AWS ANS-C01 30-, 60-, and 90-day study plan for hybrid routing, DNS, Transit Gateway, PrivateLink, observability, security, encryption, review loops, and final-week priorities.
Use this study plan when you want a structured route through AWS Certified Advanced Networking - Specialty (ANS-C01). ANS-C01 is not an associate-level VPC review. It tests whether you can design, implement, manage, operate, troubleshoot, secure, and govern AWS and hybrid network architectures at scale.
The exam rewards path reasoning: source, destination, route table, propagation, association, DNS answer, security control, inspection point, return path, health signal, and evidence source. If you answer by service familiarity instead of proving the path, ANS-C01 will feel unpredictable.
I verified these current AWS exam facts on May 17, 2026.
| Item | Value |
|---|---|
| Exam | AWS Certified Advanced Networking - Specialty |
| Exam code | ANS-C01 |
| Category | Specialty |
| Questions | 65 total |
| Scoring | 50 scored and 15 unscored; unscored items are not identified |
| Question types | AWS overview lists multiple choice or multiple response; current exam guide also lists matching |
| Time | 170 minutes |
| Passing score | 700 on a 100-1000 scaled score |
| Cost | 300 USD |
| Target candidate | 5+ years of networking experience, including 2+ years of cloud and hybrid networking |
Because the current AWS exam-guide page lists matching, practice pairing prompts with network controls and evidence sources. Treat matching as a path-proof exercise, not as flash-card recall.
| Domain | Weight | How to allocate study time |
|---|---|---|
| Network Design | 30% | Spend the most time on hybrid connectivity, multi-VPC design, DNS/service discovery, edge entry, failover, segmentation, observability, and cost-aware topology. |
| Network Implementation | 26% | Drill VPC routing, Direct Connect, VPN, Transit Gateway, Cloud WAN, peering, PrivateLink, endpoints, DNS, automation, and rollout steps. |
| Network Security, Compliance, and Governance | 24% | Practice inspection, segmentation, WAF/Shield, Network Firewall, GWLB, endpoint policies, encryption, logging, and audit evidence. |
| Network Management and Operations | 20% | Study maintenance, route changes, troubleshooting, flow evidence, reliability, performance, cost, health checks, and operational validation. |
Design and implementation are 56% of scored content, but security and operations are not separate afterthoughts. Most difficult questions combine path design, security placement, DNS behavior, and evidence.
| Starting point | Typical study time | Best-fit timeline |
|---|---|---|
| You design AWS hybrid networks or multi-account VPCs today | 60-85 hours | 30-60 days |
| You are strong in traditional networking but newer to AWS networking | 90-130 hours | 60 days |
| You know AWS associate networking but not advanced hybrid patterns | 100-150 hours | 60-90 days |
| BGP, hybrid DNS, TGW, PrivateLink, and inspection routing are new | 150+ hours | 90 days before scheduling |
Choose the longer route if you cannot explain BGP route preference, Transit Gateway route-table association/propagation, Resolver inbound/outbound endpoints, overlapping CIDR strategy, asymmetric routing, endpoint policy behavior, and inspection insertion without notes.
Use one path-proof loop every week.
flowchart LR
S["Scenario"] --> P["Path"]
P --> R["Route and return"]
R --> D["DNS"]
D --> C["Control point"]
C --> E["Evidence"]
E --> M["Miss rule"]
| Step | What to ask |
|---|---|
| Scenario | Is the problem design, implementation, operations, security, governance, performance, or cost? |
| Path | What is the exact source, destination, VPC/account/Region boundary, and expected traffic direction? |
| Route and return | Which route table, TGW table, propagation, association, BGP advertisement, endpoint, or NAT path controls forward and return traffic? |
| DNS | Which hosted zone, Resolver endpoint, forwarding rule, record, health check, or cache behavior controls name resolution? |
| Control point | Where should filtering, inspection, encryption, WAF/Shield, endpoint policy, segmentation, or audit happen? |
| Evidence | Which tool proves the issue: flow logs, route tables, Reachability Analyzer, Traffic Mirroring, CloudWatch, health checks, ELB logs, WAF logs, or CloudTrail? |
Do not only read documentation. ANS-C01 preparation works better when every study block produces a small artifact you can reuse during review.
| Artifact | Build it when | What it should contain |
|---|---|---|
| Route proof | Hybrid, TGW, peering, PrivateLink, endpoint, or multi-account question | Source, destination, route table, propagation, association, route priority, return path, and failure mode. |
| DNS proof | Route 53, Resolver, private hosted zone, split-horizon, or hybrid name-resolution question | Query source, resolver path, hosted zone, forwarding rule, association boundary, cache/TTL, and health behavior. |
| Control proof | WAF, Shield, Network Firewall, GWLB, SG, NACL, endpoint policy, or IAM question | Traffic direction, trust boundary, enforcement layer, route steering, and what bypass would look like. |
| Evidence proof | Audit, troubleshooting, alerting, or monitoring question | Log source, delivery target, correlation key, alarm/finding, and retention path. |
| Confidentiality proof | TLS, IPsec, VPN over DX, MACsec, ACM, ACM PCA, S3 HTTPS, or DNSSEC question | Protected hop, encryption layer, certificate/key lifecycle, and shared-responsibility boundary. |
You do not need to deploy a giant network lab, but you should be able to explain these paths precisely:
| Path | What you should know |
|---|---|
| Private subnet to AWS service | Gateway endpoint vs interface endpoint, route behavior, DNS, endpoint policy, security group, and NAT avoidance |
| VPC-to-VPC at scale | Peering vs Transit Gateway vs Cloud WAN vs PrivateLink, including segmentation, overlapping CIDR, and blast radius |
| Hybrid connectivity | Site-to-Site VPN vs Direct Connect, BGP, route preference, redundancy, failover, encryption, and monitoring |
| Hybrid DNS | Route 53 Resolver inbound/outbound endpoints, forwarding rules, private hosted zones, split-horizon DNS, and association boundaries |
| Edge entry | Route 53, CloudFront, Global Accelerator, ALB, NLB, GWLB, WAF, Shield, origin protection, and health behavior |
| Inspection path | AWS Network Firewall or GWLB insertion, route symmetry, centralized inspection, fail-open/fail-closed trade-offs, and logging |
| Evidence path | VPC Flow Logs, Reachability Analyzer, Traffic Mirroring, ELB logs, WAF logs, CloudFront logs, CloudWatch metrics, health checks, and route inspection |
| Confidentiality path | TLS placement, target-side encryption, VPN over Direct Connect, MACsec boundary, ACM, ACM PCA, DNSSEC, and service policy enforcement |
Use this route only if you already have strong networking experience and practical AWS exposure.
| Week | Focus | What to produce |
|---|---|---|
| 1 | Network design | A design decision table for hybrid connectivity, multi-VPC topology, DNS/service discovery, edge entry, segmentation, observability, and failover. |
| 2 | Network implementation | A configuration checklist for TGW, peering, PrivateLink, endpoints, DX/VPN, Resolver, route tables, BGP, automation, and deployment order. |
| 3 | Network operations | A troubleshooting runbook that separates route, DNS, security, endpoint, inspection, health, return path, and telemetry failures. |
| 4 | Security, governance, and mixed review | A control map for WAF/Shield, Network Firewall, GWLB, segmentation, TLS/IPsec, endpoint policies, audit logs, compliance evidence, and matching practice. |
Every study day should create one concrete artifact.
| Artifact | Why it matters |
|---|---|
| Route diagram | Forces you to verify next hop, TGW association, TGW propagation, BGP route, return path, and failure domain. |
| DNS diagram | Prevents hybrid/private-zone confusion and exposes Resolver endpoint or forwarding-rule mistakes. |
| Inspection diagram | Shows whether traffic remains symmetric and whether the control belongs at edge, subnet, firewall, endpoint, or policy layer. |
| Evidence table | Converts “check logs” into a specific source: flow logs, route table, analyzer, mirror, ELB log, WAF log, metric, or health check. |
| Matching drill | Builds speed for pairing symptoms with services, controls, and evidence. |
| Miss log | Converts plausible-but-wrong answers into reusable path rules. |
This is the best default route for most candidates.
| Weeks | Focus | What to do |
|---|---|---|
| 1-2 | Network Design | Study hybrid connectivity, multi-VPC topology, DNS, service discovery, load balancing, edge, observability by design, segmentation, and cost-aware path choices. |
| 3-4 | Network Implementation | Drill DX/VPN, BGP, TGW route tables, peering, RAM sharing, Cloud WAN, PrivateLink, Resolver endpoints, endpoint policies, automation, and rollout order. |
| 5 | Network Management and Operations | Practice route maintenance, troubleshooting, flow evidence, packet evidence, performance, reliability, health checks, cost optimization, and validation. |
| 6 | Network Security, Compliance, and Governance | Study WAF, Shield, Network Firewall, GWLB, segmentation, inspection, TLS/IPsec, MACsec, ACM PCA, endpoint policies, audit evidence, and governance controls. |
| 7 | Mixed path drills | Run mixed sets and redraw every missed question with source, destination, route, DNS, security, return path, and evidence. |
| 8 | Final repair and scheduling decision | Reread weak lessons, review the cheat sheet, answer sample questions, practice matching items, and schedule only if misses are narrow. |
Use this route if you are building AWS networking depth while studying.
| Phase | Weeks | Outcome |
|---|---|---|
| AWS networking foundation | 1-3 | You can explain VPC routing, SG/NACL behavior, endpoints, NAT, DNS, load balancers, and edge entry without guessing. |
| Hybrid and scale architecture | 4-6 | You can choose DX, VPN, TGW, Cloud WAN, PrivateLink, peering, Resolver, and multi-Region patterns under constraints. |
| Operations and evidence | 7-8 | You can troubleshoot failures using route state, DNS behavior, flow logs, packet evidence, health checks, metrics, and analyzer tools. |
| Security and governance | 9-10 | You can place inspection, encryption, segmentation, WAF/Shield, endpoint policies, and audit controls on the correct path. |
| Exam execution | 11-12 | You can answer dense path scenarios and matching items under time pressure and explain why distractors solve the wrong layer. |
| Domain | Drill questions until you can answer… |
|---|---|
| Network Design | Which connectivity primitive satisfies scale, failure domain, route control, segmentation, DNS, security, and cost requirements? |
| Network Implementation | Which route table, TGW table, association, propagation, endpoint, BGP advertisement, DNS rule, or automation step must be configured? |
| Network Management and Operations | What evidence proves where the path fails, and what validates that the fix worked? |
| Network Security, Compliance, and Governance | Where should the control live: edge, subnet, firewall, endpoint, policy, certificate, encryption, or audit layer? |
Use the guide’s practice pages in a sequence, not as random links.
| Stage | Use | Goal |
|---|---|---|
| After each domain | ANS-C01 Sample Questions with Explanations | Test whether you can explain the right answer and each distractor. |
| After the full first pass | ANS-C01 Cheat Sheet | Compress each miss into a path, control, evidence, or encryption rule. |
| When terms blur | ANS-C01 Glossary | Separate close services such as TGW vs PrivateLink, WAF vs Network Firewall, or CloudTrail vs Flow Logs. |
| Before official-doc review | ANS-C01 Resources | Open official AWS docs only for the specific weak path or service. |
| Before scheduling | ANS-C01 FAQ | Recheck facts, readiness, timing, and common exam traps. |
| Decision | Choose by asking… |
|---|---|
| Transit Gateway vs VPC peering | Do you need hub-and-spoke scale, route-table segmentation, and centralized control, or a small direct VPC relationship? |
| PrivateLink vs peering/TGW | Does the consumer need private service access without full network-level connectivity? |
| Cloud WAN vs Transit Gateway | Is the requirement a global policy-managed network operating model or regional hub-and-spoke routing? |
| Direct Connect vs Site-to-Site VPN | Do you need predictable private connectivity and higher consistency, or faster/lower-cost encrypted connectivity over the internet? |
| Resolver inbound vs outbound endpoint | Are on-premises resolvers querying AWS zones, or AWS workloads forwarding queries to on-premises DNS? |
| Gateway endpoint vs interface endpoint | Is the target S3/DynamoDB through route tables, or another AWS service through PrivateLink ENIs? |
| CloudFront vs Global Accelerator | Is the requirement HTTP caching/content delivery, or global application entry-path performance for static IPs and non-HTTP patterns? |
| Network Firewall vs GWLB appliance | Is the requirement AWS-managed network firewalling, or insertion of third-party virtual appliances? |
| Flow Logs vs Traffic Mirroring | Do you need metadata about traffic decisions, or packet-level inspection for deeper analysis? |
| CloudTrail vs Flow Logs | Do you need to know who changed AWS configuration, or whether traffic was accepted/rejected? |
| VPN over Direct Connect vs MACsec | Do you need IPsec tunnel encryption over the DX path, or Layer 2 encryption on a supported dedicated DX connection? |
| ACM vs ACM PCA | Do you need public certificates for supported AWS endpoints, or a private internal trust hierarchy? |
The current AWS exam-guide page lists matching as a question type. Practice these explicitly.
| Prompt type | Match to… |
|---|---|
| Hybrid DNS symptom | Resolver inbound/outbound endpoint, forwarding rule, private hosted zone association, or split-horizon design |
| Connectivity failure | Route table, TGW route table, propagation, association, security group, NACL, endpoint, or return path |
| Edge/performance requirement | Route 53, CloudFront, Global Accelerator, ALB, NLB, or origin protection control |
| Inspection requirement | Network Firewall, GWLB, WAF, Shield, centralized egress, route symmetry, or log source |
| Evidence requirement | VPC Flow Logs, Reachability Analyzer, Traffic Mirroring, CloudWatch metrics, ELB logs, WAF logs, or CloudTrail |
For matching items, do not match by service familiarity. Match by the exact layer being tested.
Use the final week for path speed, not new service sprawl.
| Day | Work |
|---|---|
| 7 days out | Reread the cheat sheet and redraw the main network path map from memory. |
| 6 days out | Drill hybrid connectivity: DX, VPN, BGP, route preference, redundancy, encryption, failover, and monitoring. |
| 5 days out | Drill scale patterns: Transit Gateway, peering, PrivateLink, Cloud WAN, multi-account, multi-Region, and overlapping CIDR. |
| 4 days out | Drill DNS: Resolver endpoints, private hosted zones, forwarding rules, split-horizon DNS, health checks, and failover. |
| 3 days out | Drill edge and inspection: Route 53, CloudFront, Global Accelerator, ALB/NLB/GWLB, WAF, Shield, Network Firewall, and route symmetry. |
| 2 days out | Drill troubleshooting and evidence: flow logs, packet mirroring, Reachability Analyzer, metrics, route tables, health checks, matching prompts, and return path. |
| 1 day out | Review only weak path rules, domain weights, current facts, and high-yield comparisons. |
You are close to ready when:
This is not ideal for a specialty exam, but if you are already near-ready:
Schedule only when your misses are narrow and explainable. If you still answer by service familiarity instead of path reasoning, keep studying. ANS-C01 rewards network proof: route, DNS, security, return path, failure domain, and evidence.