AWS ANS-C01 resources for official exam guide links, domain pages, VPC, Direct Connect, Transit Gateway, Route 53, PrivateLink, observability, security, and encryption docs.
Use this page as the official-source hub for AWS Certified Advanced Networking - Specialty (ANS-C01). Start with the live AWS certification page and exam guide, then open service documentation only after you know which domain and network path the question is testing.
This is not a random reading list. Use it to verify current facts, resolve close answer choices, and connect this guide back to AWS documentation.
Check these before scheduling or doing a final scope review.
| Resource | Use it for |
|---|---|
| AWS Certified Advanced Networking - Specialty certification page | Current duration, question format, cost, languages, delivery options, scheduling, and AWS prep links. |
| ANS-C01 exam guide in AWS Documentation | Official exam purpose, target candidate, question types, scoring model, domain weights, and navigation to domain pages. |
| ANS-C01 in-scope services | Current AWS services and features that AWS lists as in scope. The list is non-exhaustive and subject to change. |
| AWS Certification exam guides index | Official index for AWS exam guides. |
| AWS Certification policies | Scheduling, rescheduling, identification, online proctoring, exam security, and policy checks. |
Use the domain pages when you need to verify whether a topic belongs in the exam scope.
| Domain | AWS page | Use inside this guide |
|---|---|---|
| Network Design | Domain 1 | ANS-C01 Network Design |
| Network Implementation | Domain 2 | ANS-C01 Network Implementation |
| Network Management and Operation | Domain 3 | ANS-C01 Network Management and Operations |
| Network Security, Compliance, and Governance | Domain 4 | ANS-C01 Security, Compliance, and Governance |
Use these when a question is about choosing, implementing, maintaining, or troubleshooting the network path.
| Service or feature | Official docs | Best exam use |
|---|---|---|
| Amazon VPC | Amazon VPC documentation | Subnets, route tables, security groups, NACLs, endpoints, flow logs, peering, IPv4/IPv6, quotas. |
| Transit Gateway | AWS Transit Gateway documentation | Hub routing, route tables, associations, propagation, hybrid attachments, inspection, Route Analyzer. |
| AWS Direct Connect | Direct Connect documentation | Dedicated connectivity, VIFs, DX gateway, BGP, redundancy, MACsec, jumbo frames, route preference. |
| Site-to-Site VPN | AWS Site-to-Site VPN documentation | IPsec, tunnel health, route priority, static versus dynamic routing, backup connectivity. |
| AWS PrivateLink | PrivateLink documentation | Private producer-consumer service access, endpoint policies, private DNS, endpoint services. |
| Route 53 | Route 53 documentation | Public/private hosted zones, records, health checks, routing policies, DNSSEC, Resolver. |
| Elastic Load Balancing | ELB documentation | ALB, NLB, GWLB, target groups, health checks, TLS, cross-zone, proxy protocol, appliance insertion. |
| CloudFront | CloudFront documentation | Edge delivery, cache behavior, origin protection, TLS, WAF integration, logging. |
| Global Accelerator | Global Accelerator documentation | Static Anycast IPs, TCP/UDP acceleration, endpoint health, fast regional failover. |
| Cloud WAN | AWS Cloud WAN documentation | Global network policy, segments, core networks, multi-Region WAN management. |
Use these when the prompt asks to prove, troubleshoot, audit, alert, or optimize.
| Need | Official docs | Best exam use |
|---|---|---|
| Flow-level evidence | VPC Flow Logs | Accepted/rejected traffic, base and extended fields, ENI/subnet/VPC visibility. |
| Transit Gateway flow evidence | Transit Gateway Flow Logs | TGW traffic analysis and central route-domain visibility. |
| Packet-level inspection | VPC Traffic Mirroring | Packet-level traffic copies for IDS, analysis appliances, and deep troubleshooting. |
| Reachability testing | Reachability Analyzer | Static path analysis across VPC resources. |
| Global network visibility | Transit Gateway Network Manager | Global network topology, monitoring, events, and visualization. |
| Metrics and alarms | Amazon CloudWatch | Metrics, alarms, dashboards, Logs Insights, metric filters, operational visibility. |
| API-change evidence | AWS CloudTrail | Who changed security groups, routes, firewall policies, endpoint policies, or logging. |
| Configuration posture | AWS Config | Resource configuration history, rules, compliance checks, and drift evidence. |
Use these when the requirement is inspection, least privilege, audit, or confidentiality.
| Need | Official docs | Best exam use |
|---|---|---|
| HTTP request filtering | AWS WAF | Web ACLs, managed rules, request filtering, CloudFront/ALB/API Gateway integrations. |
| DDoS resilience | AWS Shield | DDoS protection patterns and supported resources. |
| Managed network firewalling | AWS Network Firewall | Stateful/stateless rules, inspection VPC, centralized firewall policy. |
| Appliance insertion | Gateway Load Balancer | Transparent virtual appliance scaling and insertion. |
| Central firewall governance | AWS Firewall Manager | Multi-account WAF, Shield, security group, Network Firewall, and DNS Firewall governance. |
| Identity and authorization | IAM documentation | IAM conditions, cross-account permissions, least privilege, endpoint and resource policy interaction. |
| Certificate management | AWS Certificate Manager | Public certificates for supported AWS services and TLS lifecycle. |
| Private CA | AWS Private Certificate Authority | Internal PKI, private certificates, service-to-service trust, private TLS. |
| Direct Connect encryption | Encryption in AWS Direct Connect | Direct Connect is not encrypted by default; choose VPN over DX, MACsec, or TLS where appropriate. |
| MACsec | MAC Security in Direct Connect | Layer 2 point-to-point encryption on supported dedicated DX connections/LAGs. |
| If the stem says | Open first |
|---|---|
| “many VPCs across accounts need controlled routing” | Transit Gateway docs, RAM docs, Organizations docs, and Domain 1/2 pages. |
| “private access to one provider service” | PrivateLink docs and endpoint policy docs. |
| “hybrid route disappeared” | Direct Connect, Site-to-Site VPN, BGP/route priority docs, and Domain 3. |
| “DNS differs between VPC and on-premises” | Route 53 Resolver docs and Domain 1/2 DNS tasks. |
| “need packet-level visibility” | VPC Traffic Mirroring docs. |
| “who changed the security group” | CloudTrail and AWS Config docs. |
| “flow was rejected” | VPC Flow Logs and Network Firewall logs. |
| “HTTP web attack” | AWS WAF and CloudFront/ALB docs. |
| “central inspection” | Network Firewall, GWLB, Transit Gateway route tables, and Firewall Manager docs. |
| “Direct Connect traffic must be encrypted” | Direct Connect encryption, VPN over Direct Connect, MACsec, and TLS docs. |
Use the local guide pages after you verify official scope.
| Need | Page |
|---|---|
| Study sequence | ANS-C01 Study Plan |
| Final review | ANS-C01 Cheat Sheet |
| Planning questions | ANS-C01 FAQ |
| Practice-style prompts | ANS-C01 Sample Questions with Explanations |
| Term distinctions | ANS-C01 Glossary |