ExamGecko
Home Home / Amazon / ANS-C00

Amazon ANS-C00 Practice Test - Questions Answers, Page 23

Question list
Search
Search

List of questions

Search

Related questions











A company's web application is deployed on Amazon EC2 instances behind a public Application Load Balancer. The application flags malicious requests and uses an AWS Lambda function to add the offending IP addresses to the network ACL to block any further requests for 24 hours. Recently, the application has been receiving more malicious requests, which causes the network ACL to reach its limit of allowed entries.

Which action should be taken to block more IP addresses, without compromising the existing security requirements?

A.
Update the AWS Lambda function to remove blocked entries from the network ACL after 2 hours.
A.
Update the AWS Lambda function to remove blocked entries from the network ACL after 2 hours.
Answers
B.
Update the AWS Lambda function to block malicious IPs in security groups rather than the network ACL.
B.
Update the AWS Lambda function to block malicious IPs in security groups rather than the network ACL.
Answers
C.
Update the AWS Lambda function to block malicious IPs in AWS WAF attached to the Application Load Balancer.
C.
Update the AWS Lambda function to block malicious IPs in AWS WAF attached to the Application Load Balancer.
Answers
D.
Update the AWS Lambda function to add an additional network ACL to the subnets once the limit for the previous ones has been reached.
D.
Update the AWS Lambda function to add an additional network ACL to the subnets once the limit for the previous ones has been reached.
Answers
Suggested answer: D

A company has a hybrid IT architecture with two AWS Direct Connect connections to provide high availability. The services hosted on-premises are accessible using public IPs, and are also on the 172.16.0.0/16 range. The AWS resources are on the 192.168.0.0/18 range. The company wants to use Amazon Elastic Load Balancing for SSL offloading, health checks, and sticky sessions. What should be done to meet these requirements?

A.
Create a Network Load Balancer pointing to the on-premises server's private IP address.
A.
Create a Network Load Balancer pointing to the on-premises server's private IP address.
Answers
B.
Create an Amazon CloudFront distribution for the on-premises service and use the public IPs of the on-premises servers as the origin.
B.
Create an Amazon CloudFront distribution for the on-premises service and use the public IPs of the on-premises servers as the origin.
Answers
C.
Create a Network Load Balancer pointing to the on-premises server's public IP address.
C.
Create a Network Load Balancer pointing to the on-premises server's public IP address.
Answers
D.
Create an Application Load Balancer pointing to the on-premises server's private IP address.
D.
Create an Application Load Balancer pointing to the on-premises server's private IP address.
Answers
Suggested answer: A

Your organization needs to resolve DNS entries stored in an Amazon Route 53 private zone "awscloud:internal" from the corporate network. An AWS Direct Connect connection with a private virtual interface is configured to provide access to a VPC with the CIDR block 192.168.0.0/16. A DNS Resolver (BIND) is configured on an Amazon Elastic Compute Cloud (EC2) instance with the IP address 192.168.10.5 within the VPC. The DNS Resolver has standard root server hints configured and conditional forwarding for "awscloud.internal" to the IP address 192.168.0.2.

From your PC on the corporate network, you query the DNS server at 192.168.10.5 for www.amazon.com. The query is successful and returns the appropriate response. When you query for "server.awscloud.internal", the query times out. You receive no response.

How should you enable successful queries for "server.awscloud.internal"?

A.
Attach an internet gateway to the VPC and create a default route.
A.
Attach an internet gateway to the VPC and create a default route.
Answers
B.
Configure the VPC settings for enableDnsHostnames and enableDnsSupport as True
B.
Configure the VPC settings for enableDnsHostnames and enableDnsSupport as True
Answers
C.
Relocate the BIND DNS Resolver to the corporate network.
C.
Relocate the BIND DNS Resolver to the corporate network.
Answers
D.
Update the security group for the EC2 instance at 192.168.10.5 to allow UDP Port 53 outbound.
D.
Update the security group for the EC2 instance at 192.168.10.5 to allow UDP Port 53 outbound.
Answers
Suggested answer: B

A company has an AWS Direct Connect connection between its on-premises data center and Amazon VPC. An application running on an Amazon EC2 instance in the VPC needs to access confidential data stored in the on-premises data center with consistent performance. For compliance purposes, data encryption is required. What should the network engineer do to meet these requirements?

A.
Configure a public virtual interface on the Direct Connect connection. Set up an AWS Site-to-Site VPN between the customer gateway and the virtual private gateway in the VPC.
A.
Configure a public virtual interface on the Direct Connect connection. Set up an AWS Site-to-Site VPN between the customer gateway and the virtual private gateway in the VPC.
Answers
B.
Configure a private virtual interface on the Direct Connect connection. Set up an AWS Site-to-Site VPN between the customer gateway and the virtual private gateway in the VPC.
B.
Configure a private virtual interface on the Direct Connect connection. Set up an AWS Site-to-Site VPN between the customer gateway and the virtual private gateway in the VPC.
Answers
C.
Configure an internet gateway in the VPSet up a software VPN between the customer gateway and an EC2 instance in the VPC.
C.
Configure an internet gateway in the VPSet up a software VPN between the customer gateway and an EC2 instance in the VPC.
Answers
D.
Configure an internet gateway in the VPC. Set up an AWS Site-to-Site VPN between the customer gateway and the virtual private gateway in the VPC.
D.
Configure an internet gateway in the VPC. Set up an AWS Site-to-Site VPN between the customer gateway and the virtual private gateway in the VPC.
Answers
Suggested answer: A

Which service would you use to see the DSCP value in a packet header?

A.
CloudTrail
A.
CloudTrail
Answers
B.
Config
B.
Config
Answers
C.
Flow Logs
C.
Flow Logs
Answers
D.
None of the above
D.
None of the above
Answers
Suggested answer: D

Explanation:

Explanation:

To perform deep packet inspection, you would need a specialized tool such as Wireshark.

A company deployed its production Amazon VPC using CIDR block 33.16.0.0/16. The company has nearly depleted its addresses and now needs to extend the VPC network.

Which CIDR blocks meet the company's requirement to extend the VPC network with a secondary CIDR? (Choose two.)

A.
33.17.0.0/16
A.
33.17.0.0/16
Answers
B.
172.16.0.0/18
B.
172.16.0.0/18
Answers
C.
100.70.0.0/17
C.
100.70.0.0/17
Answers
D.
192.168.1.0/24
D.
192.168.1.0/24
Answers
E.
10.0.0.0/8
E.
10.0.0.0/8
Answers
Suggested answer: A, C

What is the IPv6 subnet CIDR used by a VPC?

A.
/128
A.
/128
Answers
B.
/56
B.
/56
Answers
C.
/48
C.
/48
Answers
D.
/16
D.
/16
Answers
Suggested answer: B

Explanation:

Explanation:

A VPC will always use /56 as its CIDR

You have a three-tier web application with separate subnets for Web, Applications, and Database tiers. Your CISO suspects your application will be the target of malicious activity. You are tasked with notifying the security team in the event your application is port scanned by external systems.

Which two AWS Services cloud you leverage to build an automated notification system? (Choose two.)

A.
Internet gateway
A.
Internet gateway
Answers
B.
VPC Flow Logs
B.
VPC Flow Logs
Answers
C.
AWS CloudTrail
C.
AWS CloudTrail
Answers
D.
Lambda
D.
Lambda
Answers
E.
AWS Inspector
E.
AWS Inspector
Answers
Suggested answer: C, D

Explanation:

Explanation:

References: https://aws.amazon.com/blogs/security/how-to-receive-alerts-when-specific-apis-are-called-by-using-awscloudtrail-amazon-sns-and-aws-lambda/

You need to set up an Amazon Elastic Compute Cloud (EC2) instance for an application that requires the lowest latency and the highest packet-per-second network performance. The application will talk to other servers in a peered VPC.

Which two of the following components should be part of the design? (Choose two.)

A.
Select an instance with support for single root I/O virtualization.
A.
Select an instance with support for single root I/O virtualization.
Answers
B.
Select an instance that has support for multiple ENAs.
B.
Select an instance that has support for multiple ENAs.
Answers
C.
Ensure that the instance supports jumbo frames and set 9001 MTU.
C.
Ensure that the instance supports jumbo frames and set 9001 MTU.
Answers
D.
Select an instance with Amazon Elastic Block Store (EBS)-optimization.
D.
Select an instance with Amazon Elastic Block Store (EBS)-optimization.
Answers
E.
Ensure that proper OS drivers are installed.
E.
Ensure that proper OS drivers are installed.
Answers
Suggested answer: A, B

Explanation:

Explanation:

References: https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/enhanced-networking.html

What is the DNS server address for a VPC (10.111.0.0/16) with a subnet of 10.111.4.0/24?

A.
10.111.0.2
A.
10.111.0.2
Answers
B.
10.111.4.2
B.
10.111.4.2
Answers
C.
10.111.1.2
C.
10.111.1.2
Answers
D.
10.111.4.1
D.
10.111.4.1
Answers
Suggested answer: A

Explanation:

Explanation:

The DNS server is the base VPC CIDR + 2.

Total 414 questions
Go to page: of 42