Amazon Web Services · Free Practice Questions · Last reviewed May 2026
24real exam-style questions organised by domain, each with the correct answer highlighted and a plain-English explanation of why it's right — and why the others are wrong.
20% of exam · 6 sample questions below
A company has a Direct Connect connection with multiple virtual interfaces (VIFs). The network team notices that traffic to a specific VPC is intermittently failing. The team suspects an issue with BGP routing. Which THREE steps should the team take to troubleshoot the BGP session? (Choose THREE.)
View the BGP route advertisements received by the on-premises router from AWS.
This helps identify if AWS is advertising the expected routes.
Check the Direct Connect endpoint health in the AWS Management Console.
Verify the allowed prefixes configuration on the virtual interface in the AWS console.
If allowed prefixes do not match, routes may be rejected.
Examine VPC Flow Logs for dropped packets on the virtual interface.
Check the BGP session status using the 'bgp session' command on the on-premises router.
BGP session state (e.g., Established) indicates the health of the session.
A global e-commerce company is migrating to AWS and plans to use a hub-and-spoke topology with AWS Transit Gateway. The network team wants to ensure high availability for the connection between the hub VPC and the on-premises data center using AWS Direct Connect with multiple virtual interfaces (VIFs). They need to be able to fail over quickly with minimal packet loss. Which design should meet these requirements?
Provision one Direct Connect connection with a single private VIF, and enable BFD on the VIF to detect failures quickly.
Provision one Direct Connect connection with two private VIFs, and use a second Direct Connect connection as backup with a single VIF. Configure route tables to prefer the primary.
Provision two Direct Connect connections, each with multiple private VIFs, and attach them to the same transit gateway. Use BFD to detect failures and rely on ECMP routing across the VIFs.
Two Direct Connect connections with multiple private VIFs attached to one transit gateway give redundant paths. BFD detects failures sub-second and ECMP load-balances across VIFs, delivering fast failover with minimal packet loss as the stem requires.
Provision two Direct Connect connections, each with a single private VIF, and use AWS Site-to-Site VPN as a backup for each.
Refer to the exhibit. A network engineer is analyzing VPC Flow Logs to troubleshoot connectivity issues. The engineer notices that traffic from 10.0.1.5 to 192.168.1.1 on port 80 is logged as ACCEPT, but the application team reports that the web request failed. What is the most likely cause?
The VPC Flow Logs are not capturing all packets due to sampling.
The network ACL is returning an ICMP unreachable message that is not logged.
The destination host 192.168.1.1 is not reachable or does not have a route back to the source.
VPC Flow Logs record only whether a security group or network ACL permitted the packet at the capturing interface; ACCEPT does not confirm delivery. The destination may lack a return route, be down, or have a firewall dropping replies, so the request still fails.
The security group on the ENI is blocking outbound traffic to 192.168.1.1.
A network engineer is troubleshooting a Site-to-Site VPN connection between an on-premises network and AWS. The VPN tunnel is up, but traffic is not flowing from the on-premises network to a VPC. The VPC has a virtual private gateway attached, and the route table has a route pointing to the virtual private gateway for the on-premises CIDR (192.168.0.0/16). The on-premises firewall shows that traffic is being sent to the VPN tunnel. What should the engineer check next?
Verify that the virtual private gateway is attached to the VPC.
Verify that the on-premises route table has a route to the VPC CIDR via the VPN tunnel.
The tunnel being up with on-premises traffic entering it means the AWS side is likely fine. Return traffic needs a matching on-premises route pointing the VPC CIDR at the VPN tunnel; without it, replies are dropped.
Verify that the on-premises firewall is not blocking UDP port 500 for IKE.
Verify that the VPN tunnel's pre-shared key matches on both sides.
A company is using AWS Direct Connect with a private VIF to access their VPC. Users report intermittent connectivity issues. You check the Direct Connect console and see that the virtual interface state is 'down'. What is the MOST likely cause?
AWS Site-to-Site VPN is not established.
MACsec encryption is misconfigured on the customer router.
BGP session between the customer router and AWS is down.
A private VIF's state depends on its BGP peering session; if that session drops, the VIF reports 'down' even though the physical link and VLAN remain up. Intermittent connectivity followed by a down state therefore points to BGP session failure between the customer router and AWS, not a physical fault.
Jumbo frames are enabled on the VIF but not supported by the customer router.
Arrange the steps to configure a site-to-site VPN connection between an AWS Virtual Private Gateway and an on-premises Cisco ASA in the correct order.
Define customer gateway, then create VPN connection, then apply VPN configuration to Cisco ASA, then verify tunnel status, then configure routing.
This is the correct order because the customer gateway must be defined first to represent the on-premises device, then the VPN connection is created in AWS, followed by applying the configuration to the ASA to establish the tunnel, verifying the tunnel is up, and finally configuring routing to direct traffic through the tunnel.
Create VPN connection, then define customer gateway, then apply configuration, then verify tunnel, then configure routing.
Define customer gateway, then create VPN connection, then verify tunnel, then apply configuration, then configure routing.
Define customer gateway, then apply configuration, then create VPN connection, then verify tunnel, then configure routing.
Want more Network Management and Operations practice?
Practice this domain24% of exam · 6 sample questions below
A security engineer is designing a network security architecture for a multi-account AWS environment using AWS Organizations. The company requires that all VPC flow logs be delivered to a central S3 bucket in the security account. The security engineer has created a bucket policy that grants the necessary permissions. However, flow logs from member accounts are failing to be delivered. What is the most likely cause?
The member accounts have not created an IAM role with permissions to write to the central bucket.
The bucket policy does not include a condition that restricts access to the flow log delivery service using aws:SourceArn or aws:SourceAccount.
This condition is essential to prevent the confused deputy problem.
The bucket policy does not grant write access to the member accounts' root user.
The central S3 bucket has not been configured with ACLs enabled.
A company is using AWS Direct Connect to connect its on-premises network to AWS. The company wants to encrypt all traffic between its on-premises network and AWS. Which solution meets this requirement?
Use a public virtual interface (VIF) and route traffic through a NAT gateway.
Use a private VIF and establish an IPsec VPN tunnel over the Direct Connect connection.
A private VIF carries traffic over the Direct Connect private connection, and running an IPsec VPN tunnel across it encrypts that traffic end to end. This satisfies the stem's encryption requirement, since native Direct Connect alone provides no encryption.
Use a private virtual interface (VIF) and enable encryption on the Direct Connect connection.
Use a private VIF and enable TLS on all applications.
A company wants to audit all changes made to security groups and network ACLs in its AWS account. Which AWS service should be used to capture these API calls?
AWS CloudTrail
AWS CloudTrail records API activity in your account, capturing management events such as CreateSecurityGroup, AuthorizeSecurityGroupIngress and CreateNetworkAclEntry. This satisfies the audit requirement for security group and network ACL changes, since those modifications are control-plane API calls logged with the caller identity, timestamp and source IP.
Amazon GuardDuty
VPC Flow Logs
AWS Config
A security engineer is designing a security group configuration for a web application that consists of an Application Load Balancer (ALB), Amazon EC2 instances in an Auto Scaling group, and an Amazon RDS database. Which TWO actions should the engineer take to follow security best practices? (Choose TWO.)
Configure the RDS security group to allow inbound traffic on port 3306 from 0.0.0.0/0.
Configure the EC2 instance security group to allow inbound traffic on port 443 from the ALB security group.
Best practice: reference security group instead of CIDR.
Configure the RDS security group to allow inbound traffic on port 3306 from the EC2 instance security group.
Best practice: restrict database access to app servers.
Configure the ALB security group to allow inbound traffic on port 443 from the security group of the EC2 instances.
Configure the ALB security group to allow inbound traffic on port 80 from the security group of the EC2 instances.
A company is designing a network security architecture for a multi-account environment using AWS Transit Gateway. The company requires that all traffic between VPCs must be inspected by a centralized security appliance in a shared services VPC. The security appliance must receive traffic for both directions (ingress and egress). Which THREE components are required to achieve this? (Choose THREE.)
A shared services VPC containing the security appliances.
Centralized inspection point.
VPC attachments to the Transit Gateway for each VPC.
Required for connectivity.
VPC peering connections between each spoke VPC and the shared services VPC.
Transit Gateway route tables that route traffic between VPCs through the security appliances.
Enforces inspection.
NAT gateways in each spoke VPC for outbound traffic.
A company uses AWS Organizations with SCPs to restrict access to services. The security team needs to ensure that no IAM role can be created without an approved custom trust policy. Which SCP should be attached to the root OU to enforce this requirement?
{"Version":"2012-10-17","Statement":[{"Effect":"Deny","Action":"iam:CreateRole","Resource":"*","Condition":{"StringNotEquals":{"aws:RequestTag/Approved":"true"}}}]}
This SCP denies CreateRole unless the request includes a tag 'Approved' with value 'true', enforcing the requirement.
{"Version":"2012-10-17","Statement":[{"Effect":"Deny","Action":"iam:CreateRole","Resource":"*"}]}
{"Version":"2012-10-17","Statement":[{"Effect":"Deny","Action":"iam:CreateRole","Resource":"arn:aws:iam::*:role/*","Condition":{"StringNotLike":{"iam:RoleName":"approved-*"}}}]}
{"Version":"2012-10-17","Statement":[{"Effect":"Deny","Action":"iam:PassRole","Resource":"*"}]}
Want more Network Security, Compliance and Governance practice?
Practice this domainA company is designing a network for a three-tier web application in a single VPC. The web tier must be accessible from the internet, but the application and database tiers must not have direct internet access. The application servers need to make outbound calls to a third-party API. Which architecture meets these requirements?
Web servers in public subnets, application and database servers in private subnets with an internet gateway for outbound traffic.
All servers in public subnets with security groups restricting access.
Web servers in public subnets with an Application Load Balancer, application servers in private subnets with a NAT gateway, and database servers in private subnets.
Public subnets host the web tier behind an Application Load Balancer for inbound internet access, while application and database servers sit in private subnets. A NAT gateway gives application servers outbound-only access to the third-party API without exposing them to inbound internet traffic.
All servers in private subnets and a VPN connection to the internet.
A company has a Direct Connect connection with two private virtual interfaces (VIFs) to two different VPCs in the same AWS Region. The company wants to use AWS Transit Gateway to simplify connectivity between these VPCs and their on-premises network. Which steps are required to integrate the existing Direct Connect connection with Transit Gateway?
Set up a VPN connection over the Direct Connect link and attach the VPN to the Transit Gateway.
Attach the existing private VIFs directly to the Transit Gateway.
Create a new private VIF on the Direct Connect connection and attach it to the Transit Gateway.
Create a Direct Connect gateway, associate the existing VIFs, and attach the Direct Connect gateway to the Transit Gateway.
A Direct Connect gateway is the required intermediary that links private VIFs to a Transit Gateway, enabling on-premises reachability to attached VPCs. Directly associating VIFs with the Transit Gateway is unsupported, so this sequence satisfies the integration requirement.
A company is designing a multi-region architecture with VPCs in us-east-1 and eu-west-1. The company needs low-latency connectivity between the VPCs and wants to avoid traffic over the public internet. The VPCs have overlapping CIDR blocks (10.0.0.0/16). Which solution should the network engineer recommend?
Set up an AWS Transit Gateway in each region and connect them via Transit Gateway peering.
This is correct. Although not the most optimal solution (Transit Gateway peering would be ideal), a VPN attachment between Transit Gateways can provide private connectivity between regions, even with overlapping CIDRs, by using separate route tables per VPC attachment.
Use a Direct Connect connection between the regions.
Use VPC peering between the two VPCs.
Place all resources in a single VPC with multiple Availability Zones.
A network engineer has configured an AWS Site-to-Site VPN connection between a VPC and an on-premises network. The engineer checks the VPN status and sees the output above. What is the MOST likely cause of Tunnel2 being down?
The BGP ASN on the on-premises device is misconfigured.
The route tables in the VPC do not have a route to the on-premises network.
The IKE pre-shared key used for Tunnel2 is incorrect.
The IPsec encryption or integrity algorithms do not match between the AWS VPN endpoint and the on-premises device.
Mismatched IPsec parameters cause Phase 2 negotiation failure.
A company has a VPC with public and private subnets in two Availability Zones. An Application Load Balancer in the public subnets distributes traffic to EC2 instances in the private subnets. The security group for the EC2 instances allows inbound traffic from the ALB security group. Users report intermittent timeouts. What is the most likely cause?
The security group for the ALB does not allow inbound traffic from the internet.
The ALB is not associated with an internet gateway.
The network ACL for the private subnets is blocking inbound traffic from the ALB subnets.
Correct. Network ACLs are stateless and must allow both inbound and outbound ephemeral port traffic. A missing inbound rule for ephemeral ports from ALB subnets will cause intermittent timeouts as some connections succeed and others fail.
Cross-zone load balancing is disabled on the ALB.
A solutions architect is designing a VPC with public and private subnets in two Availability Zones. The private subnets require outbound internet access for software updates, but inbound internet access must be blocked. Which solution meets these requirements?
Attach an internet gateway to the VPC and add a default route to the internet gateway in the private subnet route tables.
Deploy a NAT Gateway in a public subnet and add a default route to the NAT Gateway in the private subnet route tables.
A NAT Gateway placed in a public subnet performs source network address translation for traffic originating in the private subnets, allowing outbound internet access for updates while remaining unidirectional, so unsolicited inbound connections from the internet are blocked.
Launch an EC2 instance in a public subnet with a proxy software and route private subnet traffic through it.
Create a VPC endpoint for Amazon S3 and add a route to the endpoint in the private subnet route tables.
Want more Network Design practice?
Practice this domain26% of exam · 6 sample questions below
A company is deploying a VPC with public and private subnets in two Availability Zones. They need to ensure that instances in private subnets can access the internet for software updates while remaining unreachable from the internet. Which solution meets these requirements?
Attach an internet gateway to the private subnets and configure route tables.
Deploy a NAT Gateway in a public subnet and add a route to the NAT Gateway in the private subnet route tables.
A NAT Gateway in a public subnet performs source NAT, letting private instances initiate outbound internet traffic for updates while blocking unsolicited inbound connections. The private route table must point 0.0.0.0/0 to that gateway, satisfying both internet access and unreachability constraints.
Use a transit gateway to connect the VPC to the internet.
Establish a VPN connection to an on-premises network and route traffic through it.
A company has a VPC with a CIDR of 10.0.0.0/16 and has enabled VPC Flow Logs to capture all traffic. The logs show that an EC2 instance (10.0.1.10) is sending outbound traffic to an external IP (203.0.113.50) on port 443, but the traffic is being rejected. The instance's security group allows outbound HTTPS to 0.0.0.0/0, and the subnet's NACL allows outbound traffic on port 443. The VPC has an internet gateway attached, and the route table directs 0.0.0.0/0 to the internet gateway. What is the most likely cause of the rejection?
The NACL inbound rules are blocking the return traffic.
Security groups are stateful, but network ACLs are stateless. Return traffic from 203.0.113.50 arrives on ephemeral ports, so the NACL's inbound rules must permit those ports; blocking them rejects the response and the connection fails.
The security group does not allow inbound HTTPS traffic.
The internet gateway is not attached to the VPC.
The route table does not have a route to the internet gateway.
A network engineer is analyzing VPC Flow Logs for a VPC with CIDR 10.0.0.0/16. The exhibit shows a sample log entry. The engineer notices that traffic from 10.0.1.10 to 10.0.2.10 on port 443 is being accepted. However, the application team reports that the connection is failing. What is the most likely reason for the disconnect?
The security groups are blocking the traffic.
The route tables are incorrectly configured, causing packet loss.
The flow logs are misconfigured and not capturing all traffic.
The application layer is failing to establish a proper connection.
Flow Logs record only packet-level metadata at the ENI, so an ACCEPT entry confirms the security group and NACL permitted the traffic. The failure therefore lies above the network layer, meaning TLS negotiation, listener configuration or application logic is rejecting the connection despite permitted packets.
A company has set up a transit gateway with attachments to VPC-A and VPC-B. The transit gateway route table shows routes to both VPCs and a blackhole for 0.0.0.0/0. VPC-A's public subnet route table sends 10.1.0.0/16 traffic to the transit gateway. However, an EC2 instance in VPC-A's public subnet cannot reach an instance in VPC-B. What is the most likely cause?
VPC-B's route table does not have a route to VPC-A's CIDR via the transit gateway.
Transit gateway routing is bidirectional: each attachment's subnet route table must point to the transit gateway, and the transit gateway route table must associate both VPCs. VPC-B lacking a return route to VPC-A's CIDR breaks reply traffic, causing the connectivity failure.
VPC-A's route table does not have a route to the transit gateway.
The transit gateway route table does not have a route for 10.0.0.0/16.
The blackhole route in the transit gateway is blocking traffic between VPCs.
A company is deploying a new VPC with both public and private subnets. The public subnet hosts an internet-facing Application Load Balancer (ALB), and the private subnet hosts EC2 instances running a web application. The EC2 instances need to download updates from the internet, but they must not be directly accessible from the internet. Which combination of steps should a network engineer implement to meet these requirements?
Create a NAT Gateway in a public subnet, and add a default route (0.0.0.0/0) to the NAT Gateway in the private subnet's route table.
A NAT Gateway placed in the public subnet performs source NAT for outbound traffic, and the private route table's 0.0.0.0/0 entry directs that traffic to it. Instances thereby reach the internet for updates while remaining unreachable inbound, meeting the no-direct-access constraint.
Launch a proxy server in the public subnet and configure the private instances to use it for outbound traffic.
Set up a VPN connection to an on-premises network and route all internet traffic through the VPN.
Attach an Internet Gateway to the VPC and add a default route (0.0.0.0/0) to the Internet Gateway in the private subnet's route table.
A company wants to ensure that traffic between two VPCs in the same region is encrypted in transit. The VPCs are connected via a VPC peering connection. What should the network engineer do to meet this requirement?
Create an AWS Site-to-Site VPN between the VPCs and disable the VPC peering connection.
Use TLS or IPsec at the application layer between instances.
VPC peering does not support transitive encryption, so the network engineer must encrypt at the application layer using TLS or IPsec between instances. This satisfies the requirement for traffic encryption in transit across the peering connection.
Replace the VPC peering connection with a Transit Gateway and enable VPN encryption.
Enable encryption on the VPC peering connection.
Want more Network Implementation practice?
Practice this domainThe ANS-C01 exam has 65 questions and must be completed in 170 minutes. The passing score is 750/1000.
Scenario-based questions covering exam objectives with detailed answer explanations.
The exam covers 4 domains: Network Management and Operations, Network Security, Compliance and Governance, Network Design, Network Implementation. Questions are weighted by domain — higher-weight domains appear more on your actual exam.
No. These are original exam-style practice questions written against the official Amazon Web Services ANS-C01 exam objectives. They are not copied from the real exam. Courseiva focuses on genuine understanding, not memorisation of braindumps.
Courseiva tracks your accuracy per domain and routes you toward weak areas automatically. Free, no account required.