AWS-Certified-Advanced-Networking-Specialty Dumps

AWS-Certified-Advanced-Networking-Specialty Free Practice Test

Amazon AWS-Certified-Advanced-Networking-Specialty: Amazon AWS Certified Advanced Networking - Specialty

QUESTION 16

A network engineer is managing two AWS Direct Connect connections. Each connection has a public virtual interface configured with a private ASN. The engineer wants to configure active/passive routing between the Direct Connect connections to access Amazon public endpoints. What BGP configuration is required for the on-premises equipment? (Select two.)

Correct Answer: AE
https://aws.amazon.com/premiumsupport/knowledge-center/active-passive-direct-connect/

QUESTION 17

A VPC is deployed with a 10 0 0.0/16 CIDR block. The engineering team is reviewing DHCP options and there is disagreement about the valid DNS addresses available for the VPC Which addresses are valid IP addresses provided by Amazon for this subnet' (Select TWO.)

Correct Answer: BE

QUESTION 18

Under increased cybersecurity concerns, a company is deploying a near real-time intrusion detection system (IDS) solution. A system must be put in place as soon as possible. The architecture consists of many AWS accounts, and all results must be delivered to a central location.
Which solution will meet this requirement, while minimizing downtime and costs?

Correct Answer: D
References:
https://aws.amazon.com/blogs/security/how-to-manage-amazon-guardduty-security-findings-across-multiple-acc

QUESTION 19

A network architect is designing an internet website. It has web, application, and database tiers that will run in AWS. The website uses Amazon DynamoDB.
Which architecture will minimize public exposure of the back-end instances?

Correct Answer: B

QUESTION 20

An architecture is being designed to support an Amazon WorkSpaces deployment of 1,000 desktops. Which architecture will support this deployment while allowing for future expansion?

Correct Answer: B