AWS • ANS-C01
Validates expertise in designing and implementing AWS and hybrid IT network architectures at scale, including complex networking tasks such as IP VPN, MPLS, automation, routing protocols, and multi-region deployments.
Questions
1453
Duration
170 minutes
Passing Score
750/1000
Difficulty
SpecialtyLast Updated
Jan 2026
The AWS Certified Advanced Networking – Specialty (ANS-C01) validates expert-level proficiency in designing, implementing, operating, and securing AWS and hybrid IT network architectures at scale. The certification covers a broad set of advanced networking competencies including Amazon VPC architecture, AWS Direct Connect, Amazon Route 53, transit gateway designs, IP VPN, MPLS, BGP and other routing protocols, IPv4/IPv6 subnetting and transition, and multi-region network deployments. Candidates are expected to demonstrate mastery of both AWS-native networking constructs and traditional on-premises integration patterns.
This is a Specialty-tier credential, placing it at the highest level of AWS technical certifications. It requires candidates to go beyond basic cloud networking to demonstrate the ability to automate network deployments using infrastructure-as-code tools, apply AWS security best practices within network designs, and troubleshoot complex hybrid connectivity scenarios. The exam was updated to version ANS-C01 and covers the most current AWS networking services and architectures, including centralized inspection, egress controls, and network observability tooling.
This certification is designed for experienced networking professionals who hold or are pursuing a role as an AWS networking specialist. Ideal candidates have five or more years of hands-on networking experience and at least two years of cloud and hybrid networking experience. They are typically employed in roles such as Network Engineer, Cloud Network Architect, Infrastructure Architect, or Senior Solutions Architect, and are responsible for designing and managing large-scale, enterprise-grade network environments.
Candidates who benefit most from this certification are those already working with complex AWS environments and seeking to formalize their expertise, or those transitioning from traditional network engineering roles into cloud-focused positions. AWS recommends holding an Associate- or Professional-level AWS certification before attempting this Specialty exam, as familiarity with core AWS services is assumed throughout.
There are no mandatory formal prerequisites to register for the ANS-C01 exam, but AWS strongly recommends that candidates have five or more years of professional networking experience and at least two to five years of AWS Cloud exposure. Candidates should be comfortable with AWS security best practices, AWS compute and storage services and their networking implications, and AWS service integration patterns before sitting the exam.
Recommended technical knowledge includes advanced proficiency with routing protocols (BGP, OSPF), IP subnetting (IPv4 and IPv6), virtual private network technologies, DNS design, and network automation scripting. Candidates should also have working knowledge of AWS-specific services such as Amazon VPC (including VPC peering, PrivateLink, and Transit Gateway), AWS Direct Connect, AWS Site-to-Site VPN, Amazon Route 53, AWS Network Firewall, and AWS Global Accelerator. Earning the AWS Certified Solutions Architect – Associate or AWS Certified SysOps Administrator – Associate credential first is a practical preparation step.
The ANS-C01 exam consists of 65 total questions: 50 scored questions and 15 unscored questions that are used for statistical evaluation purposes and are not identified during the exam. Question types include multiple choice (one correct answer from four options) and multiple response (two or more correct answers from five or more options); some versions of the exam guide also include matching questions where candidates pair 3–7 prompts with the correct responses. The exam must be completed within 170 minutes and costs $300 USD.
The exam is delivered through Pearson VUE, either at an authorized testing center or via online proctoring. It is available in English, Japanese, Korean, and Simplified Chinese. Results are reported as a scaled score ranging from 100 to 1,000, with a minimum passing score of 750. The scoring model is compensatory, meaning candidates do not need to pass any individual domain — only the overall scaled score matters. There is no penalty for guessing; unanswered questions are counted as incorrect.
The AWS Certified Advanced Networking – Specialty is consistently ranked among the highest-paying IT certifications globally. According to global IT Skills and Salary survey data, certified professionals earn an average of approximately $151,000 per year, with compensation ranging from roughly $60,000 to over $191,000 depending on role, seniority, and location. Common job titles held by certified professionals include Cloud Network Architect, Senior Network Engineer, Infrastructure Architect, and Cloud Solutions Architect — roles that are in strong demand as enterprises accelerate hybrid cloud adoption and multi-account AWS deployments.
As a Specialty-level credential, the ANS-C01 differentiates candidates from the large pool of Associate-certified professionals and signals deep domain expertise to employers and clients. It is particularly valued in industries with complex compliance and connectivity requirements, such as financial services, healthcare, and government contracting. Unlike broader AWS Professional certifications, this credential demonstrates focused mastery of network design and security, making it a strong complement to the AWS Certified Security – Specialty or AWS Certified Solutions Architect – Professional for professionals building comprehensive cloud expertise.
5 sample questions with correct answers and explanations. Start a practice session to test yourself across all 1453 questions.
1. Proseware Inc secures their database by enabling multi-factor authentication and using security groups. They avoid bastion hosts for direct database access. Which security best practice does this follow?
Explanation
Avoiding bastion hosts and using security groups with MFA promotes secure, controlled access. It restricts internet access, prevents credential sharing, and supports encryption.
2. AdventureWorks Cycles needs to validate domain ownership for a certificate in AWS Certificate Manager. Which method should they choose for automation if their domain is hosted in Route 53?
Explanation
DNS validation allows AWS to automatically add CNAME records to Route 53 for domain validation. Email validation requires manual responses to emails sent to domain contacts. Manual certificate upload involves importing existing certificates. Third-party certificate authorities are for external issuance, not AWS-managed validation.
3. Northwind Traders is using CloudFront and needs to clear cached content manually. Which action should they take?
Explanation
Invalidating the cache removes specific content from edge locations to force fresh retrieval from the origin. Changing geographical restrictions affects access control. Signed cookies manage content access. Proxy protocol preserves source IPs.
4. Northwind Traders is expanding their application to use multiple regions for global availability. They need to connect VPCs across these regions securely. Which AWS service facilitates this cross-region connectivity?
Explanation
VPC Peering allows direct, private connectivity between VPCs in different regions without routing traffic over the public internet. An internet gateway is for internet access within a VPC. Direct Connect provides dedicated connections to AWS but is not for inter-VPC connectivity. A NAT gateway handles outbound internet traffic for private instances.
5. WoodGrove Bank has a mobile banking stack in a VPC and needs IPv6 connectivity for a third-party API without allowing inbound internet traffic. Servers must initiate all IPv6 connections. Which solution will meet these requirements?
Explanation
Egress-only internet gateways allow outbound IPv6 traffic while blocking inbound connections. NAT gateways and instances do not support IPv6. Security groups cannot be associated with egress-only gateways.
One-time access to this exam