AmazonAmazon Advanced Networking Specialty ANS-C01 Certification ·EN ·Updated 3 Aug 2026

A company operates a workload in a single AWS VPC. The architecture includes several interface VPC endpoints for AWS services (for example, Amazon CloudWatch Logs and AWS KMS). All endpoints use the same security group, which is not attached to any other resources. A security review found the shared security group is overly permissive. The company wants to tighten the security group rules but must not break access from VPC resources to AWS services via the interface endpoints. Current security group rules are:

Choose an answer

Tap an option to check your answer.

Pass your exam — without the endless answer hunt

Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.

Pass your exam faster No card needed
✓ Verified by ExamRoll editorial · Updated 3 August 2026 · Source: official academy
All-in-one access

One subscription. Every exam.

Every plan unlocks unlimited answer search, practice tests, AI explanations, and the full resource library — in 20+ languages.

Monthly
24.87
Just €0.83/day
Everything included:
  • Unlimited answer search
  • Unlimited practice tests
  • AI-powered explanations
  • Full resource library
  • 20+ languages
  • Weekly content updates
  • Rewards & referrals
  • Priority support
Start free trial

No credit card required*

Best value
12 months
179.87
Just €0.49/daySave 40%
Everything included:
  • Unlimited answer search
  • Unlimited practice tests
  • AI-powered explanations
  • Full resource library
  • 20+ languages
  • Weekly content updates
  • Rewards & referrals
  • Priority support
Start free trial

No credit card required*

✓ Free plan included · ✓ Cancel anytime · ✓ All plans unlock the full product