CloudPath Academy

Your guide to AWS certification success

Amazon Web Services AWS Broken Labs

AWS Certified Advanced Networking - Specialty (ANS-C01) Domain 4

Network Security, Compliance, and Governance

Official Exam Guide: Domain 4: Network Security, Compliance, and Governance

Skill Builder: AWS Certified Advanced Networking - Specialty Exam Prep


Domain Overview

Domain 4 (24%) focuses on implementing network security features, validating/auditing security, and maintaining data confidentiality.


Task 4.1: Implement network security features

Essential Documentation:


Task 4.2: Validate and audit security

Essential Documentation:


Task 4.3: Implement confidentiality of data and communications

Essential Documentation:


AWS Service FAQs


Study Tips

  1. Master Network Firewall - Stateful/stateless rules, Suricata-compatible IPS, domain filtering, traffic flow inspection.

  2. Learn encryption in transit - IPsec over Direct Connect, MACsec, TLS termination at load balancers, VPN tunnels.

  3. Understand security layers - NACLs (stateless, subnet-level), security groups (stateful, instance-level), WAF (application-level).

  4. Practice with Flow Logs - Accepted/rejected traffic, troubleshooting security group rules, identifying patterns, custom fields.

  5. Study DNSSEC - Chain of trust, KSK/ZSK keys, Route 53 implementation, validation.


Complete Exam Summary

Exam Format:

Domain Weightings:

Target Candidate:

Key AWS Networking Services:

Core Networking Concepts:

Study Resources:

Good luck with your AWS Certified Advanced Networking - Specialty certification!


Note: This is Domain 4 of 4, representing 24% of exam content.