Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.
exam questions

Exam AWS Certified Advanced Networking - Specialty ANS-C01 All Questions

View all questions & answers for the AWS Certified Advanced Networking - Specialty ANS-C01 exam

Exam AWS Certified Advanced Networking - Specialty ANS-C01 topic 1 question 153 discussion

A company has deployed a multi-VPC environment in the AWS Cloud. The company uses a transit gateway to connect all the VPCs together. In the past, the company has experienced a loss of connectivity between applications after changes to security groups, network ACLs, and route tables in a VPC. When these changes occur, the company wants to automatically verify that connectivity still exists between different resources in a single VPC.

  • A. Create a list of paths between different resources to check in VPC Reachability Analyzer. Create an Amazon EventBridge rule to monitor when a change is made and logged in Amazon CloudWatch. Configure the rule to invoke an AWS Lambda function to test the different paths in Reachability Analyzer.
  • B. Create a list of paths between different resources to check in VPC Reachability Analyzer. Create an Amazon EventBridge rule to monitor when a change is made and logged in AWS. CloudTrail. Configure the rule to invoke an AWS Lambda function to test the different paths in Reachability Analyzer.
  • C. Create a list of paths to check in AWS Transit Gateway Network Manager Route Analyzer. Create an Amazon EventBridge rule to monitor when a change is made and logged in Amazon CloudWatch. Configure the rule to invoke an AWS Lambda function to test the diffident paths in Route Analyzer.
  • D. Create a list of paths to check in AWS Transit Gateway Network Manager Route Analyzer. Create an Amazon EventBridge rule to monitor when a change is made and logged in AWS CloudTrail. Configure the rule to invoke an AWS Lambda function to test the different paths in Route Analyzer.
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
cerifyme85
Highly Voted 7 months ago
This is one of the biggest problems with AWS, way too many serivces, that could potentially be doing the same (eg monitoring), and we have know them all and their use cases? Would be a lot easier if their developer just had 2 or 3,and we dont have to remember all these nonsense
upvoted 5 times
...
Spaurito
Most Recent 5 days, 10 hours ago
B - all API calls are recorded in CloudTrail. When you make a change in the console, it is a backend API call.
upvoted 1 times
...
seochan
5 months, 2 weeks ago
Selected Answer: B
I thought it was D, but it's about reachability in a single VPC. So it's B.
upvoted 1 times
...
cerifyme85
6 months, 3 weeks ago
Selected Answer: B
B https://docs.aws.amazon.com/vpc/latest/reachability/logging-using-cloudtrail.html#:~:text=Reachability%20Analyzer%20is,and%20additional%20details
upvoted 1 times
...
vikasj1in
9 months ago
Selected Answer: A
Option B mentions CloudTrail, which is generally used for auditing AWS API calls rather than tracking changes within a VPC. Option C refers to AWS Transit Gateway Network Manager Route Analyzer, which is designed for analyzing routes in a transit gateway network, not within a single VPC. Option D is similar to Option C and is not applicable for checking connectivity within a single VPC. Therefore, Option A is the most appropriate choice for automatically verifying connectivity after changes in a single VPC.
upvoted 1 times
[Removed]
7 months, 1 week ago
A change in a VPC is a perfect management api call :) so you are basically explaining why B is right :)
upvoted 2 times
...
mrt261
8 months, 1 week ago
https://aws.amazon.com/blogs/networking-and-content-delivery/automating-connectivity-assessments-with-vpc-reachability-analyzer
upvoted 1 times
...
...
Marfee400704
9 months ago
I think that it's correct answer is C according to SPOTO products.
upvoted 1 times
...
sanalainen
1 year ago
Selected Answer: B
"When a security group change is made, the change event is logged in AWS CloudTrail. CloudTrail then forwards the change event to Amazon EventBridge, which evaluates the change against a series of rules to determine if any actions must be taken. Within EventBridge, a rule will be created to forward all security group change events from CloudTrail to an AWS Lambda function. The Lambda function is responsible for determining if any EC2 instances are impacted by the security group change, and if any Reachability Analyzer paths assessing the connectivity from the internet to the instance exist. " [https://aws.amazon.com/blogs/networking-and-content-delivery/automating-connectivity-assessments-with-vpc-reachability-analyzer/]
upvoted 3 times
...
[Removed]
1 year ago
sure B https://docs.aws.amazon.com/vpc/latest/reachability/what-is-reachability-analyzer.html
upvoted 1 times
...
Jahm
1 year ago
Selected Answer: A
B CloudTrail?
upvoted 1 times
...
Certified101
1 year, 3 months ago
Selected Answer: B
B https://docs.aws.amazon.com/vpc/latest/reachability/what-is-reachability-analyzer.html
upvoted 4 times
...
ISSDoksim
1 year, 3 months ago
agreed - B, https://aws.amazon.com/blogs/aws/new-vpc-insights-analyzes-reachability-and-visibility-in-vpcs/
upvoted 3 times
...
Neo00
1 year, 3 months ago
Selected Answer: B
B https://docs.aws.amazon.com/vpc/latest/reachability/what-is-reachability-analyzer.html
upvoted 4 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...