20+ practice questions focused on Network Security, Compliance and Governance — one of the most tested topics on the AWS Certified Advanced Networking Specialty ANS-C01 exam. Each question includes a detailed explanation so you learn why the right answer is correct.
Start Network Security, Compliance and Governance PracticeA company has a hybrid network with an AWS Direct Connect connection to a VPC. They also have a site-to-site VPN connection as a backup. The VPC routing tables are configured with a route to the on-premises CIDR via the virtual private gateway. The network engineer notices that traffic from the VPC to on-premises is not using the Direct Connect connection even when it is healthy. What is the most likely cause?
Explanation: When both Direct Connect and VPN are configured, the VPC route table typically has a single route to the on-premises CIDR via the virtual private gateway. Without more specific routing, the VPN BGP route may be preferred depending on route propagation and prefix matching. Option B is wrong because the VPN connection being down would not cause traffic to avoid Direct Connect. Option C is wrong because the Direct Connect virtual interface must be in the 'Available' state to pass traffic. Option D is wrong because the AWS Site-to-Site VPN connection uses a virtual private gateway or transit gateway, not a Customer Gateway as the target.
A company uses AWS Shield Advanced for DDoS protection. During an attack, the security team notices that legitimate traffic is being throttled. They want to allow certain known IP addresses to bypass Shield Advanced rate-based rules. What should they do?
Explanation: AWS WAF rules can be configured with IP sets to allow traffic from specific IPs before applying rate-based rules. Option A is wrong because Shield Advanced does not support custom allow lists directly; it works with WAF. Option B is wrong because disabling rate-based rules would remove protection for all traffic. Option D is wrong because Shield Advanced does not have a bypass feature; it uses WAF for custom rules.
Refer to the exhibit. A network engineer is troubleshooting connectivity issues from an EC2 instance in subnet-11111111. The instance can send traffic outbound, but cannot receive inbound HTTPS traffic from the internet. What is the likely cause?
Explanation: The NACL inbound rule allows HTTPS (port 443) from 0.0.0.0/0, and the outbound rule allows all traffic. NACLs are stateless, so the outbound all-traffic rule correctly permits response traffic using ephemeral ports (1024–65535). Therefore, the NACL configuration is correct for inbound HTTPS traffic. The issue must lie elsewhere, such as the instance's security group not allowing inbound HTTPS, or a missing internet gateway route. Option C is correct because it acknowledges that the NACL is not misconfigured, which is the likely scenario given the exhibit.
A company is designing a network security architecture for a multi-tier application. The web tier must be accessible from the internet, while the application and database tiers must be isolated. The security team wants to minimize the attack surface. Which design should they choose?
Explanation: It follows best practices by placing the web tier in public subnets for direct internet access via an internet gateway, and isolating the application and database tiers in private subnets. Security groups are used to allow traffic only from the web tier to the app tier and from the app tier to the DB tier, implementing least privilege. Option B is wrong because placing all tiers in private subnets with only a NAT gateway does not provide inbound internet access to the web tier; NAT gateway only supports outbound traffic. Option C is wrong because placing all tiers in the same subnet with a single security group violates the principle of least privilege, allowing unnecessary communication between tiers. Option D is wrong because placing all tiers in public subnets exposes the app and DB tiers to the internet, increasing the attack surface, and network ACLs are stateless and less flexible than security groups for controlling traffic between tiers.
A company wants to secure data at rest in an Amazon S3 bucket. Which TWO of the following can be used to achieve this? (Choose two.)
Explanation: Server-side encryption (SSE-S3) and bucket policies that deny uploads without encryption both enforce encryption of data at rest in S3. Option A enables SSE-S3, which encrypts data automatically. Option C uses a bucket policy to require encryption on uploads, ensuring data is encrypted at rest. Option B (VPC endpoint) provides private connectivity but does not encrypt data at rest. Option D (client-side encryption) is a valid encryption method, but it is not managed by S3 and is not one of the two selected answers. Option E (Transfer Acceleration) improves transfer speed, not security.
+15 more Network Security, Compliance and Governance questions available
Practice all Network Security, Compliance and Governance questions1. Baseline your knowledge
Start with 10 questions to gauge your current understanding of Network Security, Compliance and Governance. This tells you whether you need a concept refresher or just practice.
2. Review every explanation
For each question — right or wrong — read the full explanation. Understanding why an answer is correct is more valuable than knowing the answer itself.
3. Focus on exam traps
Network Security, Compliance and Governance questions on the ANS-C01 frequently use trap wording. Look for subtle differences in answers that test your precision, not just general knowledge.
4. Reach 80% consistently
Do repeated sessions until you score 80%+ three times in a row. Then move to mixed-mode practice to test cross-topic recall under realistic conditions.
The exact number varies per candidate. Network Security, Compliance and Governance is tested as part of the AWS Certified Advanced Networking Specialty ANS-C01 blueprint. Practicing with targeted Network Security, Compliance and Governance questions ensures you can handle any format or difficulty that appears.
Yes. Courseiva provides free ANS-C01 practice questions across all exam topics and domains. The platform includes topic-based practice, mock exams, missed-question review, bookmarked questions, and readiness tracking — no account required.
Difficulty is subjective, but Network Security, Compliance and Governance is a high-priority exam concept tested in multiple ways — direct recall, scenario analysis, and command-output interpretation. Consistent practice is the best way to build confidence.
Launch a full Network Security, Compliance and Governance practice session with instant scoring and detailed explanations.
Start Network Security, Compliance and Governance Practice →