Courseiva

ANS-C01 · topic practice

Network Implementation practice questions

Use this page to practise Network Implementation questions for this certification. Focus on how the exam tests network implementation in scenario format — understanding the why behind each answer builds more durable knowledge than memorising options.

Courseiva uses original exam-style practice questions designed for learning and revision. The goal is to understand the concepts, recognise exam patterns, and improve through explanations — not memorise copied exam dumps.

Reviewed byJohnson Ajibi· MSc IT Security
20 questionsDomain: Network Implementation

What the exam tests

What to know about Network Implementation

Network Implementation questions on this certification test your ability to deploy and manage network implementation concepts in scenario-based situations.

Core Network Implementation concepts and how they apply in real-world cloud scenarios.

How to deploy network implementation correctly and verify the outcome.

Troubleshooting network implementation issues by interpreting error output and system state.

Cloud best practices and Network Implementation design trade-offs tested by this certification.

Watch out for

Common Network Implementation exam traps

  • Selecting the most expensive service when a simpler managed option meets the requirement.
  • Forgetting that cloud resources must be explicitly secured — defaults are rarely secure.
  • Choosing a global service fix when the issue is region-specific.
  • Overlooking cost implications of cross-region data transfer in architecture questions.

Practice set

Network Implementation questions

20 questions · select your answer, then reveal the explanation

Question 1hardmultiple choice
Open the full BGP breakdown →

A company has a Direct Connect connection with a private VIF connected to a VPC. The company wants to add a second Direct Connect connection for redundancy. They plan to use BGP AS_PATH prepending to influence traffic steering so that the primary connection is preferred for inbound traffic. The on-premises router advertises the same prefix over both connections. The company configures BGP on the primary VIF with AS_PATH prepending (prepend two AS numbers). However, after configuration, inbound traffic still uses both paths equally. What is the most likely cause?

Question 2mediummulti select
Study the full multicast explanation →

A company is migrating a legacy application to AWS. The application requires multicast communication between EC2 instances in the same VPC. Which THREE options can support this requirement? (Choose three.)

Question 3hardmultiple choice
Review the full subnetting walkthrough →

A network engineer is troubleshooting connectivity between two VPCs (VPC-A and VPC-B) connected via a VPC peering connection. Both VPCs have CIDR blocks: VPC-A = 10.0.0.0/16, VPC-B = 10.1.0.0/16. An EC2 instance in VPC-A (10.0.1.10) cannot ping an EC2 instance in VPC-B (10.1.1.10). Security groups and NACLs allow all traffic. The route tables are configured as follows: In VPC-A, a route to 10.1.0.0/16 via the peering connection. In VPC-B, a route to 10.0.0.0/16 via the peering connection. What is the most likely cause?

Question 4mediummultiple choice
Review the full subnetting walkthrough →

A company is deploying a multi-tier web application in a VPC with public and private subnets. The web servers in the public subnets must be able to initiate outbound connections to the internet for software updates, but must not be directly accessible from the internet. Which configuration meets these requirements?

Question 5hardmultiple choice
Open the full BGP breakdown →

A company has a Direct Connect connection with a private VIF to a VPC. The on-premises network uses BGP to advertise a specific prefix (10.0.0.0/16) to the VPC. Recently, the company deployed a new VPC with CIDR 10.0.0.0/16 in a different region and established a VPC peering connection between the two VPCs. Now, traffic from on-premises to the new VPC is being routed to the old VPC instead. How should the company resolve this issue?

Question 6hardmulti select
Read the full VPN explanation →

A company has a Direct Connect connection with a private VIF to a VPC. The on-premises network advertises the prefix 10.0.0.0/8 to AWS. The VPC has a CIDR of 10.0.0.0/16. A network engineer wants to ensure that traffic from on-premises to a specific subnet 10.0.1.0/24 in the VPC is routed via a dedicated VPN connection instead of Direct Connect for testing purposes. Which TWO actions should the engineer take?

Question 7hardmultiple choice
Review the full subnetting walkthrough →

An EC2 instance with the attached IAM role is unable to download objects from an S3 bucket. The instance is in a VPC with CIDR 10.0.0.0/16. The S3 bucket policy allows access from the VPC. What is the most likely reason for the failure?

Exhibit

Refer to the exhibit.

IAM policy attached to an EC2 instance role:

{
  "Version": "2012-10-17",
  "Statement": [
    {
      "Effect": "Allow",
      "Action": "s3:GetObject",
      "Resource": "arn:aws:s3:::example-bucket/*",
      "Condition": {
        "IpAddress": {
          "aws:SourceIp": "10.0.0.0/16"
        }
      }
    }
  ]
}
Question 8easymultiple choice
Review the full subnetting walkthrough →

A company has a VPC with multiple subnets. They want to monitor all network traffic entering and leaving the VPC for security analysis. Which AWS service should they use?

Question 9hardmultiple choice
Study the full ACL explanation →

A company has a VPC with CIDR 10.0.0.0/16. They have two subnets: a public subnet (10.0.1.0/24) and a private subnet (10.0.2.0/24). An Application Load Balancer (ALB) is deployed in the public subnet, and EC2 instances are in the private subnet. The ALB has a target group pointing to the EC2 instances. The security group for the EC2 instances allows traffic from the ALB's security group on port 80. The network ACL for the private subnet allows inbound traffic on port 80 from the public subnet CIDR (10.0.1.0/24) and allows outbound ephemeral ports. However, the ALB health checks are failing with 503 errors. The network engineer checks the ALB logs and sees that TCP connections are established but HTTP requests are timing out. What is the most likely cause?

Question 10hardmultiple choice
Read the full NAT/PAT explanation →

A company has a VPC with a public subnet and a private subnet. An EC2 instance in the private subnet needs to download patches from the internet. The instance is associated with a security group that allows outbound HTTPS (443) traffic. The route table for the private subnet has a default route pointing to a NAT Gateway in the public subnet. Which additional configuration is required to ensure the NAT Gateway can route the traffic?

Question 11hardmultiple choice
Review the full subnetting walkthrough →

A company has a multi-tier application deployed in a VPC. The web tier consists of an internet-facing Application Load Balancer (ALB) in public subnets, and EC2 instances in private subnets. The application tier runs on EC2 instances in separate private subnets, and the database tier uses an Amazon RDS for MySQL instance in private subnets. The application tier needs to connect to the database on port 3306. The security group for the RDS instance (sg-database) has an inbound rule allowing TCP 3306 from the security group of the application tier (sg-app). The application tier instances can connect to the database, but the web tier instances cannot. The web tier instances should not have direct database access. What is the most likely reason for the web tier's inability to connect to the database?

Question 12hardmultiple choice
Review the full subnetting walkthrough →

A large enterprise uses AWS Organizations with multiple accounts. The central networking account hosts a Transit Gateway with attachments from VPCs in various accounts. The enterprise uses AWS Resource Access Manager (RAM) to share the Transit Gateway with other accounts. A network engineer in a spoke account creates a VPC and attaches it to the shared Transit Gateway. The attachment shows 'available' state. However, traffic from the spoke VPC to other attached VPCs fails. The spoke VPC route table has a route to the Transit Gateway for 0.0.0.0/0. The Transit Gateway route table has routes for the spoke VPC CIDR and other VPC CIDRs. What is the most likely cause?

Question 13hardmultiple choice
Review the full subnetting walkthrough →

A company has a VPC with public and private subnets across two Availability Zones. They have a Network Load Balancer (NLB) in the public subnets. The NLB has a target group of EC2 instances in the private subnets. The NLB is configured with TLS listeners and uses a certificate from AWS Certificate Manager (ACM). Clients connect to the NLB over the internet. Some clients report connection timeouts. The NLB access logs show that the connections are established but then hang. The target instances are healthy. The security groups for the instances allow inbound TCP/443 from the NLB's private IPs. What is the most likely cause?

Question 14mediummultiple choice
Study the full IPv6 explanation →

A company has a VPC with IPv4 and IPv6 CIDRs. They have a public subnet with an internet gateway and a private subnet with a NAT gateway. EC2 instances in the private subnet need to download updates from the internet. The instances have IPv6 addresses. The private subnet route table has a default route (::/0) pointing to an egress-only internet gateway. However, instances cannot reach IPv6 internet destinations. The egress-only internet gateway is attached to the VPC and in 'available' state. What is the most likely cause?

Question 15mediummultiple choice
Read the full NAT/PAT explanation →

A company has an AWS Transit Gateway with multiple VPC attachments. They want to centralize outbound internet traffic through a single VPC that has a NAT gateway and an internet gateway. All other VPCs should route internet-bound traffic through this central VPC. What configuration is required?

Question 16mediummulti select
Review the full subnetting walkthrough →

Which THREE actions are required to enable an EC2 instance in a private subnet to download software updates from the internet? (Select THREE.)

Question 17hardmultiple choice
Review the full routing breakdown →

A network engineer is troubleshooting connectivity between two VPCs that are peered. The route tables are correct, and security groups allow traffic. However, ICMP ping fails. What is the most likely cause?

Question 18mediummultiple choice
Open the full BGP breakdown →

A company has multiple VPCs in the same AWS region that need to communicate with each other and with an on-premises data center. The company currently uses VPC peering connections between each VPC pair, which has become difficult to manage as the number of VPCs grows. The company wants to simplify the network architecture and implement a hub-and-spoke model using AWS Transit Gateway. The on-premises data center is connected to AWS via a Direct Connect connection with a private VIF. The company has already created a Transit Gateway and attached all VPCs to it. They have also created a Direct Connect gateway and associated it with the Transit Gateway. The on-premises router is advertising the on-premises CIDR (10.0.0.0/8) over BGP. However, after the migration, the VPCs cannot communicate with each other, and the on-premises network cannot reach the VPCs. The VPC route tables have been updated to route all traffic to the Transit Gateway. The Transit Gateway route table has propagation enabled for all VPC attachments and the Direct Connect gateway attachment. What is the most likely missing configuration?

Question 19mediummultiple choice
Review the full subnetting walkthrough →

A company is deploying a multi-tier web application across two AWS Regions. The application uses an Application Load Balancer (ALB) in each region, and traffic must be distributed to the closest healthy ALB using Route 53 latency-based routing. The application requires that clients maintain the same source IP address when the request is forwarded from the ALB to the backend targets. The backend targets are EC2 instances in private subnets. The company also needs to ensure that traffic between the ALB and targets stays within AWS. What should the company implement to meet these requirements?

Question 20easymultiple choice
Review the full routing breakdown →

A networking engineer is troubleshooting connectivity issues between two VPCs that are peered using a VPC peering connection. The VPCs are in different AWS accounts. The engineer has verified that the route tables are correct and the security groups allow traffic. However, ICMP ping fails from an instance in VPC A to an instance in VPC B. What is a likely cause?

Free account

Track your progress over time

Create a free account to save your results and see which topics improve across sessions.

Focused Network Implementation sessions

Start a Network Implementation only practice session

Every question in these sessions is drawn from the Network Implementation domain — nothing else.

Related practice questions

Related ANS-C01 topic practice pages

Move into related areas when this topic feels solid.

Frequently asked questions

What does the ANS-C01 exam test about Network Implementation?
Network Implementation questions on this certification test your ability to deploy and manage network implementation concepts in scenario-based situations.
How should I use these practice questions?
Select your answer before revealing the explanation. Then read why each option is right or wrong — this active recall approach builds retention far faster than re-reading notes.
Can I practise just Network Implementation questions in a focused session?
Yes — the session launcher on this page draws every question from the Network Implementation domain. Use a 10-question session first to gauge your baseline, then move to 20 or 30 once the weak spots are clear.
Where can I practise other ANS-C01 topics?
Use the topic links above to move to related areas, or go back to the ANS-C01 question bank to see all topics.
Are these real exam questions or dumps?
These are original practice questions written to test the same concepts the ANS-C01 exam covers. They are not copied from any real exam or dump site.