Courseiva
Network Management and OperationseasyMultiple ChoiceObjective-mapped

ANS-C01 Network Management and Operations Practice Question

A network engineer is troubleshooting intermittent connectivity issues between an on-premises data center and AWS over a Direct Connect connection. The issue occurs only during peak business hours. CloudWatch metrics show increased latency and packet loss at the Direct Connect virtual interface. What is the MOST likely cause?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Insufficient bandwidth on the Direct Connect connection

Insufficient bandwidth leads to congestion during peak hours, causing increased latency and packet loss. Option A is incorrect because VPN over Direct Connect is not a common configuration and would not cause these symptoms. Option B is incorrect because asymmetric routing would cause persistent connectivity issues, not intermittent latency and packet loss. Option C is incorrect because BGP peering session flapping would result in complete loss of connectivity, not just increased latency and packet loss.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • VPN tunnel misconfiguration over Direct Connect

    Why it's wrong here

    VPN over Direct Connect is not standard and would not cause these symptoms.

  • Asymmetric routing between on-premises and AWS

    Why it's wrong here

    Asymmetric routing would cause persistent issues, not intermittent.

  • BGP peering session flapping

    Why it's wrong here

    BGP flapping would cause complete connectivity loss.

  • Insufficient bandwidth on the Direct Connect connection

    Why this is correct

    Congestion during peak hours causes latency and packet loss.

Quick reference

Asymmetric Encryption Algorithm Comparison

AlgorithmKey ExchangeSignaturesEquivalent Security KeyNotes
RSA-3072YesYes128-bitWidely deployed; slow for bulk data
ECDSA P-256NoYes128-bitFast signatures; standard TLS certs
ECDH / ECDHEYesNo128-bitPerfect forward secrecy in TLS 1.3
DH / DHEYesNo128-bit (3072-bit key)Replaced by ECDHE in modern TLS
Ed25519NoYes~128-bitSSH keys, modern PKI

About these practice questions

Courseiva writes every ANS-C01 question from scratch — 1,621 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This ANS-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the ANS-C01 exam.