaviors according to matching rules and uses the most appropriate behavior for a request.<\/span><\/p>\n<h3><b>Question 78. Which AWS service is specifically designed to protect web applications from common HTTP-based attacks such as SQL injection and cross-site scripting?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> AWS Network Firewall<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> AWS Shield<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> AWS WAF<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Amazon GuardDuty<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. AWS WAF<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">AWS WAF is a web application firewall designed to inspect HTTP and HTTPS requests and apply rules that can allow, block, or count traffic. It can help protect web applications against common application-layer threats such as SQL injection and cross-site scripting. AWS WAF can be associated with supported AWS resources, including CloudFront distributions and application-facing services. Managed rule groups can provide collections of commonly needed protections, while custom rules can address application-specific requirements. AWS WAF is different from AWS Network Firewall, which provides network-layer firewall capabilities, and AWS Shield, which focuses primarily on DDoS protection.<\/span><\/p>\n<h3><b>Question 79. Which VPC feature can capture information about IP traffic entering and leaving network interfaces for network troubleshooting and analysis?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> VPC Flow Logs<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Route tables<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Security groups<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Elastic IP addresses<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. VPC Flow Logs<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">VPC Flow Logs capture information about IP traffic flowing to and from network interfaces and can be used for troubleshooting, security analysis, and network monitoring. Flow log records can provide information such as source and destination addresses, ports, protocol, packet and byte counts, and whether traffic was accepted or rejected according to the relevant network controls. Flow Logs do not capture packet payloads, so they should not be treated as a full packet-capture mechanism. They can be published to supported destinations for analysis and retention. When troubleshooting connectivity, Flow Logs can help identify whether traffic is reaching an interface and whether it is being accepted or rejected.<\/span><\/p>\n<h3><b>Question 80. An organization needs to inspect copies of network traffic from selected EC2 network interfaces using security monitoring appliances. Which VPC capability should it consider?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Traffic Mirroring<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Route 53 Resolver<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> NAT Gateway<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Elastic Load Balancing<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Traffic Mirroring<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">VPC Traffic Mirroring allows organizations to copy network traffic from supported elastic network interfaces and send the mirrored traffic to a monitoring or security appliance. This can be useful for deep packet inspection, intrusion detection, troubleshooting, and other security analysis activities. Traffic Mirroring is different from VPC Flow Logs because Flow Logs provide metadata about network flows, whereas Traffic Mirroring can provide copies of network packets for inspection. The mirrored traffic can be sent to a designated monitoring destination through an appropriate traffic-mirroring session. Organizations should consider traffic volume, appliance capacity, filtering requirements, and associated costs when designing a Traffic Mirroring solution.<\/span><\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>View Full Amazon AWS Certified Advanced Networking &#8211; Specialty ANS-C01 Exam Dumps and Practice Test Dumps &nbsp; Question 61. Which BGP attribute can be used to influence outbound traffic selection within an autonomous system? MED Local preference AS_PATH Origin Correct Answer: 2. Local preference Explanation: BGP local preference is commonly used to influence the path [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[1648,1647],"tags":[],"_links":{"self":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/15272"}],"collection":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/comments?post=15272"}],"version-history":[{"count":1,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/15272\/revisions"}],"predecessor-version":[{"id":15306,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/15272\/revisions\/15306"}],"wp:attachment":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/media?parent=15272"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/categories?post=15272"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/tags?post=15272"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}