{"id":15280,"date":"2026-09-17T11:22:40","date_gmt":"2026-09-17T11:22:40","guid":{"rendered":"https:\/\/www.examlabs.com\/certification\/?p=15280"},"modified":"2026-09-17T11:22:40","modified_gmt":"2026-09-17T11:22:40","slug":"amazon-aws-certified-advanced-networking-specialty-ans-c01-practice-test-questions-and-exam-dumps-part-12-q221-240","status":"publish","type":"post","link":"https:\/\/www.examlabs.com\/certification\/amazon-aws-certified-advanced-networking-specialty-ans-c01-practice-test-questions-and-exam-dumps-part-12-q221-240\/","title":{"rendered":"Amazon AWS Certified Advanced Networking &#8211; Specialty ANS-C01 Practice Test Questions and Exam Dumps Part 12 Q221-240"},"content":{"rendered":"<h1><\/h1>\n<p><b>View Full <\/b><a href=\"https:\/\/www.examlabs.com\/aws-certified-advanced-networking-specialty-ans-c01-exam-dumps\"><b>Amazon AWS Certified Advanced Networking &#8211; Specialty ANS-C01 Exam Dumps<\/b><\/a><b> and Practice Test Dumps<\/b><\/p>\n<p>&nbsp;<\/p>\n<h3><b>Question 221. Which BGP attribute is commonly used to influence outbound path selection within an autonomous system?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> MED<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> AS_PATH<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Local preference<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Origin<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. Local preference<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">BGP local preference is used within an autonomous system to influence which available path should be preferred for outbound traffic. A higher local preference is generally preferred, allowing administrators to select a preferred exit point when multiple connections are available. In an AWS hybrid architecture, this can be useful when an organization has redundant Direct Connect or VPN paths and wants to establish a preferred route for traffic leaving its network. Local preference is different from AS_PATH prepending, which is commonly used to influence inbound traffic from neighboring networks. Understanding the direction in which BGP attributes influence routing decisions is important when designing predictable hybrid connectivity.<\/span><\/p>\n<h3><b>Question 222. A company advertises the same network prefix through two Direct Connect connections and wants one connection to be less preferred for inbound traffic. Which technique can be used?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> AS_PATH prepending<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Increasing local preference<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Adding a security group rule<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Changing the DNS TTL<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. AS_PATH prepending<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">AS_PATH prepending can be used to influence inbound BGP path selection by making one advertised route appear longer. An organization can add additional instances of its autonomous system number to the AS_PATH for the route advertised over the less-preferred connection. External BGP speakers generally consider a shorter AS_PATH more attractive when comparing otherwise suitable routes, so the prepended path may become less preferred. This technique is useful in multihomed environments where an organization wants to influence which Direct Connect path receives inbound traffic. It is important to remember that BGP path selection can involve multiple attributes and policies, so AS_PATH prepending influences path selection rather than guaranteeing a particular traffic flow.<\/span><\/p>\n<h3><b>Question 223. Which Direct Connect feature allows multiple physical connections to be combined into a logical link for increased bandwidth and improved resiliency?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Direct Connect gateway<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Link Aggregation Group (LAG)<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Transit VIF<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Public VIF<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Link Aggregation Group (LAG)<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A Direct Connect Link Aggregation Group, or LAG, allows multiple eligible Direct Connect connections to be treated as a logical group using standard link aggregation concepts. This can simplify management and allow multiple connections to contribute to the overall connectivity architecture. LAGs can be useful when an organization needs greater aggregate capacity or wants to organize multiple connections as part of a resilient Direct Connect deployment. However, a LAG does not automatically eliminate every failure domain; organizations should still consider physical location, devices, facilities, and independent connectivity paths when designing high availability. Capacity and configuration requirements must also be considered when determining whether a LAG is appropriate.<\/span><\/p>\n<h3><b>Question 224. Which Direct Connect virtual interface is intended for connectivity to AWS services with publicly advertised IP addresses?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Private VIF<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Transit VIF<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Public VIF<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> VPN VIF<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. Public VIF<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A public virtual interface allows an on-premises network connected through Direct Connect to access AWS public services using publicly advertised AWS IP prefixes. The traffic can use the Direct Connect connection rather than traversing the public internet. This is different from a private VIF, which provides private connectivity to VPC resources, and a transit VIF, which supports connectivity through a Direct Connect gateway to supported Transit Gateway environments. The choice of VIF should match the intended destination and network architecture. Public VIF connectivity can be useful when organizations need predictable private connectivity to AWS public service endpoints while maintaining centralized control over their hybrid network infrastructure.<\/span><\/p>\n<h3><b>Question 225. Which AWS feature can help simplify route management when the same set of CIDR prefixes must be referenced by multiple VPC route tables or network security configurations?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Managed prefix list<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> CloudFront cache policy<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Route 53 health check<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Internet Gateway<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Managed prefix list<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A managed prefix list allows a collection of CIDR blocks to be represented as a reusable network object. Instead of repeatedly entering the same set of prefixes in different configurations, administrators can reference the prefix list where supported. This can simplify network administration and reduce configuration errors when multiple resources need to use the same destinations. Prefix lists can be particularly helpful in environments with shared services, centralized network ranges, or frequently updated address collections. AWS-managed prefix lists can represent AWS service networks, while customer-managed prefix lists can be created for organizational address ranges. They provide a convenient abstraction for maintaining groups of related network prefixes.<\/span><\/p>\n<h3><b>Question 226. Which AWS networking service can provide private access from a VPC to an AWS service without requiring the workload to have a public IP address?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> VPC endpoint<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Internet Gateway only<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Public VIF only<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Route 53 public hosted zone<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. VPC endpoint<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">VPC endpoints allow workloads in a VPC to access supported AWS services or endpoint services without requiring public internet connectivity. Depending on the service, an organization can use a gateway endpoint or an interface endpoint. Gateway endpoints are commonly used for Amazon S3 and DynamoDB, while interface endpoints use elastic network interfaces and private IP addresses for supported services. This architecture is especially useful for private subnets where administrators want to minimize or eliminate dependencies on NAT Gateways and Internet Gateways. Endpoint policies and security controls can further restrict access. VPC endpoints therefore provide an important building block for private AWS service connectivity.<\/span><\/p>\n<h3><b>Question 227. Which AWS service allows a network administrator to analyze the configured network path between two supported resources without manually testing every route and security rule?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> AWS Network Manager<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> VPC Reachability Analyzer<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Amazon CloudFront<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> AWS Shield<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. VPC Reachability Analyzer<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">VPC Reachability Analyzer analyzes network configurations to determine whether a path exists between supported source and destination resources. It evaluates relevant networking components, including route tables, security groups, network ACLs, and other supported configuration elements. This can help administrators identify where a connectivity path is blocked without having to manually inspect every component. For example, if an EC2 instance cannot reach another resource, Reachability Analyzer can identify a routing or security configuration that prevents the path. It is a configuration-analysis tool rather than a packet capture service. This makes it particularly useful for systematic troubleshooting of complex VPC connectivity problems.<\/span><\/p>\n<h3><b>Question 228. Which feature provides metadata about network flows but does not capture the full packet payload?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Traffic Mirroring<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> VPC Flow Logs<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Packet Capture<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Gateway Load Balancer<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. VPC Flow Logs<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">VPC Flow Logs provide metadata about network traffic rather than complete packet contents. Depending on the configured format, records can contain information such as source and destination addresses, ports, protocols, packet counts, byte counts, timestamps, and whether traffic was accepted or rejected. This makes Flow Logs useful for identifying communication patterns, investigating rejected traffic, and supporting security analysis. Traffic Mirroring serves a different purpose because it can copy packet traffic for deeper inspection by supported monitoring or security appliances. Flow Logs are therefore generally more lightweight for broad network visibility, while packet-level analysis requires a more specialized mechanism.<\/span><\/p>\n<h3><b>Question 229. An organization needs to inspect traffic from multiple VPCs using third-party firewall appliances. Which combination can provide scalable appliance insertion into the traffic path?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Gateway Load Balancer and Gateway Load Balancer endpoints<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Route 53 and CloudFront<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> NAT Gateway and public VIF<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> S3 gateway endpoint and Internet Gateway<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Gateway Load Balancer and Gateway Load Balancer endpoints<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Gateway Load Balancer (GWLB) is designed to make it easier to deploy and scale third-party virtual network appliances such as firewalls and intrusion prevention systems. Gateway Load Balancer endpoints allow traffic from other VPCs to reach the appliance service privately. This architecture can be combined with routing controls so that traffic is directed through the inspection appliances before reaching its final destination. GWLB distributes traffic across healthy appliance instances and helps simplify appliance fleet management. In larger environments, organizations can combine GWLB with Transit Gateway to create centralized inspection architectures. Correct route-table configuration remains essential because the desired inspection path must be explicitly established.<\/span><\/p>\n<h3><b>Question 230. Which AWS service is designed to provide centralized private connectivity to a service provider&#8217;s application without exposing the provider&#8217;s VPC network to the consumer?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> AWS PrivateLink<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> VPC peering<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Internet Gateway<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> NAT Gateway<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. AWS PrivateLink<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">AWS PrivateLink provides private connectivity between a consumer VPC and a published endpoint service. The consumer creates an interface VPC endpoint, while the service provider typically exposes the service through a Network Load Balancer. The consumer does not need direct network-level connectivity to the provider&#8217;s VPC, which helps preserve network isolation and simplifies cross-account service consumption. This is particularly useful for SaaS providers and organizations offering shared internal services to multiple AWS accounts. Unlike VPC peering, PrivateLink does not create broad bidirectional network connectivity between the VPCs. Instead, it provides controlled access to the specific service that the provider has published.<\/span><\/p>\n<h3><b>Question 231. Which VPC routing feature can direct traffic destined for a specific CIDR block to a Transit Gateway attachment?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Route table entry<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Security group<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Network ACL<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> DHCP option set<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Route table entry<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A VPC route table determines where traffic is directed based on destination IP prefixes. An administrator can create a route with a destination CIDR block and specify a Transit Gateway as the target, provided the appropriate Transit Gateway attachment exists. When traffic matches the route, the VPC forwards it toward the Transit Gateway, where additional Transit Gateway routing determines the next destination. Security groups and network ACLs control traffic permissions but do not determine the primary next-hop destination. DHCP option sets provide configuration information such as DNS settings and do not act as packet-forwarding mechanisms. Correct route-table configuration is therefore essential when connecting VPCs to centralized network architectures.<\/span><\/p>\n<h3><b>Question 232. What happens when a VPC route table contains both a broad route and a more specific route that match the same destination traffic?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> The broad route is always selected<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> The route with the longest matching prefix is selected<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Both routes are always used simultaneously<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> The route with the oldest creation time is selected<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. The route with the longest matching prefix is selected<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">When multiple routes match a destination, AWS uses the most specific matching route, commonly described as longest prefix match. For example, a route for a broad network such as a large CIDR can coexist with a route covering a smaller portion of that network. Traffic destined for the smaller, more specific range follows the specific route, while other traffic can continue to use the broader route. This behavior allows administrators to create routing exceptions without replacing an entire routing policy. Understanding longest prefix matching is particularly important when troubleshooting VPCs containing routes to Transit Gateway, VPC peering, VPN, NAT Gateway, and other targets.<\/span><\/p>\n<h3><b>Question 233. Which AWS service provides private, low-latency connectivity between applications and supported AWS services using the AWS network rather than the public internet?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> AWS PrivateLink<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Amazon Route 53 public DNS<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Internet Gateway<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Public VIF<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. AWS PrivateLink<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">AWS PrivateLink provides private connectivity between VPC resources and supported services through private IP addresses. Consumer applications can access an endpoint service without requiring public internet routing or direct VPC-to-VPC connectivity. The architecture is especially useful when a service provider wants to expose a specific application or service to other accounts while maintaining isolation from the rest of the provider&#8217;s network. Interface endpoints create network interfaces within the consumer VPC, and endpoint policies and service permissions can provide additional control. PrivateLink is therefore a service-oriented connectivity mechanism rather than a general-purpose routing solution such as VPC peering or Transit Gateway.<\/span><\/p>\n<h3><b>Question 234. Which Route 53 routing policy chooses a resource based primarily on the geographic location of the DNS requester?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Weighted routing<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Latency-based routing<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Geolocation routing<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Failover routing<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. Geolocation routing<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Route 53 geolocation routing allows DNS responses to be configured according to the geographic location associated with the DNS query. Administrators can define routing rules based on locations such as continents, countries, or certain states in the United States. This can be useful when an organization needs to provide different content or endpoints to users in different geographic areas. Geolocation routing differs from latency-based routing, which attempts to direct users to resources based on measured network latency. Weighted routing distributes responses according to configured proportions, while failover routing is designed around primary and secondary resources and health evaluation.<\/span><\/p>\n<h3><b>Question 235. Which Route 53 routing policy is designed to direct users to the AWS resource that provides the lowest network latency from the user&#8217;s location?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Geolocation routing<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Latency-based routing<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Weighted routing<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Simple routing<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Latency-based routing<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Latency-based routing directs DNS queries to the resource associated with the Region that Route 53 determines can provide the lowest latency for the requesting user. This can help applications improve responsiveness for globally distributed users when equivalent resources are deployed across multiple AWS Regions or supported locations. Route 53 evaluates latency measurements and returns the appropriate resource according to its routing configuration. This differs from geolocation routing, which uses geographic location rather than measured network latency. Latency-based routing can be particularly useful for globally distributed applications where reducing network distance and improving response time are important considerations.<\/span><\/p>\n<h3><b>Question 236. Which CloudFront configuration determines how CloudFront handles requests differently based on URL path patterns?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Cache behavior<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Security group<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Route table<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Transit Gateway route table<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Cache behavior<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">CloudFront cache behaviors allow administrators to define how requests matching particular path patterns should be processed. Different cache behaviors can specify settings such as the allowed HTTP methods, cache policy, origin request policy, viewer protocol behavior, and associated origin. For example, requests matching one path can be directed to one origin while requests matching another path are handled differently. This allows a single CloudFront distribution to support multiple application components with distinct caching and forwarding requirements. Cache behaviors operate within the CloudFront distribution and are separate from VPC route tables, which control network-layer routing within a VPC.<\/span><\/p>\n<h3><b>Question 237. Which CloudFront security feature is recommended for controlling access from CloudFront to an Amazon S3 origin without requiring the S3 bucket to be publicly accessible?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Origin Access Control<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Public VIF<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> NAT Gateway<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Transit Gateway Connect<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Origin Access Control<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">CloudFront Origin Access Control (OAC) helps secure an Amazon S3 origin by allowing CloudFront to access the bucket while the bucket itself can remain private. The S3 bucket policy can be configured to permit the CloudFront distribution to retrieve objects, preventing direct public access to those objects when the overall configuration is properly secured. OAC is the modern mechanism for controlling CloudFront access to S3 origins and supports important security features such as signed requests. This approach reduces the need to expose the S3 bucket publicly simply to serve content through CloudFront. Proper bucket policies and CloudFront configuration are still required for the complete security design.<\/span><\/p>\n<h3><b>Question 238. Which AWS service can protect applications against distributed denial-of-service attacks at the AWS network edge?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> AWS Shield<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> AWS Direct Connect<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> AWS Transit Gateway<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Amazon Route 53 Resolver<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. AWS Shield<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">AWS Shield is a managed DDoS protection service designed to help protect AWS applications and resources from distributed denial-of-service attacks. AWS Shield Standard provides automatic protection for many AWS services, while Shield Advanced provides additional capabilities for organizations with more demanding DDoS protection and response requirements. Shield operates differently from AWS WAF. WAF focuses on filtering web requests according to configured application-layer rules, while Shield provides DDoS protection at the network and transport layers and integrates with supported AWS services. Organizations can use Shield and WAF together as part of a layered security architecture for internet-facing applications.<\/span><\/p>\n<h3><b>Question 239. Which network connectivity option provides an encrypted tunnel between a customer gateway device and AWS using IPsec?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> AWS Site-to-Site VPN<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> AWS Direct Connect<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> VPC peering<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> AWS PrivateLink<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. AWS Site-to-Site VPN<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">AWS Site-to-Site VPN establishes encrypted IPsec tunnels between a customer gateway device and AWS. It is commonly used to connect on-premises networks with VPCs or Transit Gateway environments over an underlying IP network. The encryption provided by IPsec protects the traffic as it crosses the network between the customer environment and AWS. Site-to-Site VPN can support static or dynamic routing depending on the configuration, and multiple tunnels provide additional resilience. Direct Connect provides dedicated connectivity but is not itself an IPsec VPN service. PrivateLink and VPC peering solve different connectivity problems and do not create an equivalent encrypted site-to-site tunnel.<\/span><\/p>\n<h3><b>Question 240. Which architecture is generally used to provide resilient hybrid connectivity by combining a primary Direct Connect connection with a VPN backup path?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Direct Connect with Site-to-Site VPN backup<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> CloudFront with Route 53 weighted routing<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> VPC peering with NAT Gateway<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Gateway endpoint with Internet Gateway<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Direct Connect with Site-to-Site VPN backup<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Combining Direct Connect with Site-to-Site VPN can provide a resilient hybrid connectivity architecture. Direct Connect can serve as the preferred path because it provides dedicated connectivity, while an IPsec VPN connection can provide a backup path if the primary connection becomes unavailable. Routing protocols and appropriate route preferences can be configured to establish the intended primary and secondary behavior. For higher resilience, organizations may also deploy redundant Direct Connect connections and multiple VPN tunnels across appropriate failure domains. The objective is to avoid a single connectivity failure disconnecting the hybrid environment. Careful routing, monitoring, and failover testing are important to verify that the backup path behaves as expected.<\/span><\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>View Full Amazon AWS Certified Advanced Networking &#8211; Specialty ANS-C01 Exam Dumps and Practice Test Dumps &nbsp; Question 221. Which BGP attribute is commonly used to influence outbound path selection within an autonomous system? MED AS_PATH Local preference Origin Correct Answer: 3. Local preference Explanation: BGP local preference is used within an autonomous system to [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[1648,1647],"tags":[],"_links":{"self":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/15280"}],"collection":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/comments?post=15280"}],"version-history":[{"count":1,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/15280\/revisions"}],"predecessor-version":[{"id":15298,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/15280\/revisions\/15298"}],"wp:attachment":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/media?parent=15280"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/categories?post=15280"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/tags?post=15280"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}