ANS-C01 exam dumps

ANS-C01 practice question 364 of 513

AWS Certified Advanced Networking - Specialty. Expert level, Amazon Web Services. Free question with the correct answer and a full explanation.

ANS-C01 Question 364

Select 3

You are managing a hybrid cloud architecture where an on-premises data center is connected to AWS through a Site-to-Site VPN. Users are reporting intermittent connectivity issues when accessing an application hosted in a private subnet of an Amazon VPC. Which of the following steps can help you monitor and analyze network traffic to troubleshoot and optimize connectivity patterns?

  1. A

    Enable VPC Flow Logs for the affected subnet to capture traffic metadata for analysis.

  2. B

    Use AWS CloudTrail to monitor the specific API calls made to the application.

  3. C

    Set up Amazon CloudWatch metrics to monitor VPN tunnel status and bandwidth utilization.

  4. D

    Run packet capture on the on-premises router to analyze traffic patterns to AWS.

  5. E

    Use AWS Direct Connect to replace the Site-to-Site VPN for more stable connectivity.

Show answer and explanation

Correct answers: A, C, D

Explanation

To troubleshoot intermittent connectivity issues, it is critical to monitor and analyze network traffic using tools like VPC Flow Logs, CloudWatch metrics for VPN tunnel status, and packet capture on the on-premises side of the connection. These methods help identify issues like dropped packets, latency, or traffic anomalies. While switching to AWS Direct Connect may provide a longer-term solution, it is not directly related to troubleshooting and monitoring the current network setup.

  • A. Correct.

    Correct. VPC Flow Logs provide detailed traffic metadata for network interfaces, which can help identify anomalies in traffic patterns and troubleshoot connectivity issues.

  • B. Incorrect.

    Incorrect. While AWS CloudTrail is useful for tracking API activity, it does not provide insights into network traffic or connectivity patterns.

  • C. Correct.

    Correct. Monitoring VPN tunnel status and bandwidth utilization in Amazon CloudWatch can help identify potential bottlenecks or outages in the VPN connection.

  • D. Correct.

    Correct. Packet capture on the on-premises router is a valid step to analyze traffic flow and identify potential network issues between the on-premises environment and AWS.

  • E. Incorrect.

    Incorrect. While AWS Direct Connect can improve connectivity, it is a separate service that requires setup and is not directly related to monitoring or analyzing the existing Site-to-Site VPN traffic.

Timed practice exam

Take a ANS-C01 practice test under exam conditions

65 questions in 170 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam