Amazon ANS-C00 - AWS Certified Advanced Networking - Specialty Exam

Question #11 (Topic: Topic 1)
An organization processes consumer information submitted through its website. The organizationג€™s security policy requires that personally identifiable information
(PII) elements are specifically encrypted at all times and as soon as feasible when received. The front-end Amazon EC2 instances should not have access to
decrypted PII. A single service within the production VPC must decrypt the PII by leveraging an IAM role.
Which combination of services will support these requirements? (Choose two.)
A. Amazon Aurora in a private subnet B. Amazon CloudFront using AWS Lambda@Edge C. Customer-managed MySQL with Transparent Data Encryption D. Application Load Balancer using HTTPS listeners and targets E. AWS Key Management Services
Answer: CE
Question #12 (Topic: Topic 1)
A Lambda function needs to access the private address of an Amazon ElastiCache cluster in a VPC. The Lambda function also needs to write messages to
Amazon SQS. The Lambda function has been configured to run in a subnet in the VPC.
Which of the following actions meet the requirements? (Choose two.)
A. The Lambda function needs an IAM role to access Amazon SQS B. The Lambda function must route through a NAT gateway or NAT instance in another subnet to access the public SQS API. C. The Lambda function must be assigned a public IP address to access the public Amazon SQS API. D. The ElastiCache server outbound security group rules must be configured to permit the Lambda functionג€™s security group. E. The Lambda function must consume auto-assigned public IP addresses but not elastic IP addresses.
Answer: AC
Question #13 (Topic: Topic 1)
You are deploying an EC2 instance in a private subnet that requires access to the Internet. One of the requirements for this solution is to restrict access to only
particular URLs on a whitelist. In addition to the whitelisted URLs, the instances should be able to access any Amazon S3 bucket in the same region via any URL.
Which of the following solutions should you deploy? (Choose two.)
A. Include s3.amazonaws.com in the whitelist. B. Create a VPC endpoint for S3. C. Run Squid proxy on a NAT instance. D. Deploy a NAT gateway into your VPC. E. Utilize a security group to restrict access.
Answer: CD
Question #14 (Topic: Topic 1)
Your company runs an HTTPS application using an Elastic Load Balancing (ELB) load balancer/PHP on nginx server/RDS in multiple Availability Zones. You need
to apply Geographic Restriction and identify the clientג€™s IP address in your application to generate dynamic content.
How should you utilize AWS services in a scalable fashion to perform this task?
A. Modify the nginx log configuration to record value in X-Forwarded-For and use CloudFront to apply the Geographic Restriction. B. Enable ELB access logs to store the client IP address and parse these to dynamically modify a blacklist. C. Use X-Forwarded-For with security groups to apply the Geographic Restriction. D. Modify the application code to use value of X-Forwarded-For and CloudFront to apply the Geographic Restriction.
Answer: A
Question #15 (Topic: Topic 1)
You run a well-architected, multi-AZ application in the eu-central-1 (Frankfurt) AWS region. The application is hosted in a VPC and is only accessed from the
corporate network. To support large volumes of data transfer and administration of the application, you use a single 10-Gbps AWS Direct Connect connection with
multiple private virtual interfaces. As part of a review, you decide to improve the resilience of your connection to AWS and make sure that any additional
connectivity does not share the same Direct Connect routers at AWS. You need to provide the best levels of resilience to meet the applicationג€™s needs.
Which two options should you consider? (Choose two.)
A. Install a second 10-Gbps Direct Connect connection to the same Direct Connection location. B. Deploy an IPsec VPN over a public virtual interface on a new 10-Gbps Direct Connect connection. C. Install a second 10-Gbps Direct Connect connection to a Direct Connect location in eu-west-1. D. Deploy an IPsec VPN over the Internet to the eu-west-1 region for diversity. E. Install a second 10-Gbps Direct Connect connection to a second Direct Connect location for eu-central-1.
Answer: BC
Download Exam
Page: 3 / 76
Total 377 questions