ExamGecko
Home Home / Amazon / ANS-C00

Amazon ANS-C00 Practice Test - Questions Answers, Page 28

Question list
Search
Search

List of questions

Search

Related questions











An organization launched an IPv6-only web portal to support IPv6-native mobile clients. Front-end instances launch in an Amazon VPC associated with an appropriate IPv6 CIDR. The VPC IPv4 CIDR is fully utilized. A single subnet exists in each of two Availability Zones with appropriately configured IPv6 CIDR associations. Auto Scaling is properly configured, and no Elastic Load Balancing is used.

Customers say the service is unavailable during peak load times. The network engineer attempts to launch an instance manually and receives the following message: "There are not enough free addresses in subnet 'subnet-12345678' to satisfy the requested number of instances." What action will resolve the availability problem?

A.
Create a new subnet using a VPC secondary IPv6 CIDR, and associate an IPv6 CIDR. Include the new subnet in the Auto Scaling group.
A.
Create a new subnet using a VPC secondary IPv6 CIDR, and associate an IPv6 CIDR. Include the new subnet in the Auto Scaling group.
Answers
B.
Create a new subnet using a VPC secondary IPv4 CIDR, and associate an IPv6 CIDR. Include the new subnet in the Auto Scaling group.
B.
Create a new subnet using a VPC secondary IPv4 CIDR, and associate an IPv6 CIDR. Include the new subnet in the Auto Scaling group.
Answers
C.
Resize the IPv6 CIDR on each of the existing subnets. Modify the Auto Scaling group maximum number of instances.
C.
Resize the IPv6 CIDR on each of the existing subnets. Modify the Auto Scaling group maximum number of instances.
Answers
D.
Add a secondary IPv4 CIDR to the Amazon VPC. Assign secondary IPv4 address space to each of the existing subnets.
D.
Add a secondary IPv4 CIDR to the Amazon VPC. Assign secondary IPv4 address space to each of the existing subnets.
Answers
Suggested answer: B

You have a data center with a 2 connection LAG. You wish to add 2 more connections, how many LOAs must you complete?

A.
2
A.
2
Answers
B.
1
B.
1
Answers
C.
4
C.
4
Answers
D.
0
D.
0
Answers
Suggested answer: A

Explanation:

Explanation:

You must complete a LOA for each new physical connection.

An unfortunate situation has just come to your attention. A business critical application with sensitive data running on-prem will run out of storage disk space in 24hrs. This business critical application is dependent a very large set of routes - required for integration with other system. You make a quick but well informed decision to migrate this application quickly to AWS. You are able to quickly launch a new VPC and within it equivalent infrastructure to re-home the application. In order to complete the replication of application data and ensure the application remains operational beyond the next 24hrs, select the best implementation.

A.
Within the new VPC - establish a Direct Connect connection with max 10Gbps port speed for data replication. Establish a 802.1Q VLAN and configure a Virtual Private Gateway and Private Virtual Interface, and ensure Jumbo Frames isenabled.
A.
Within the new VPC - establish a Direct Connect connection with max 10Gbps port speed for data replication. Establish a 802.1Q VLAN and configure a Virtual Private Gateway and Private Virtual Interface, and ensure Jumbo Frames isenabled.
Answers
B.
Within the new VPC - deploy a Virtual Private Gateway, Customer Gateway, and establish a new IPsec VPN Connection with BGP dynamic routing
B.
Within the new VPC - deploy a Virtual Private Gateway, Customer Gateway, and establish a new IPsec VPN Connection with BGP dynamic routing
Answers
C.
Within the new VPC - deploy a Virtual Private Gateway, Customer Gateway, and establish a new IPsec VPN Connection with static routing, and ensure Jumbo Frames is enabled.
C.
Within the new VPC - deploy a Virtual Private Gateway, Customer Gateway, and establish a new IPsec VPN Connection with static routing, and ensure Jumbo Frames is enabled.
Answers
D.
Within the new VPC - deploy a software based virtual router (for example a Cisco CSR). Configure with dual ENIs (external and internal), create and attach an EIP to the external ENI, Configure and setup IPsec VPN tunnels, and ensureJumbo Frames is enabled.
D.
Within the new VPC - deploy a software based virtual router (for example a Cisco CSR). Configure with dual ENIs (external and internal), create and attach an EIP to the external ENI, Configure and setup IPsec VPN tunnels, and ensureJumbo Frames is enabled.
Answers
Suggested answer: B

Explanation:

Explanation:

Answer A - Let's start by stating that all possible options are actually workable solutions. The key criteria of the question is to complete the data migration aspects as *quickly* as possible. With this in mind we can immediately rule out Answer A - due to the time it takes to provision and activate a fully functional Direct Connect connection, 72+ hrs. Answer C is the same as Answer D but lacks BGP - therefore we would need to setup the routes manually - more time and effort. Additionally Answer D uses Jumbo Frames - but AWS does not support Jumbo frames over the Virtual Private Gateway - therefore Answer D's use of Jumbo Frames is negated. Overall Answer B is considered the quickest option.

Reference: http://docs.aws.amazon.com/AmazonVPC/latest/NetworkAdminGuide/GenericConfig.html

A company has 225 mobile and desktop devices and 300 partner VPNs that need access to an AWS VPC. VPN users should not be able to reach one another. Which approach will meet the technical and security requirements while minimizing costs?

A.
Use the AWS IPsec VPN for the mobile, desktop, and partner VPN connections. Use network access control lists (Network ACLs) and security groups to maintain routing separation.
A.
Use the AWS IPsec VPN for the mobile, desktop, and partner VPN connections. Use network access control lists (Network ACLs) and security groups to maintain routing separation.
Answers
B.
Use the AWS IPsec VPN for the partner VPN connections. Use an Amazon EC2 instance VPN for the mobile and desktop devices. Use Network ACLs and security groups to maintain routing separation.
B.
Use the AWS IPsec VPN for the partner VPN connections. Use an Amazon EC2 instance VPN for the mobile and desktop devices. Use Network ACLs and security groups to maintain routing separation.
Answers
C.
Create an AWS Direct Connect connection between on-premises and AWS Use a public virtual interface to connect to the AWS IPsec VPN for the mobile, desktop, and partner VPN connections.
C.
Create an AWS Direct Connect connection between on-premises and AWS Use a public virtual interface to connect to the AWS IPsec VPN for the mobile, desktop, and partner VPN connections.
Answers
D.
Use an Amazon EC2 instance VPN for the desktop, mobile, and partner VPN connections. Use features of the VPN instance to limit routing and connectivity.
D.
Use an Amazon EC2 instance VPN for the desktop, mobile, and partner VPN connections. Use features of the VPN instance to limit routing and connectivity.
Answers
Suggested answer: B

You have to set up an AWS Direct Connect connection to connect your on-premises to an AWS VPC. Due to budget requirements, you can only provision a single Direct Connect port. You have two border gateway routers at your onpremises data center that can peer with the Direct Connect routers for redundancy.

Which two design methodologies, in combination, will achieve this connectivity? (Choose two.)

A.
Terminate the Direct Connect circuit on a L2 border switch, which in turn has trunk connections to the two routers.
A.
Terminate the Direct Connect circuit on a L2 border switch, which in turn has trunk connections to the two routers.
Answers
B.
Create two Direct Connect private VIFs for the same VPC, each with a different peer IP.
B.
Create two Direct Connect private VIFs for the same VPC, each with a different peer IP.
Answers
C.
Terminate the Direct Connect circuit on any of the one routers, which in turn will have an IBGP session with the other router.
C.
Terminate the Direct Connect circuit on any of the one routers, which in turn will have an IBGP session with the other router.
Answers
D.
Create one Direct Connect private VIF for the VPC with two customer peer IPs.
D.
Create one Direct Connect private VIF for the VPC with two customer peer IPs.
Answers
E.
Provision two VGWs for the VPC and create one Direct Connect private VIF per VGW.
E.
Provision two VGWs for the VPC and create one Direct Connect private VIF per VGW.
Answers
Suggested answer: A, D

A company is using AWS to host all of its applications. Each application is isolated in its own Amazon VPC. Different environments such as Development, Test, and Production are also isolated in their own VPCs. The network engineer needs to automate VPC creation to enforce the company's network and security standards. Additionally, the CIDR range used in each VPC needs to be unique. Which solution meets all of these requirements?

A.
Use AWS CloudFormation to deploy the VPC infrastructure and a custom resource to request a CIDR range from an external IP address management (IPAM) service.
A.
Use AWS CloudFormation to deploy the VPC infrastructure and a custom resource to request a CIDR range from an external IP address management (IPAM) service.
Answers
B.
Use AWS OpsWorks to deploy the VPC infrastructure and a custom resource to request a CIDR range from an external IP address management (IPAM) service.
B.
Use AWS OpsWorks to deploy the VPC infrastructure and a custom resource to request a CIDR range from an external IP address management (IPAM) service.
Answers
C.
Use the VPC wizard in the AWS Management Console. Type in the CIDR blocks for the VPC and subnets.
C.
Use the VPC wizard in the AWS Management Console. Type in the CIDR blocks for the VPC and subnets.
Answers
D.
Create the VPCs using AWS CLI and use the dry-run flag to validate if the current CIDR range is in use.
D.
Create the VPCs using AWS CLI and use the dry-run flag to validate if the current CIDR range is in use.
Answers
Suggested answer: A

A company runs a large-scale application on a fleet of Amazon EC2 instances that are distributed across several VPCs. A Network Load Balancer (NLB) in a separate VPC routes traffic to the EC2 instances. The NLB's VPC is peered to all the application VPCs.

The application must process millions of requests each minute during times of peak utilization. Users are reporting that the connections to the application are failing during peak times. Monitoring shows an increase in port allocation errors on the NLB.

Which action will solve this issue with the LEAST change to the architecture?

A.
Increase the number of EC2 instances in the target group.
A.
Increase the number of EC2 instances in the target group.
Answers
B.
Create an Application Load Balancer for the target group.
B.
Create an Application Load Balancer for the target group.
Answers
C.
Add a new target group to the same NLB listener.
C.
Add a new target group to the same NLB listener.
Answers
D.
Change the target group type to "instance."
D.
Change the target group type to "instance."
Answers
Suggested answer: C

You need to create a baseline of normal traffic flow in order to implement some security changes to your organization.

What two items would be best to use? (Choose two.)

A.
Wireshark
A.
Wireshark
Answers
B.
CloudTrail
B.
CloudTrail
Answers
C.
An IDS
C.
An IDS
Answers
D.
CloudWatch
D.
CloudWatch
Answers
Suggested answer: A, D

What are two routing methods used by Route 53? (Choose two.)

A.
RIP
A.
RIP
Answers
B.
Failover
B.
Failover
Answers
C.
Latency
C.
Latency
Answers
D.
AS_PATH
D.
AS_PATH
Answers
Suggested answer: B, C

Explanation:

Explanation:

RIP is used for network routing and AS_PATH is used for BGP path manipulation.

A company is running services in a VPC with a CIDR block of 10.5.0.0/22. End users report that they no longer can provision new resources because some of the subnets in the VPC have run out of IP addresses. How should a network engineer resolve this issue?

A.
Add 10.5.2.0/23 as a second CIDR block to the VP
A.
Add 10.5.2.0/23 as a second CIDR block to the VP
Answers
B.
Create a new subnet with a new CIDR block, and provision new resources in the new subnet.
B.
Create a new subnet with a new CIDR block, and provision new resources in the new subnet.
Answers
C.
Add 10.5.4.0/21 as a second CIDR block to the VP
C.
Add 10.5.4.0/21 as a second CIDR block to the VP
Answers
D.
Assign a second network from this CIDR block to the existing subnets that have run out of IP addresses.
D.
Assign a second network from this CIDR block to the existing subnets that have run out of IP addresses.
Answers
E.
Add 10.5.4.0/22 as a second CIDR block to the VPAssign a second network from this CIDR block to the existing subnets that have run out of IP addresses.
E.
Add 10.5.4.0/22 as a second CIDR block to the VPAssign a second network from this CIDR block to the existing subnets that have run out of IP addresses.
Answers
F.
Add 10.5.4.0/22 as a second CIDR block to the VPC. Create a new subnet with a new CIDR block, and provision new resources in the new subnet.
F.
Add 10.5.4.0/22 as a second CIDR block to the VPC. Create a new subnet with a new CIDR block, and provision new resources in the new subnet.
Answers
Suggested answer: D
Total 414 questions
Go to page: of 42