{"id":15273,"date":"2026-09-17T11:24:27","date_gmt":"2026-09-17T11:24:27","guid":{"rendered":"https:\/\/www.examlabs.com\/certification\/?p=15273"},"modified":"2026-09-17T11:24:27","modified_gmt":"2026-09-17T11:24:27","slug":"amazon-aws-certified-advanced-networking-specialty-ans-c01-practice-test-questions-and-exam-dumps-part-5-q81-100","status":"publish","type":"post","link":"https:\/\/www.examlabs.com\/certification\/amazon-aws-certified-advanced-networking-specialty-ans-c01-practice-test-questions-and-exam-dumps-part-5-q81-100\/","title":{"rendered":"Amazon AWS Certified Advanced Networking &#8211; Specialty ANS-C01 Practice Test Questions and Exam Dumps Part 5 Q81-100"},"content":{"rendered":"<h1><\/h1>\n<p><b>View Full <\/b><a href=\"https:\/\/www.examlabs.com\/aws-certified-advanced-networking-specialty-ans-c01-exam-dumps\"><b>Amazon AWS Certified Advanced Networking &#8211; Specialty ANS-C01 Exam Dumps<\/b><\/a><b> and Practice Test Dumps<\/b><\/p>\n<p>&nbsp;<\/p>\n<h3><b>Question 81. Which AWS service provides a managed wide-area networking solution for connecting and centrally managing multiple VPCs, branch offices, and on-premises networks?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> AWS Network Manager<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> AWS Cloud WAN<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Amazon Route 53<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> AWS PrivateLink<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. AWS Cloud WAN<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">AWS Cloud WAN provides a managed global wide-area networking service that can simplify connectivity between VPCs, branch offices, data centers, and other network environments. It uses a core network model that allows organizations to centrally define network segments and connectivity policies. This is particularly useful for enterprises operating across multiple AWS Regions and geographic locations. Instead of manually building and maintaining numerous independent networking relationships, administrators can use Cloud WAN to create a centralized global network structure. AWS Network Manager can provide network visualization and management capabilities, but Cloud WAN is specifically designed to build and operate a managed global WAN.<\/span><\/p>\n<h3><b>Question 82. A company wants to create separate logical network segments within AWS Cloud WAN for production and development workloads. Which Cloud WAN capability should it use?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Network segments<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Security groups<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Prefix lists<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Internet gateways<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Network segments<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">AWS Cloud WAN network segments provide logical separation within a core network. Organizations can use segments to isolate different classes of workloads, such as production, development, testing, or shared services. Connectivity between segments can then be controlled using network policies. This approach provides centralized segmentation across a global network architecture rather than requiring administrators to configure every network relationship independently. Network segments are different from security groups, which control traffic at the resource or network-interface level within supported AWS environments. When designing a large enterprise network, Cloud WAN segmentation can help create clear boundaries while maintaining centralized policy management.<\/span><\/p>\n<h3><b>Question 83. Which AWS service allows administrators to visualize and centrally monitor their AWS and hybrid network topology?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> AWS Network Manager<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> AWS WAF<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Amazon CloudFront<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> AWS PrivateLink<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. AWS Network Manager<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">AWS Network Manager provides centralized network management capabilities for AWS and hybrid environments. It can help organizations visualize their global network topology and monitor connectivity across networks such as Transit Gateways, virtual private networks, and on-premises infrastructure. This is valuable for large environments where manually tracking every connection becomes difficult. Network Manager can provide operational visibility that helps administrators understand how different network components are connected. It does not replace routing services such as Transit Gateway or security services such as AWS Network Firewall. Instead, it helps organizations manage and observe their broader network architecture from a centralized perspective.<\/span><\/p>\n<h3><b>Question 84. Which AWS feature allows a VPC route table to reference a managed collection of CIDR prefixes instead of requiring individual routes for each prefix?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Prefix list<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Resolver rule<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Security group<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Network ACL<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Prefix list<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A prefix list is a collection of CIDR blocks that can be referenced as a single logical object in supported AWS networking configurations. Using prefix lists can simplify route management and security configurations when the same group of network destinations is repeatedly referenced. AWS-managed prefix lists are maintained by AWS for certain services, while customer-managed prefix lists can be created for organizational requirements. Instead of repeatedly entering individual CIDR ranges, administrators can reference the prefix list and update its entries centrally. This can reduce configuration duplication and make large-scale network administration easier, particularly in environments with shared service destinations.<\/span><\/p>\n<h3><b>Question 85. A network administrator wants to ensure that IPv6-enabled instances can initiate outbound internet connections without allowing unsolicited inbound internet connections. Which component should be used?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> NAT Gateway<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Internet Gateway only<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Egress-only Internet Gateway<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Transit Gateway<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. Egress-only Internet Gateway<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">An egress-only Internet Gateway is designed for IPv6 traffic originating from resources in a VPC that need outbound internet connectivity while preventing unsolicited inbound connections from the internet. It provides a stateful mechanism for outbound IPv6 communication. This differs from a NAT Gateway, which is commonly used to provide outbound IPv4 connectivity for private resources using translated addresses. IPv6 addresses are globally routable, so organizations need an appropriate architecture when workloads should initiate internet connections without accepting new inbound sessions. Route tables must also be configured correctly so that IPv6 traffic is directed through the egress-only Internet Gateway.<\/span><\/p>\n<h3><b>Question 86. Which IPv4 mechanism allows private subnet resources to initiate outbound internet connections while preventing direct inbound connections initiated from the internet?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> NAT Gateway<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Internet Gateway without translation<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Egress-only Internet Gateway<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> VPC peering<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. NAT Gateway<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A NAT Gateway enables resources in a private subnet to initiate outbound IPv4 connections to destinations such as the public internet while preventing unsolicited inbound connections from the internet from being initiated directly toward those private resources. The NAT Gateway is deployed in a public subnet and uses an Elastic IP address for internet connectivity through an Internet Gateway. Private subnet route tables send internet-bound IPv4 traffic to the NAT Gateway. For high availability, organizations commonly deploy NAT Gateways in multiple Availability Zones and route each private subnet through the NAT Gateway in the same Availability Zone where practical.<\/span><\/p>\n<h3><b>Question 87. What is the primary purpose of an AWS Gateway Load Balancer endpoint?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> To provide DNS resolution for private domains<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> To provide private connectivity from a VPC to a service behind a Gateway Load Balancer<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> To distribute HTTP requests among web servers<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> To provide encrypted VPN tunnels<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. To provide private connectivity from a VPC to a service behind a Gateway Load Balancer<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A Gateway Load Balancer endpoint provides private connectivity between a VPC and a service that is exposed through a Gateway Load Balancer endpoint service. This architecture is commonly used for centralized network security appliances such as firewalls, intrusion prevention systems, and traffic inspection devices. The endpoint uses AWS PrivateLink technology to provide connectivity without requiring direct VPC peering between the consumer and service provider environments. Gateway Load Balancer is specifically designed to deploy and scale third-party virtual network appliances, while the endpoint provides the private connection from consumer VPCs to those appliances.<\/span><\/p>\n<h3><b>Question 88. A security team wants to inspect traffic from several application VPCs using a centralized third-party firewall appliance. Which AWS architecture can simplify this design?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Gateway Load Balancer with centralized inspection<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> CloudFront with S3 only<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Route 53 weighted routing<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Direct Connect public VIF only<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Gateway Load Balancer with centralized inspection<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Gateway Load Balancer, or GWLB, is designed to deploy, scale, and distribute traffic across virtual network appliances such as firewalls and intrusion prevention systems. In a centralized inspection architecture, traffic from application VPCs can be directed toward a security VPC containing the inspection infrastructure. GWLB helps distribute traffic among appliance instances while maintaining the flow characteristics needed by many network appliances. GWLB endpoints can provide private connectivity from other VPCs to the centralized appliance service. This architecture can reduce the need to deploy separate inspection appliances in every application VPC while allowing security controls to be managed centrally.<\/span><\/p>\n<h3><b>Question 89. Which AWS PrivateLink feature allows a service provider to control which AWS principals are permitted to connect to an endpoint service?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Endpoint service permissions<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Route table propagation<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> NAT rules<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> CloudFront cache policy<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Endpoint service permissions<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">AWS PrivateLink endpoint service permissions allow a service provider to control which AWS principals can access an endpoint service. This provides an authorization layer for private service exposure. A provider can configure permissions so that only specified AWS accounts or principals are allowed to create or use connections to the service, depending on the architecture. The service provider can also configure whether endpoint connection requests require acceptance. This makes PrivateLink suitable for controlled service sharing across accounts or organizations. Network connectivity alone does not automatically mean that every consumer should have access, so endpoint service permissions are an important part of a secure PrivateLink design.<\/span><\/p>\n<h3><b>Question 90. Which Route 53 Resolver feature can help block DNS queries for domains associated with unwanted or malicious activity?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> DNS Firewall<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Traffic Mirroring<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Global Accelerator<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Direct Connect Gateway<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. DNS Firewall<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Route 53 Resolver DNS Firewall helps organizations control DNS queries originating from resources in their VPCs. Administrators can create rule groups that allow or block queries based on domain names and apply those rules to VPCs. This can help prevent workloads from resolving domains associated with known malicious or unwanted destinations. DNS Firewall operates at the DNS-query level, so it is different from AWS Network Firewall, which provides broader network traffic inspection capabilities. DNS Firewall can be especially useful as part of a layered security architecture where organizations want to reduce the ability of workloads to communicate with undesirable destinations through domain-based controls.<\/span><\/p>\n<h3><b>Question 91. A company wants DNS queries for an internal domain to be automatically forwarded from multiple VPCs to centralized corporate DNS servers. Which solution is appropriate?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Route 53 Resolver forwarding rules associated with VPCs<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> CloudFront cache behaviors<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> AWS WAF managed rules<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Internet Gateway routing<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Route 53 Resolver forwarding rules associated with VPCs<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Route 53 Resolver forwarding rules allow organizations to specify which DNS queries should be forwarded to designated DNS servers. For example, a rule can specify that queries for an internal corporate domain should be sent to on-premises DNS resolvers through a Resolver outbound endpoint. Rules can be associated with multiple VPCs, making centralized DNS management practical in multi-VPC environments. This architecture avoids configuring separate DNS forwarding infrastructure in every VPC. Network connectivity between AWS and the corporate DNS servers must still exist, commonly through Direct Connect or Site-to-Site VPN, because DNS forwarding requires an underlying reachable path.<\/span><\/p>\n<h3><b>Question 92. Which Route 53 routing policy is designed to direct users to resources based on the lowest network latency measured from the user&#8217;s location?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Simple routing<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Weighted routing<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Latency-based routing<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Failover routing<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. Latency-based routing<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Route 53 latency-based routing directs DNS responses toward the AWS Region that provides the lowest latency among the configured resources based on AWS&#8217;s latency measurements. This is useful for applications deployed across multiple Regions where user experience can benefit from being directed toward a geographically appropriate and network-efficient endpoint. Latency-based routing is not the same as geolocation routing. Geolocation uses the geographic location of the DNS requester, while latency-based routing focuses on measured network latency. Organizations can also combine routing policies with health checks so that unhealthy endpoints are not selected when suitable healthy alternatives are available.<\/span><\/p>\n<h3><b>Question 93. An organization wants Route 53 to send traffic to a primary application endpoint and automatically direct users to a secondary endpoint if the primary becomes unhealthy. Which routing policy should be used?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Weighted routing<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Failover routing<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Geoproximity routing<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Multivalue answer routing<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Failover routing<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Route 53 failover routing is designed for active-passive architectures where one resource is designated as the primary and another as the secondary. Route 53 health checks can be used to determine whether the primary endpoint is healthy. If the primary is considered unhealthy, DNS responses can direct clients toward the secondary resource. This approach is useful for disaster recovery and simple high-availability architectures. Failover routing differs from weighted routing, where traffic is distributed according to configured weights, and latency-based routing, where the endpoint with the lowest measured latency is selected. Correct health-check configuration is important for reliable failover behavior.<\/span><\/p>\n<h3><b>Question 94. Which CloudFront capability allows a distribution to use a secondary origin when the primary origin returns certain configured failure responses?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Origin failover<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Origin Access Control<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Field-level encryption<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Cache invalidation<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Origin failover<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">CloudFront origin failover allows a distribution to use a secondary origin when the primary origin encounters configured failure conditions. An origin group can contain a primary and secondary origin, and CloudFront can forward requests to the secondary when the primary returns specified HTTP status codes. This can improve application resilience when an origin becomes unavailable or cannot serve particular requests. Origin failover is different from cache invalidation, which removes cached objects, and Origin Access Control, which is used to secure access between CloudFront and supported origins. A carefully designed origin failover strategy can help maintain availability during backend failures.<\/span><\/p>\n<h3><b>Question 95. Which CloudFront feature is recommended for controlling access from CloudFront to an Amazon S3 bucket origin?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Origin Access Control<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> NAT Gateway<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Transit Gateway<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> VPC Flow Logs<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Origin Access Control<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">CloudFront Origin Access Control, or OAC, allows CloudFront to securely access an Amazon S3 origin while restricting direct access to the bucket. OAC works with AWS Signature Version 4 signing and is designed to provide controlled access between CloudFront and supported S3 origins. This allows organizations to keep the S3 bucket private while still delivering objects through CloudFront. Proper S3 bucket policy configuration is required so that CloudFront is authorized to retrieve the objects. OAC is therefore an important component when designing secure CloudFront distributions that use private S3 content rather than exposing the bucket directly to the public internet.<\/span><\/p>\n<h3><b>Question 96. Which AWS Network Firewall rule type evaluates packets using connection and traffic state information?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Stateless rule group<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Stateful rule group<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Route table<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Prefix list<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Stateful rule group<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">AWS Network Firewall supports both stateless and stateful rule groups. Stateful rule groups evaluate traffic while maintaining information about network connections and traffic state, allowing policies to make decisions based on context within a flow. Stateless rule groups evaluate packets independently and are generally used for simpler packet-level filtering decisions. Stateful inspection is particularly useful for security policies that need to understand traffic flows rather than treating every packet as an unrelated event. When designing Network Firewall policies, administrators should select rule types based on the inspection requirements and understand how traffic moves through the firewall so that both forward and return paths are handled correctly.<\/span><\/p>\n<h3><b>Question 97. Which AWS Network Firewall rule group type evaluates each packet independently without maintaining connection state?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Stateful rule group<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Stateless rule group<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> DNS Firewall rule group<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Security group<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Stateless rule group<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Stateless rule groups in AWS Network Firewall evaluate packets independently without maintaining connection state between packets. This makes them suitable for straightforward filtering decisions based on packet attributes such as source and destination addresses, ports, and protocols. Stateful rule groups provide more advanced inspection because they maintain traffic-flow context. In a Network Firewall deployment, stateless processing occurs before traffic reaches the stateful engine, depending on the configured policy and rule actions. Understanding the distinction is important when troubleshooting firewall behavior because a packet may be handled differently depending on the stateless action and subsequent stateful inspection policy.<\/span><\/p>\n<h3><b>Question 98. Which VPC feature can provide a copy of selected network packets for analysis by intrusion detection or packet inspection systems?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> VPC Flow Logs<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Traffic Mirroring<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Route 53 Resolver<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> NAT Gateway<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Traffic Mirroring<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">VPC Traffic Mirroring is designed to capture and replicate network traffic from supported network interfaces for security monitoring, troubleshooting, and packet analysis. The mirrored traffic can be sent to monitoring appliances or analysis systems where security teams can inspect packet-level information. This differs from VPC Flow Logs, which provide flow metadata rather than complete packet contents. Traffic Mirroring can be filtered so that organizations do not necessarily need to replicate every packet from a source interface. Because packet replication can generate substantial traffic, administrators should consider the capacity of the monitoring destination and the performance and cost implications of the monitoring architecture.<\/span><\/p>\n<h3><b>Question 99. An EC2 instance is unable to communicate with another network because the instance&#8217;s source\/destination check is preventing it from forwarding traffic. Which configuration should be considered for a network appliance instance acting as a router?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Disable source\/destination checks<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Enable DNS Firewall<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Attach an Internet Gateway directly to the instance<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Create a CloudFront distribution<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Disable source\/destination checks<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">EC2 instances normally perform source\/destination checks, meaning the instance is expected to be the source or destination of network traffic that it processes. A network appliance such as a router, firewall, or NAT instance may need to forward packets where the source and destination addresses belong to other systems. In such cases, source\/destination checks may need to be disabled on the appliance&#8217;s network interface or instance. This allows the instance to function as a traffic-forwarding device within an appropriate architecture. Routing tables must also direct traffic through the appliance, and the appliance itself must be correctly configured to forward packets.<\/span><\/p>\n<h3><b>Question 100. An organization needs to support very large packets between compatible EC2 networking paths to reduce processing overhead. Which networking concept should the architect consider?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> DNS failover<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Jumbo frames and increased MTU<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Weighted DNS routing<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> NAT port translation<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Jumbo frames and increased MTU<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Jumbo frames allow network interfaces to transmit packets larger than the traditional Ethernet MTU of 1500 bytes. In AWS environments, supported networking paths can use larger MTU values, which may reduce packet-processing overhead and improve efficiency for workloads that transfer large amounts of data. However, every relevant network segment and device must support the selected MTU for end-to-end communication to work correctly. If a packet exceeds the supported MTU along the path, fragmentation or Path MTU Discovery behavior can become relevant. Therefore, architects should validate the complete network path before increasing MTU rather than assuming that every AWS service or network path supports jumbo frames.<\/span><\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>View Full Amazon AWS Certified Advanced Networking &#8211; Specialty ANS-C01 Exam Dumps and Practice Test Dumps &nbsp; Question 81. Which AWS service provides a managed wide-area networking solution for connecting and centrally managing multiple VPCs, branch offices, and on-premises networks? AWS Network Manager AWS Cloud WAN Amazon Route 53 AWS PrivateLink Correct Answer: 2. AWS [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[1648,1647],"tags":[],"_links":{"self":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/15273"}],"collection":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/comments?post=15273"}],"version-history":[{"count":1,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/15273\/revisions"}],"predecessor-version":[{"id":15305,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/15273\/revisions\/15305"}],"wp:attachment":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/media?parent=15273"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/categories?post=15273"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/tags?post=15273"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}