Skip to content

Network Implementation Questions

Practice questions for Network Implementation topic in AWS Certified Advanced Networking - Specialty. 52 questions covering this domain.

52 questions14 easy25 medium13 hard
Q1
hard

A company uses AWS Transit Gateway Connect for SD-WAN integration and wants routing plane redundancy so loss of one BGP peering session does not inter...

Q2
medium

A VPC peering connection has been accepted, but instances still cannot communicate over private IP addresses. Which action is required next?

Q3
easy

In a VPC subnet sharing model, what can participant accounts do in shared subnets?

Q4
hard

Instances in two same-Region peered VPCs use each other's public DNS hostnames, but the names still resolve to public IP addresses instead of private ...

Q5
easy

Which statement about an AWS Site-to-Site VPN connection is correct?

Q6
medium

A VPC has multiple Route 53 Resolver rules that could match the same query, such as example.com and acme.example.com. Which rule does Route 53 Resolve...

Q7
easy

A team is creating a VPC peering connection between two VPCs. Which condition must be true before the accepter can activate the peering connection?

Q8
medium

A team creates a Route 53 Resolver outbound endpoint to forward DNS queries from VPCs to on-premises DNS resolvers. What additional requirement must b...

Q9
medium

Two VPCs in the same AWS Region are peered. The security team wants to simplify security group rules by referencing a peer VPC security group directly...

Q10
hard

A security team deploys AWS Network Firewall in a dedicated inspection VPC. How should the team design the firewall subnets?

Q11
medium

A team attaches a VPC to AWS Transit Gateway and expects traffic to start flowing automatically from the VPC. What must the team configure in the VPC?

Q12
medium

Which AWS Transit Gateway attachment type requires a static route in the transit gateway route table that points to the attachment?

Q13
medium

A company wants to delegate authority for a subdomain that is hosted in a Route 53 private hosted zone so that on-premises DNS can resolve it through ...

Q14
hard

An engineer needs to terminate TLS on a load balancer for very high TPS where source IP visibility (preserving client source IP at L4) is required and...

Q15
easy

What is the maximum number of Direct Connect connections that can be aggregated into a single Link Aggregation Group (LAG)?

Q16
easy

On AWS Direct Connect, which feature provides MAC layer encryption (MACsec, IEEE 802.1AE) on dedicated connections of supported port speeds?

Q17
medium

An engineer is configuring a Site-to-Site VPN customer gateway. Which BGP feature must be supported on the customer gateway device for dynamic VPN rou...

Q18
medium

Two Transit Gateways in different AWS Regions need to exchange routes and forward traffic between them on the AWS backbone. What should the architect ...

Q19
medium

A Transit Gateway route table receives propagated routes from a VPC attachment. The team wants traffic for an external prefix to be sent through a sec...

Q20
medium

A team enables AWS Site-to-Site VPN with the Accelerated VPN feature. What does this option do?

Sign in to see all 52 questions

Create a free account to browse all questions — completely free during our launch phase.