{"id":15276,"date":"2026-09-17T11:23:28","date_gmt":"2026-09-17T11:23:28","guid":{"rendered":"https:\/\/www.examlabs.com\/certification\/?p=15276"},"modified":"2026-09-17T11:23:28","modified_gmt":"2026-09-17T11:23:28","slug":"amazon-aws-certified-advanced-networking-specialty-ans-c01-practice-test-questions-and-exam-dumps-part-8-q141-160","status":"publish","type":"post","link":"https:\/\/www.examlabs.com\/certification\/amazon-aws-certified-advanced-networking-specialty-ans-c01-practice-test-questions-and-exam-dumps-part-8-q141-160\/","title":{"rendered":"Amazon AWS Certified Advanced Networking &#8211; Specialty ANS-C01 Practice Test Questions and Exam Dumps Part 8 Q141-160"},"content":{"rendered":"<h1><\/h1>\n<p><b>View Full <\/b><a href=\"https:\/\/www.examlabs.com\/aws-certified-advanced-networking-specialty-ans-c01-exam-dumps\"><b>Amazon AWS Certified Advanced Networking &#8211; Specialty ANS-C01 Exam Dumps<\/b><\/a><b> and Practice Test Dumps<\/b><\/p>\n<p>&nbsp;<\/p>\n<h3><b>Question 141. Which AWS service provides centralized connectivity and routing between VPCs, on-premises networks, and other supported network attachments?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Amazon CloudFront<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> AWS Transit Gateway<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Amazon Route 53<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> AWS WAF<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. AWS Transit Gateway<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">AWS Transit Gateway acts as a centralized network transit hub that can connect multiple VPCs, VPN connections, Direct Connect architectures, and other supported attachments. Instead of creating individual point-to-point connections between every network, organizations can attach networks to the Transit Gateway and control traffic using Transit Gateway route tables. This architecture is especially useful in large multi-account and multi-VPC environments. Transit Gateway also supports network segmentation through multiple route tables and can participate in centralized inspection designs. Administrators must explicitly configure associations, propagation, and routes because attaching a network does not automatically make every connected network reachable.<\/span><\/p>\n<h3><b>Question 142. Which AWS networking feature allows an administrator to create separate routing domains within a Transit Gateway?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Transit Gateway route tables<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Internet Gateway<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> VPC endpoint policies<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Elastic Network Interfaces<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Transit Gateway route tables<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Transit Gateway route tables allow organizations to create separate routing domains and control how attached networks communicate. For example, production VPCs can use one route table while development VPCs use another, limiting connectivity according to organizational requirements. Associations determine which route table receives traffic from a particular attachment, while propagation controls which routes become available within a route table. This provides a flexible foundation for network segmentation without deploying separate Transit Gateways for every environment. Careful route-table design is important because incorrect propagation or association settings can either block legitimate communication or unintentionally expose networks that should remain isolated.<\/span><\/p>\n<h3><b>Question 143. Which AWS networking service can connect VPCs in different AWS Regions using private AWS network infrastructure?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> AWS Transit Gateway peering<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> NAT Gateway<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Internet Gateway<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Amazon CloudFront<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. AWS Transit Gateway peering<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Transit Gateway peering allows Transit Gateways located in different AWS Regions to communicate over the AWS global network. This provides a centralized method for connecting regional network environments without requiring every VPC in one Region to establish separate inter-Region connections with every VPC in another Region. Appropriate routes must be configured in the Transit Gateway route tables so that traffic can reach the peering attachment and the remote destinations. This approach is useful for multi-Region enterprise architectures where regional network hubs need controlled private connectivity. Network segmentation and route propagation should be designed carefully to prevent unintended cross-Region communication.<\/span><\/p>\n<h3><b>Question 144. An enterprise needs to connect hundreds of VPCs without creating a large number of individual VPC peering relationships. Which architecture is generally more scalable?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Full-mesh VPC peering<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Transit Gateway hub-and-spoke architecture<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Separate Internet Gateways for every VPC<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> CloudFront distributions<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Transit Gateway hub-and-spoke architecture<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A Transit Gateway hub-and-spoke architecture can significantly simplify connectivity when an organization operates many VPCs. Each VPC can attach to the central Transit Gateway rather than establishing individual peering relationships with every other VPC. This reduces the number of connections that must be created and managed and provides centralized routing and segmentation. Transit Gateway route tables can control which environments communicate, while hybrid connections can also be integrated through VPN or Direct Connect architectures. Full-mesh peering becomes increasingly complex as the number of VPCs grows because each new VPC may require multiple additional connections and route configurations.<\/span><\/p>\n<h3><b>Question 145. Which AWS service can provide encrypted network connectivity between an on-premises customer gateway and an AWS virtual private gateway or Transit Gateway?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> AWS Site-to-Site VPN<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Amazon CloudFront<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> AWS Global Accelerator<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Amazon Route 53<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. AWS Site-to-Site VPN<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">AWS Site-to-Site VPN provides encrypted connectivity between a customer network and AWS. Depending on the architecture, a VPN can terminate on a virtual private gateway or Transit Gateway. The connection uses IPSec tunnels and can support static or dynamic routing configurations. Site-to-Site VPN is commonly used for hybrid connectivity, backup connectivity for Direct Connect, and environments where dedicated connectivity is not required. When high availability is important, AWS VPN connections are designed with multiple tunnels, and organizations should consider redundant customer-side equipment and independent network paths to reduce the impact of failures outside AWS.<\/span><\/p>\n<h3><b>Question 146. Which VPN component represents the physical or virtual device on the customer side of an AWS Site-to-Site VPN connection?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Customer gateway<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Internet Gateway<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> NAT Gateway<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Transit Gateway<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Customer gateway<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A customer gateway represents the customer-side device or software application used to establish an AWS Site-to-Site VPN connection. It contains information about the customer network device and, depending on the configuration, its public IP address and routing characteristics. The AWS side of the VPN uses an appropriate gateway such as a virtual private gateway or Transit Gateway. Correctly configuring the customer gateway is essential because tunnel establishment, routing, and encryption parameters depend on compatible settings between the customer environment and AWS. The customer gateway can be a physical appliance in a data center or a supported virtual networking device.<\/span><\/p>\n<h3><b>Question 147. Which VPN protocol suite provides encryption and authentication for AWS Site-to-Site VPN traffic?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> IPSec<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> FTP<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> SMTP<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> DNS<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. IPSec<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">AWS Site-to-Site VPN uses IPSec to protect network traffic traveling through VPN tunnels. IPSec provides mechanisms for encryption, integrity protection, authentication, and secure communication across an untrusted network such as the internet. IKE is used to establish and negotiate security associations between the VPN endpoints. Administrators must ensure that compatible encryption algorithms, authentication methods, lifetimes, and other tunnel parameters are configured when required. IPSec protects the network traffic, while routing protocols such as BGP can determine which prefixes should be sent through the VPN. Therefore, both security and routing configurations must be considered when troubleshooting VPN connectivity.<\/span><\/p>\n<h3><b>Question 148. Which AWS service can provide remote users with client-based VPN access to resources in AWS VPCs?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> AWS Client VPN<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> AWS Direct Connect<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> AWS Global Accelerator<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Amazon CloudFront<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. AWS Client VPN<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">AWS Client VPN is a managed client-based VPN service that allows individual users to securely connect from remote locations to AWS resources and, depending on the architecture, on-premises resources. Users connect using a compatible VPN client and authenticate according to the configured authentication mechanism. The Client VPN endpoint can be associated with VPC subnets so that authorized users can reach resources according to configured routes, authorization rules, and security controls. Client VPN is different from Site-to-Site VPN, which connects networks rather than individual remote users. This distinction is important when selecting the appropriate VPN architecture for remote workforce access.<\/span><\/p>\n<h3><b>Question 149. Which AWS networking capability allows applications in a VPC to access AWS services privately while using DNS names that resolve to private endpoint addresses?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Interface VPC endpoint<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Internet Gateway<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> NAT Gateway<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Public VIF<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Interface VPC endpoint<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Interface VPC endpoints use elastic network interfaces with private IP addresses inside selected VPC subnets. When private DNS is enabled where supported, applications can continue using normal AWS service DNS names while the DNS resolution directs traffic toward the private endpoint interfaces. This allows workloads to communicate with supported services without using public internet connectivity. Interface endpoints are powered by AWS PrivateLink and can be protected using security groups associated with their network interfaces. This architecture is particularly useful for private subnets where administrators want service access without introducing NAT or internet gateway dependencies.<\/span><\/p>\n<h3><b>Question 150. Which AWS networking component is required to provide IPv4 internet connectivity from a public subnet?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Internet Gateway<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Egress-only Internet Gateway<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Transit Gateway<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> VPC endpoint<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Internet Gateway<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">An Internet Gateway provides the VPC-level connection to the public internet for IPv4 traffic. A subnet is considered public when its route table contains a route toward an Internet Gateway for internet-bound traffic. Resources that need direct public IPv4 connectivity must also have an appropriate public IPv4 address or Elastic IP address. The Internet Gateway itself does not automatically make every resource public because route tables, security groups, network ACLs, and addressing all influence connectivity. Private subnets generally use a NAT Gateway for outbound IPv4 internet access instead of sending traffic directly through the Internet Gateway.<\/span><\/p>\n<h3><b>Question 151. Which IPv6 gateway allows resources to initiate outbound internet connections while blocking unsolicited inbound IPv6 connections?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> NAT Gateway<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Egress-only Internet Gateway<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Internet Gateway only<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Direct Connect Gateway<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Egress-only Internet Gateway<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">An egress-only Internet Gateway is designed for outbound IPv6 connectivity from resources that have IPv6 addresses. It permits resources to initiate connections to the internet while preventing unsolicited inbound connections from being initiated toward those resources. Unlike IPv4 NAT, IPv6 does not require address translation to provide globally routable addresses. Therefore, an egress-only gateway provides an important security boundary for IPv6 workloads that need outbound access but should not be directly reachable through newly initiated inbound sessions. Route tables must contain an appropriate IPv6 default route toward the egress-only gateway for the architecture to function.<\/span><\/p>\n<h3><b>Question 152. Which AWS feature can allow centralized inspection traffic to pass through stateful network appliances while helping maintain flow symmetry?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Transit Gateway appliance mode<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Route 53 weighted routing<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> CloudFront cache behavior<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> S3 gateway endpoint<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Transit Gateway appliance mode<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Transit Gateway appliance mode is designed for architectures where traffic passes through stateful network appliances, such as firewalls or inspection systems. Stateful appliances maintain information about connections and often require packets belonging to the same flow to follow a consistent path. Appliance mode helps Transit Gateway maintain flow symmetry when traffic is routed through an inspection VPC. Without appropriate symmetry, forward and return traffic could traverse different appliance instances, causing stateful inspection problems. This feature is especially relevant in centralized security architectures where many VPCs send traffic through a shared firewall or inspection environment.<\/span><\/p>\n<h3><b>Question 153. Which AWS service can distribute incoming application traffic across multiple healthy EC2 instances while performing HTTP path-based routing?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Application Load Balancer<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Network Load Balancer<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Gateway Load Balancer<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Direct Connect<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Application Load Balancer<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">An Application Load Balancer operates at the application layer and can distribute HTTP and HTTPS requests across multiple targets such as EC2 instances, containers, and IP addresses. It supports advanced routing capabilities including path-based and host-based routing. For example, requests to <\/span><span style=\"font-weight: 400;\">\/api\/*<\/span><span style=\"font-weight: 400;\"> can be directed to one target group while <\/span><span style=\"font-weight: 400;\">\/images\/*<\/span><span style=\"font-weight: 400;\"> can be directed to another. ALB also supports features such as TLS termination and integration with other AWS services. Network Load Balancer is better suited for high-performance Layer 4 traffic, while Gateway Load Balancer is designed primarily for network appliance deployments.<\/span><\/p>\n<h3><b>Question 154. Which AWS load balancer is most appropriate for distributing traffic to a fleet of virtual network security appliances?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Application Load Balancer<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Gateway Load Balancer<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Network Load Balancer<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> CloudFront<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Gateway Load Balancer<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Gateway Load Balancer is specifically designed for deploying, scaling, and distributing traffic across virtual network appliances. Security vendors can provide firewall, intrusion detection, intrusion prevention, and other inspection appliances behind a GWLB. The service provides a transparent gateway model and can distribute traffic across multiple appliance instances. Gateway Load Balancer endpoints can then provide private connectivity from consumer VPCs to the appliance service. This architecture is different from an Application Load Balancer, which handles HTTP and HTTPS application requests, and a Network Load Balancer, which primarily handles Layer 4 traffic without the specialized appliance integration provided by GWLB.<\/span><\/p>\n<h3><b>Question 155. Which AWS feature allows a company to privately expose a service from one VPC to consumers in other VPCs or AWS accounts?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> AWS PrivateLink endpoint service<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Internet Gateway<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Public hosted zone<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> NAT Gateway<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. AWS PrivateLink endpoint service<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">An AWS PrivateLink endpoint service allows a service provider to expose a supported application privately to consumers. The service can be hosted behind a Network Load Balancer or Gateway Load Balancer depending on the service architecture. Consumers create VPC endpoints to connect to the service, and the provider can control access through endpoint service permissions and connection settings. This approach avoids requiring direct VPC peering and does not expose the provider&#8217;s entire network. It is particularly useful for SaaS providers, shared enterprise services, and multi-account environments where a specific application needs to be consumed privately by many independent VPCs.<\/span><\/p>\n<h3><b>Question 156. Which Route 53 routing policy is most appropriate when traffic should be directed according to the geographic location of the DNS requester?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Weighted routing<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Geolocation routing<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Failover routing<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Simple routing<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Geolocation routing<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Route 53 geolocation routing uses the geographic location associated with the DNS query to determine which record should be returned. Organizations can configure routing rules based on geographic regions, countries, or other supported location boundaries. This can be useful when an application needs to provide different content, endpoints, or services to users in different geographic areas. Geolocation routing differs from latency-based routing because latency-based routing selects endpoints according to measured network latency rather than geographic policy. Administrators should also account for DNS resolver behavior because the location information available to Route 53 may not always precisely represent the end user&#8217;s physical location.<\/span><\/p>\n<h3><b>Question 157. Which Route 53 routing policy can route users toward resources based on geographic proximity and optionally adjust the effective geographic boundaries using bias?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Geoproximity routing<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Failover routing<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Weighted routing<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Simple routing<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Geoproximity routing<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Route 53 geoproximity routing can direct DNS traffic toward resources based on the geographic locations of resources and requesters. It also supports a bias setting that can expand or shrink the geographic area from which a resource receives traffic. This makes geoproximity routing useful when organizations need more control over geographic traffic distribution than simple geolocation rules provide. The routing policy can be used in architectures where workloads are deployed across multiple locations and administrators want to influence the boundaries of traffic distribution. Understanding the difference between geolocation and geoproximity routing is important because they use different mechanisms for making routing decisions.<\/span><\/p>\n<h3><b>Question 158. Which CloudFront feature controls how CloudFront handles requests, caching, and forwarding behavior for different URL patterns?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Cache behavior<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Direct Connect Gateway<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Transit Gateway route table<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Resolver rule<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Cache behavior<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">CloudFront cache behaviors define how a distribution handles requests that match specific path patterns. They can determine which origin receives a request and control settings related to caching, allowed HTTP methods, query strings, headers, cookies, and origin requests. This allows one CloudFront distribution to serve different application components using different policies. For example, static content can use aggressive caching while dynamic API requests can use a separate behavior with minimal caching. Proper cache behavior design is important because overlapping path patterns and configuration choices can affect both application performance and the correctness of content delivered to users.<\/span><\/p>\n<h3><b>Question 159. Which AWS service can accelerate global TCP or UDP applications without requiring application content to be cached at edge locations?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> AWS Global Accelerator<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Amazon CloudFront<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Amazon S3<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Route 53 Resolver<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. AWS Global Accelerator<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">AWS Global Accelerator improves the network path for global applications by using static anycast IP addresses and the AWS global network to route traffic toward healthy regional endpoints. Unlike CloudFront, Global Accelerator does not depend on caching application content at edge locations. This makes it suitable for applications such as APIs, gaming services, real-time applications, and other TCP or UDP workloads where low-latency network connectivity is important but content caching is not the primary requirement. Global Accelerator can also provide automatic endpoint health-based routing, helping direct traffic away from unhealthy regional endpoints.<\/span><\/p>\n<h3><b>Question 160. Which AWS service can provide centralized DNS forwarding between VPCs and on-premises DNS infrastructure?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Route 53 Resolver<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> AWS Shield<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> AWS WAF<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Global Accelerator<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Route 53 Resolver<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Amazon Route 53 Resolver supports hybrid DNS architectures by providing inbound and outbound endpoints along with forwarding rules. Outbound endpoints can forward selected DNS queries from VPCs toward on-premises DNS servers, while inbound endpoints allow DNS queries from on-premises environments to reach DNS resolution services in AWS. This allows organizations to maintain corporate DNS namespaces while also resolving private AWS resources. Appropriate network connectivity, such as Direct Connect or Site-to-Site VPN, must exist between the environments. Resolver forwarding rules can then determine which domains should be sent to specific DNS servers, providing centralized and scalable hybrid DNS management.<\/span><\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>View Full Amazon AWS Certified Advanced Networking &#8211; Specialty ANS-C01 Exam Dumps and Practice Test Dumps &nbsp; Question 141. Which AWS service provides centralized connectivity and routing between VPCs, on-premises networks, and other supported network attachments? Amazon CloudFront AWS Transit Gateway Amazon Route 53 AWS WAF Correct Answer: 2. AWS Transit Gateway Explanation: AWS Transit [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[1648,1647],"tags":[],"_links":{"self":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/15276"}],"collection":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/comments?post=15276"}],"version-history":[{"count":1,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/15276\/revisions"}],"predecessor-version":[{"id":15302,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/15276\/revisions\/15302"}],"wp:attachment":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/media?parent=15276"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/categories?post=15276"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/tags?post=15276"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}