{"id":20665,"date":"2021-11-28T11:00:00","date_gmt":"2021-11-28T05:30:00","guid":{"rendered":"https:\/\/www.testpreptraining.com\/blog\/?p=20665"},"modified":"2022-09-14T17:17:31","modified_gmt":"2022-09-14T11:47:31","slug":"how-to-start-your-career-as-an-aws-advanced-networking-specialist","status":"publish","type":"post","link":"https:\/\/www.testpreptraining.ai\/blog\/how-to-start-your-career-as-an-aws-advanced-networking-specialist\/","title":{"rendered":"How to start your career as an AWS Advanced Networking Specialist?"},"content":{"rendered":"\n<p>The AWS certification is well-known for offering the greatest IT infrastructure services for cloud computing firms and businesses. As a result, the company has increased energy efficiency by lowering capital infrastructure expenditures and variable costs as it develops. However, when it comes to AWS certifications, the demand for the AWS Certified Advanced Networking &#8211; Specialty test has increased rapidly in recent years. The exam validates networking knowledge and the learner&#8217;s ability to use AWS network services to fulfill performance, cost, and security objectives.<\/p>\n\n\n\n<p>Many businesses and organizations are turning to AWS Certified Advanced Networking Specialists to assist them to improve their networking dependability and scalability. As a result, the value of AWS Certification has increased globally. However, achieving this part isn&#8217;t simple. To put it another way, passing this exam necessitates significant knowledge and expertise, as well as a strong desire to obtain this position. As a result, in this blog, we&#8217;ll go through every aspect of the Advanced Specialty exam that will help you get this. The first and most important step, however, is to pass the AWS certification. Let&#8217;s start with a general overview of the exam.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>What is the AWS Advanced Networking Specialty exam?<\/strong><\/h3>\n\n\n\n<p>If you have the knowledge for executing the function of AWS Networking Specialist then, you should take the <a href=\"https:\/\/www.testpreptraining.ai\/aws-certified-advanced-networking-specialty-practice-exam\" target=\"_blank\" rel=\"noreferrer noopener\">AWS Certified Advanced Networking \u2013 Specialty <\/a>(ANS-C00) exam. However, the exam certifies advanced technical knowledge and competence in the design and execution of large-scale AWS and hybrid IT network infrastructures. Further, this exam certifies your ability to accomplish the following:<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li>Firstly, planning, developing and deploying cloud-based solutions by using AWS<\/li><li>Secondly, applying core AWS services according to basic architectural best practices<\/li><li>Thirdly, planning and maintaining network architecture for all AWS services<\/li><li>Lastly, using tools for automating AWS networking tasks<\/li><\/ul>\n\n\n\n<h6 class=\"wp-block-heading\"><strong><span style=\"text-decoration: underline;\">Target candidates:<\/span><\/strong><\/h6>\n\n\n\n<p>The ideal candidate has <a href=\"https:\/\/www.testpreptraining.ai\/aws-certified-advanced-networking-specialty-practice-exam\" target=\"_blank\" rel=\"noreferrer noopener\">advanced networking<\/a> knowledge that much exceeds the requirements of an AWS Certified Solutions Architect &#8211; Professional. The ideal applicant will be an experienced solutions architect with 5\u20137 years of networking specialization and experience in design, implementation, and troubleshooting. Further, they must have experience with large-scale infrastructure engineering (for example, complicated SMB, corporate, ISP, and LAN\/WAN settings).<\/p>\n\n\n\n<p><strong><span style=\"text-decoration: underline;\">Recommended general IT knowledge<\/span><\/strong>:<\/p>\n\n\n\n<p>The ideal applicant will be well-versed in the following areas:<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li>Firstly, interconnectivity and advanced networking architectures (for example, IP VPN, multiprotocol label switching [MPLS], virtual private LAN service [VPLS])<\/li><li>Secondly, the Open Systems Interconnection (OSI) model&#8217;s networking technologies and how they impact implementation decisions<\/li><li>Thirdly, Automation scripts and tools development. However, the following will be designed, implemented, and optimised:<ul><li>Routing architectures (including static and dynamic)<\/li><li>Multi-Region solutions for a global enterprise<\/li><li>Solutions for high-availability connection (for example, AWS Direct Connect, VPN)<\/li><\/ul><\/li><li>Then, CIDR and subnetting (IPv4 and IPv6)<\/li><li>After that, IPv6 transition challenges<\/li><li>Lastly, generic solutions for network security features, including:<ul><li>AWS WAF<\/li><li>intrusion detection systems (IDS)<\/li><li>intrusion prevention systems (IPS)<\/li><li>DDoS protection<\/li><li>economic denial of service\/sustainability (EDoS)<\/li><\/ul><\/li><\/ul>\n\n\n\n<p><em>But, how to start preparing to pass the AWS Advanced Networking Specialty exam?<\/em><\/p>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>Preparation ways for passing the Advanced Specialty Exam<\/strong><\/h3>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter size-full\"><img decoding=\"async\" width=\"935\" height=\"492\" src=\"https:\/\/www.testpreptraining.ai\/blog\/wp-content\/uploads\/2021\/11\/advanced-networking-exam.png\" alt=\"advanced specialty exam\" class=\"wp-image-20676\" srcset=\"https:\/\/www.testpreptraining.ai\/blog\/wp-content\/uploads\/2021\/11\/advanced-networking-exam.png 935w, https:\/\/www.testpreptraining.ai\/blog\/wp-content\/uploads\/2021\/11\/advanced-networking-exam-300x158.png 300w\" sizes=\"(max-width: 935px) 100vw, 935px\" \/><\/figure><\/div>\n\n\n\n<h4 class=\"wp-block-heading\"><strong>Step 1. Understanding the exam objectives<\/strong><\/h4>\n\n\n\n<p>We&#8217;ve covered the basics of the exam pattern and the specifics that are required to move on with exam preparation. Now we&#8217;ll go on to the most important part of this blog: the exam topics. Because the <a href=\"https:\/\/www.testpreptraining.ai\/aws-certified-advanced-networking-specialty-practice-exam\" target=\"_blank\" rel=\"noreferrer noopener\">exam guide<\/a> is the sole area in which we must devote the majority of our study time, aside from practice exams. This guide contains a test course overview as well as a list of all exam subjects and sub-topics. As a result, maintaining a high level of attention is necessary in order to grasp exam themes. This includes the following:<\/p>\n\n\n\n<h5 class=\"wp-block-heading\"><strong>Updated AWS Certified Advanced Networking &#8211; Specialty (ANS-C01) Course outline<\/strong><\/h5>\n\n\n\n<h5 class=\"wp-block-heading\"><strong>Domain 1: Network Design (30%)<\/strong><\/h5>\n\n\n\n<p><strong>Task Statement 1.1: Design a solution that incorporates edge network services to optimize user performance and traffic management for global architectures.<\/strong><\/p>\n\n\n\n<p>Knowledge of:<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li>Design patterns for the usage of content distribution networks (for example, Amazon CloudFront) <strong>(AWS Documentation:<\/strong> <a href=\"https:\/\/docs.aws.amazon.com\/mediapackage\/latest\/ug\/cdns.html\" target=\"_blank\" rel=\"noreferrer noopener\">Working with Content Delivery Networks (CDNs)<\/a>)<\/li><li>Design patterns for global traffic management (for example, AWS Global Accelerator) <strong>(AWS Documentation:<\/strong> <a href=\"https:\/\/docs.aws.amazon.com\/global-accelerator\/latest\/dg\/getting-started.html\" target=\"_blank\" rel=\"noreferrer noopener\">Getting started with AWS Global Accelerator<\/a>, <a href=\"https:\/\/aws.amazon.com\/blogs\/networking-and-content-delivery\/traffic-management-with-aws-global-accelerator\/\" target=\"_blank\" rel=\"noreferrer noopener\">Traffic management with AWS Global Accelerator<\/a>)<\/li><li>Integration patterns for content distribution networks and global traffic management with other services (for example, Elastic Load Balancing, Amazon API Gateway) <strong>(AWS Documentation:<\/strong> <a href=\"https:\/\/docs.aws.amazon.com\/whitepapers\/latest\/aws-overview\/networking-services.html\" target=\"_blank\" rel=\"noreferrer noopener\">Networking and Content Delivery<\/a>, <a href=\"https:\/\/aws.amazon.com\/blogs\/networking-and-content-delivery\/introduction-to-network-transformation-on-aws-part-2\/\" target=\"_blank\" rel=\"noreferrer noopener\">Introduction to Network Transformation on AWS<\/a>)<\/li><\/ul>\n\n\n\n<p>Skills in:<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li>Evaluating requirements of global inbound and outbound traffic from the internet to design an appropriate content distribution solution <strong>(AWS Documentation:<\/strong> <a href=\"https:\/\/docs.aws.amazon.com\/prescriptive-guidance\/latest\/security-reference-architecture\/network.html\" target=\"_blank\" rel=\"noreferrer noopener\">Infrastructure OU &#8211; Network account<\/a>, <a href=\"https:\/\/docs.aws.amazon.com\/Route53\/latest\/DeveloperGuide\/routing-to-cloudfront-distribution.html\" target=\"_blank\" rel=\"noreferrer noopener\">Routing traffic to an Amazon CloudFront distribution<\/a>)<\/li><\/ul>\n\n\n\n<p><strong>Task Statement 1.2: Design DNS solutions that meet public, private, and hybrid requirements.<\/strong><\/p>\n\n\n\n<p>Knowledge of:<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li>DNS protocol (for example, DNS records, timers, DNSSEC, DNS delegation, zones) <strong>(AWS Documentation:<\/strong> <a href=\"https:\/\/docs.aws.amazon.com\/Route53\/latest\/DeveloperGuide\/domain-configure-dnssec.html\" target=\"_blank\" rel=\"noreferrer noopener\">Configuring DNSSEC for a domain<\/a>, <a href=\"https:\/\/docs.aws.amazon.com\/Route53\/latest\/DeveloperGuide\/ResourceRecordTypes.html\" target=\"_blank\" rel=\"noreferrer noopener\">Supported DNS record types<\/a>, <a href=\"https:\/\/docs.aws.amazon.com\/Route53\/latest\/DeveloperGuide\/route-53-concepts.html\" target=\"_blank\" rel=\"noreferrer noopener\">Amazon Route&nbsp;53 concepts<\/a>)<\/li><li>DNS logging and monitoring <strong>(AWS Documentation:<\/strong> <a href=\"https:\/\/docs.aws.amazon.com\/Route53\/latest\/DeveloperGuide\/logging-monitoring.html\" target=\"_blank\" rel=\"noreferrer noopener\">Logging and monitoring in Amazon Route&nbsp;53<\/a>)<\/li><li>Amazon Route 53 features (for example, alias records, traffic policies, resolvers, health checks) <strong>(AWS Documentation:<\/strong> <a href=\"https:\/\/docs.aws.amazon.com\/Route53\/latest\/DeveloperGuide\/dns-failover.html\" target=\"_blank\" rel=\"noreferrer noopener\">Creating Amazon Route&nbsp;53 health checks and configuring DNS failover<\/a>, <a href=\"https:\/\/docs.aws.amazon.com\/Route53\/latest\/DeveloperGuide\/health-checks-how-route-53-chooses-records.html\" target=\"_blank\" rel=\"noreferrer noopener\">Amazon Route&nbsp;53 chooses records when health checking<\/a>, <a href=\"https:\/\/aws.amazon.com\/route53\/faqs\/\" target=\"_blank\" rel=\"noreferrer noopener\">Amazon Route 53 FAQs<\/a>)<\/li><li>Integration of Route 53 with other AWS networking services (for example, Amazon VPC) <strong>(AWS Documentation:<\/strong> <a href=\"https:\/\/docs.aws.amazon.com\/Route53\/latest\/DeveloperGuide\/integration-with-other-services.html\" target=\"_blank\" rel=\"noreferrer noopener\">Integration with other services<\/a>, <a href=\"https:\/\/docs.aws.amazon.com\/Route53\/latest\/DeveloperGuide\/resolver.html\" target=\"_blank\" rel=\"noreferrer noopener\">Resolving DNS queries between VPCs and your network<\/a>)<\/li><li>Integration of Route 53 with hybrid, multi-account, and multi-Region options <strong>(AWS Documentation:<\/strong> <a href=\"https:\/\/aws.amazon.com\/blogs\/architecture\/using-route-53-private-hosted-zones-for-cross-account-multi-region-architectures\/\" target=\"_blank\" rel=\"noreferrer noopener\">Using Route 53 Private Hosted Zones for Cross-account Multi-region Architectures<\/a>, <a href=\"https:\/\/aws.amazon.com\/blogs\/security\/simplify-dns-management-in-a-multiaccount-environment-with-route-53-resolver\/\" target=\"_blank\" rel=\"noreferrer noopener\">Simplify DNS management in a multi-account environment<\/a>)<\/li><li>Domain Registration <strong>(AWS Documentation:<\/strong> <a href=\"https:\/\/docs.aws.amazon.com\/Route53\/latest\/DeveloperGuide\/domain-register.html\" target=\"_blank\" rel=\"noreferrer noopener\">Registering a new domain<\/a>)<\/li><\/ul>\n\n\n\n<p>Skills in:<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li>Using Route 53 public hosted zones <strong>(AWS Documentation:<\/strong> <a href=\"https:\/\/docs.aws.amazon.com\/Route53\/latest\/DeveloperGuide\/CreatingHostedZone.html\" target=\"_blank\" rel=\"noreferrer noopener\">Creating a public hosted zone<\/a>)<\/li><li>Using Route 53 private hosted zones <strong>(AWS Documentation:<\/strong> <a href=\"https:\/\/docs.aws.amazon.com\/Route53\/latest\/DeveloperGuide\/hosted-zones-private.html\" target=\"_blank\" rel=\"noreferrer noopener\">Working with private hosted zones<\/a>)<\/li><li>Using Route 53 Resolver endpoints in hybrid and AWS architectures <strong>(AWS Documentation:<\/strong> <a href=\"https:\/\/docs.aws.amazon.com\/prescriptive-guidance\/latest\/patterns\/set-up-integrated-dns-resolution-for-hybrid-networks-in-amazon-route-53.html\" target=\"_blank\" rel=\"noreferrer noopener\">Set up integrated DNS resolution for hybrid networks in Amazon Route 53<\/a>)<\/li><li>Using Route 53 for global traffic management <strong>(AWS Documentation:<\/strong> <a href=\"https:\/\/docs.aws.amazon.com\/Route53\/latest\/DeveloperGuide\/Welcome.html\" target=\"_blank\" rel=\"noreferrer noopener\">Amazon Route&nbsp;53<\/a>)<\/li><li>Creating and managing domain registrations <strong>(AWS Documentation:<\/strong> <a href=\"https:\/\/docs.aws.amazon.com\/Route53\/latest\/DeveloperGuide\/domain-register.html\" target=\"_blank\" rel=\"noreferrer noopener\">Registering a new domain<\/a>)<\/li><\/ul>\n\n\n\n<p><strong>Task Statement 1.3: Design solutions that integrate load balancing to meet high availability, scalability,<br>and security requirements.<\/strong><\/p>\n\n\n\n<p>Knowledge of:<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li>How load balancing works at layer 3, layer 4, and layer 7 of the OSI model <strong>(AWS Documentation:<\/strong> <a href=\"https:\/\/docs.aws.amazon.com\/AmazonECS\/latest\/developerguide\/load-balancer-types.html\" target=\"_blank\" rel=\"noreferrer noopener\">Load balancer types<\/a>, <a href=\"https:\/\/aws.amazon.com\/elasticloadbalancing\/features\/\" target=\"_blank\" rel=\"noreferrer noopener\">Elastic Load Balancing features<\/a>)<\/li><li>Different types of load balancers and how they meet requirements for network design, high availability, and security <strong>(AWS Documentation:<\/strong> <a href=\"https:\/\/docs.aws.amazon.com\/AmazonECS\/latest\/developerguide\/load-balancer-types.html\" target=\"_blank\" rel=\"noreferrer noopener\">Load balancer types<\/a>)<\/li><li>Connectivity patterns that apply to load balancing based on the use case (for example, internal load balancers, external load balancers) <strong>(AWS Documentation:<\/strong> <a href=\"https:\/\/docs.aws.amazon.com\/elasticloadbalancing\/latest\/application\/application-load-balancers.html\" target=\"_blank\" rel=\"noreferrer noopener\">Application Load Balancers<\/a>, <a href=\"https:\/\/aws.amazon.com\/elasticloadbalancing\/features\/\" target=\"_blank\" rel=\"noreferrer noopener\">Elastic Load Balancing features<\/a>)<\/li><li>Scaling factors for load balancers<\/li><li>Integrations of load balancers and other AWS services (for example, Global Accelerator, CloudFront, AWS WAF, Route 53, Amazon Elastic Kubernetes Service [Amazon EKS], AWS Certificate Manager [ACM]) <strong>(AWS Documentation:<\/strong> <a href=\"https:\/\/docs.aws.amazon.com\/config\/latest\/developerguide\/resource-config-reference.html\" target=\"_blank\" rel=\"noreferrer noopener\">Supported Resource Types<\/a>, <a href=\"https:\/\/docs.aws.amazon.com\/AWSCloudFormation\/latest\/UserGuide\/aws-resource-eks-cluster.html\" target=\"_blank\" rel=\"noreferrer noopener\">AWS::EKS::Cluster<\/a>, <a href=\"https:\/\/docs.aws.amazon.com\/pt_br\/AWSCloudFormation\/latest\/UserGuide\/aws-resource-globalaccelerator-accelerator.html\" target=\"_blank\" rel=\"noreferrer noopener\">AWS::GlobalAccelerator::Accelerator<\/a>)<\/li><li>Configuration options for load balancers (for example, proxy protocol, cross-zone load balancing, session affinity [sticky sessions], routing algorithms) <strong>(AWS Documentation:<\/strong> <a href=\"https:\/\/docs.aws.amazon.com\/elasticloadbalancing\/latest\/network\/load-balancer-target-groups.html\" target=\"_blank\" rel=\"noreferrer noopener\">Target groups for your Network Load Balancers<\/a>, <a href=\"https:\/\/docs.aws.amazon.com\/elasticloadbalancing\/latest\/classic\/elb-sticky-sessions.html\" target=\"_blank\" rel=\"noreferrer noopener\">Configure sticky sessions for your Classic Load Balancer<\/a>, <a href=\"https:\/\/docs.aws.amazon.com\/elasticloadbalancing\/latest\/application\/sticky-sessions.html\" target=\"_blank\" rel=\"noreferrer noopener\">Sticky sessions for your Application Load Balancer<\/a>)<\/li><li>Configuration options for load balancer target groups (for example, TCP, GENEVE, IP compared with instance) <strong>(AWS Documentation:<\/strong> <a href=\"https:\/\/docs.aws.amazon.com\/elasticloadbalancing\/latest\/APIReference\/API_CreateTargetGroup.html\" target=\"_blank\" rel=\"noreferrer noopener\">CreateTargetGroup<\/a>, <a href=\"https:\/\/docs.aws.amazon.com\/elasticloadbalancing\/latest\/network\/load-balancer-target-groups.html\" target=\"_blank\" rel=\"noreferrer noopener\">Target groups for your Network Load Balancers<\/a>)<\/li><li>AWS Load Balancer Controller for Kubernetes clusters <strong>(AWS Documentation:<\/strong> <a href=\"https:\/\/docs.aws.amazon.com\/eks\/latest\/userguide\/aws-load-balancer-controller.html\" target=\"_blank\" rel=\"noreferrer noopener\">Installing the AWS Load Balancer Controller add-on<\/a>, <a href=\"https:\/\/docs.aws.amazon.com\/eks\/latest\/userguide\/alb-ingress.html\" target=\"_blank\" rel=\"noreferrer noopener\">Application load balancing on Amazon EKS<\/a>)<\/li><li>Considerations for encryption and authentication with load balancers (for example, TLS termination, TLS passthrough) <strong>(AWS Documentation:<\/strong> <a href=\"https:\/\/docs.aws.amazon.com\/elasticloadbalancing\/latest\/network\/create-tls-listener.html\" target=\"_blank\" rel=\"noreferrer noopener\">TLS listeners for your Network Load Balancer<\/a>,<a href=\"https:\/\/docs.aws.amazon.com\/elasticloadbalancing\/latest\/application\/create-https-listener.html\" target=\"_blank\" rel=\"noreferrer noopener\"> Create an HTTPS listener for your Application Load Balancer<\/a>)<\/li><\/ul>\n\n\n\n<p>Skills in:<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li>Selecting an appropriate load balancer based on the use case <strong>(AWS Documentation:<\/strong> <a href=\"https:\/\/docs.aws.amazon.com\/elasticloadbalancing\/latest\/application\/application-load-balancers.html\" target=\"_blank\" rel=\"noreferrer noopener\">Application Load Balancers<\/a>)<\/li><li>Integrating auto-scaling with load balancing solutions <strong>(AWS Documentation:<\/strong> <a href=\"https:\/\/docs.aws.amazon.com\/autoscaling\/ec2\/userguide\/attach-load-balancer-asg.html\" target=\"_blank\" rel=\"noreferrer noopener\">Attach a load balancer to your Auto Scaling group<\/a>)<\/li><li>Integrating load balancers with existing application deployments <strong>(AWS Documentation:<\/strong> <a href=\"https:\/\/docs.aws.amazon.com\/codedeploy\/latest\/userguide\/integrations-aws-elastic-load-balancing.html\" target=\"_blank\" rel=\"noreferrer noopener\">Integrating CodeDeploy with Elastic Load Balancing<\/a>)<\/li><\/ul>\n\n\n\n<p><strong>Task Statement 1.4: Define logging and monitoring requirements across AWS and hybrid networks.<br>Knowledge of:<\/strong><\/p>\n\n\n\n<ul class=\"wp-block-list\"><li>Amazon CloudWatch metrics, agents, logs, alarms, dashboards, and insights in AWS architectures to provide visibility <strong>(AWS Documentation:<\/strong> <a href=\"https:\/\/docs.aws.amazon.com\/AmazonCloudWatch\/latest\/monitoring\/WhatIsCloudWatch.html\" target=\"_blank\" rel=\"noreferrer noopener\">Amazon CloudWatch<\/a>, <a href=\"https:\/\/docs.aws.amazon.com\/AmazonCloudWatch\/latest\/monitoring\/cloudwatch_architecture.html\" target=\"_blank\" rel=\"noreferrer noopener\">How Amazon CloudWatch works<\/a>)<\/li><li>AWS Transit Gateway Network Manager in architectures to provide visibility <strong>(AWS Documentation:<\/strong> <a href=\"https:\/\/docs.aws.amazon.com\/vpc\/latest\/tgwnm\/network-manager-getting-started.html\" target=\"_blank\" rel=\"noreferrer noopener\">AWS Network Manager for Transit Gateway networks<\/a>)<\/li><li>VPC Reachability Analyzer in architectures to provide visibility <strong>(AWS Documentation:<\/strong> <a href=\"https:\/\/docs.aws.amazon.com\/vpc\/latest\/reachability\/what-is-reachability-analyzer.html\" target=\"_blank\" rel=\"noreferrer noopener\">VPC Reachability Analyzer<\/a>)<\/li><li>Flow logs and traffic mirroring in architecture to provide visibility <strong>(AWS Documentation:<\/strong> <a href=\"https:\/\/docs.aws.amazon.com\/vpc\/latest\/mirroring\/what-is-traffic-mirroring.html\" target=\"_blank\" rel=\"noreferrer noopener\">Traffic Mirroring<\/a>, <a href=\"https:\/\/aws.amazon.com\/blogs\/networking-and-content-delivery\/using-vpc-traffic-mirroring-to-monitor-and-secure-your-aws-infrastructure\/\" target=\"_blank\" rel=\"noreferrer noopener\">Using VPC Traffic Mirroring to monitor and secure your AWS infrastructure<\/a>)<\/li><li>Access logging (for example, load balancers, CloudFront) <strong>(AWS Documentation:<\/strong> <a href=\"https:\/\/docs.aws.amazon.com\/elasticloadbalancing\/latest\/application\/load-balancer-access-logs.html\" target=\"_blank\" rel=\"noreferrer noopener\">Access logs for your Application Load Balancer<\/a>)<\/li><\/ul>\n\n\n\n<p>Skills in:<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li>Identifying the logging and monitoring requirements <strong>(AWS Documentation:<\/strong> <a href=\"https:\/\/docs.aws.amazon.com\/prescriptive-guidance\/latest\/implementing-logging-monitoring-cloudwatch\/welcome.html\" target=\"_blank\" rel=\"noreferrer noopener\">Designing and implementing logging and monitoring with Amazon CloudWatch<\/a>)<\/li><li>Recommending appropriate metrics to provide visibility of the network status <strong>(AWS Documentation:<\/strong> <a href=\"https:\/\/docs.aws.amazon.com\/AWSEC2\/latest\/UserGuide\/viewing_metrics_with_cloudwatch.html\" target=\"_blank\" rel=\"noreferrer noopener\">List the available CloudWatch metrics for your instances<\/a>)<\/li><li>Capturing baseline network performance <strong>(AWS Documentation:<\/strong> <a href=\"https:\/\/docs.aws.amazon.com\/AWSEC2\/latest\/WindowsGuide\/ec2-instance-network-bandwidth.html\" target=\"_blank\" rel=\"noreferrer noopener\">Amazon EC2 instance network bandwidth<\/a>)<\/li><\/ul>\n\n\n\n<p><strong>Task Statement 1.5: Design a routing strategy and connectivity architecture between on-premises<br>networks and the AWS Cloud.<\/strong><\/p>\n\n\n\n<p>Knowledge of:<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li>Routing fundamentals (for example, dynamic compared with static, BGP) <strong>(AWS Documentation:<\/strong> <a href=\"https:\/\/docs.aws.amazon.com\/vpn\/latest\/s2svpn\/VPNRoutingTypes.html\" target=\"_blank\" rel=\"noreferrer noopener\">Site-to-Site VPN routing options<\/a>, <a href=\"https:\/\/docs.aws.amazon.com\/vpn\/latest\/s2svpn\/cgw-dynamic-routing-examples.html\" target=\"_blank\" rel=\"noreferrer noopener\">customer gateway device configurations for dynamic routing (BGP)<\/a>)<\/li><li>Layer 1 and layer 2 concepts for physical interconnects (for example, VLAN, link aggregation group [LAG], optics, jumbo frames) <strong>(AWS Documentation:<\/strong> <a href=\"https:\/\/docs.aws.amazon.com\/directconnect\/latest\/UserGuide\/lags.html\" target=\"_blank\" rel=\"noreferrer noopener\">Link aggregation groups<\/a>)<\/li><li>Encapsulation and encryption technologies (for example, Generic Routing Encapsulation [GRE], IPsec) <strong>(AWS Documentation:<\/strong> <a href=\"https:\/\/aws.amazon.com\/blogs\/networking-and-content-delivery\/simplify-sd-wan-connectivity-with-aws-transit-gateway-connect\/\" target=\"_blank\" rel=\"noreferrer noopener\">Simplify SD-WAN connectivity with AWS Transit Gateway Connect<\/a>, <a href=\"https:\/\/docs.aws.amazon.com\/vpn\/latest\/s2svpn\/your-cgw.html\" target=\"_blank\" rel=\"noreferrer noopener\">Your customer gateway device<\/a>)<\/li><li>Resource sharing across AWS accounts <strong>(AWS Documentation:<\/strong> <a href=\"https:\/\/docs.aws.amazon.com\/ram\/latest\/userguide\/getting-started-sharing.html\" target=\"_blank\" rel=\"noreferrer noopener\">Sharing your AWS resources<\/a>)<\/li><li>Overlay networks <strong>(AWS Documentation:<\/strong> <a href=\"https:\/\/docs.aws.amazon.com\/sap\/latest\/sap-hana\/sap-oip-overlay-ip-routing-using-aws-transit-gateway.html\" target=\"_blank\" rel=\"noreferrer noopener\">Overlay IP Routing using AWS Transit Gateway<\/a>)<\/li><\/ul>\n\n\n\n<p>Skills in:<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li>Identifying the requirements for hybrid connectivity <strong>(AWS Documentation:<\/strong> <a href=\"https:\/\/docs.aws.amazon.com\/whitepapers\/latest\/hybrid-connectivity\/connectivity-models.html\" target=\"_blank\" rel=\"noreferrer noopener\">Connectivity models<\/a>)<\/li><li>Designing a redundant hybrid connectivity model with AWS services (for example, AWS Direct Connect, AWS Site-to-Site VPN) <strong>(AWS Documentation:<\/strong> <a href=\"https:\/\/docs.aws.amazon.com\/whitepapers\/latest\/building-scalable-secure-multi-vpc-network-infrastructure\/hybrid-connectivity.html\" target=\"_blank\" rel=\"noreferrer noopener\">Hybrid connectivity<\/a>, <a href=\"https:\/\/docs.aws.amazon.com\/whitepapers\/latest\/hybrid-connectivity\/vpn-connection-as-a-backup-to-aws-dx-connection-example.html\" target=\"_blank\" rel=\"noreferrer noopener\">VPN connection as a backup<\/a>)<\/li><li>Designing BGP routing with BGP attributes to influence the traffic flows based on the desired traffic patterns (load sharing, active\/passive) <strong>(AWS Documentation:<\/strong> <a href=\"https:\/\/docs.aws.amazon.com\/directconnect\/latest\/UserGuide\/routing-and-bgp.html\" target=\"_blank\" rel=\"noreferrer noopener\">Routing policies and BGP communities<\/a>, <a href=\"https:\/\/aws.amazon.com\/blogs\/networking-and-content-delivery\/creating-active-passive-bgp-connections-over-aws-direct-connect\/\" target=\"_blank\" rel=\"noreferrer noopener\">Creating active\/passive BGP connections over AWS Direct Connect<\/a>)<\/li><li>Designing for integration of a software-defined wide area network (SD-WAN) with AWS (for example, Transit Gateway Connect, overlay networks) <strong>(AWS Documentation:<\/strong> <a href=\"https:\/\/aws.amazon.com\/blogs\/networking-and-content-delivery\/simplify-sd-wan-connectivity-with-aws-transit-gateway-connect\/\" target=\"_blank\" rel=\"noreferrer noopener\">Simplify SD-WAN connectivity with AWS Transit Gateway Connect<\/a>)<\/li><\/ul>\n\n\n\n<p><strong>Task Statement 1.6: Design a routing strategy and connectivity architecture that includes multiple AWS<br>accounts, AWS Regions, and VPCs to support different connectivity patterns.<\/strong><\/p>\n\n\n\n<p>Knowledge of:<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li>Different connectivity patterns and use cases (for example, VPC peering, Transit Gateway, AWS PrivateLink) <strong>(AWS Documentation:<\/strong> <a href=\"https:\/\/docs.aws.amazon.com\/whitepapers\/latest\/building-scalable-secure-multi-vpc-network-infrastructure\/aws-privatelink.html\" target=\"_blank\" rel=\"noreferrer noopener\">AWS PrivateLink<\/a>, <a href=\"https:\/\/docs.aws.amazon.com\/vpc\/latest\/userguide\/vpc-peering.html\" target=\"_blank\" rel=\"noreferrer noopener\">Connect VPCs using VPC peering<\/a>)<\/li><li>Capabilities and advantages of VPC sharing <strong>(AWS Documentation:<\/strong> <a href=\"https:\/\/docs.aws.amazon.com\/vpc\/latest\/userguide\/vpc-sharing.html\" target=\"_blank\" rel=\"noreferrer noopener\">Share your VPC with other accounts<\/a>, <a href=\"https:\/\/docs.aws.amazon.com\/whitepapers\/latest\/building-scalable-secure-multi-vpc-network-infrastructure\/amazon-vpc-sharing.html\" target=\"_blank\" rel=\"noreferrer noopener\">VPC sharing<\/a>)<\/li><li>IP subnets and solutions accounting for IP address overlaps<\/li><\/ul>\n\n\n\n<p>Skills in:<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li>Connecting multiple VPCs by using the most appropriate services based on requirements (for example, using VPC peering, Transit Gateway, PrivateLink) <strong>(AWS Documentation:<\/strong> <a href=\"https:\/\/docs.aws.amazon.com\/whitepapers\/latest\/building-scalable-secure-multi-vpc-network-infrastructure\/vpc-to-vpc-connectivity.html\" target=\"_blank\" rel=\"noreferrer noopener\">VPC to VPC connectivity<\/a>, <a href=\"https:\/\/docs.aws.amazon.com\/vpc\/latest\/userguide\/vpc-peering.html\" target=\"_blank\" rel=\"noreferrer noopener\">Connect VPCs using VPC peering<\/a>)<\/li><li>Using VPC sharing in a multi-account setup <strong>(AWS Documentation:<\/strong> <a href=\"https:\/\/docs.aws.amazon.com\/vpc\/latest\/userguide\/vpc-sharing.html\" target=\"_blank\" rel=\"noreferrer noopener\">Share your VPC with other accounts<\/a>)<\/li><li>Managing IP overlaps by using different available services and options (for example, NAT, PrivateLink, Transit Gateway routing) <strong>(AWS Documentation:<\/strong> <a href=\"https:\/\/docs.aws.amazon.com\/whitepapers\/latest\/building-scalable-secure-multi-vpc-network-infrastructure\/aws-privatelink.html\" target=\"_blank\" rel=\"noreferrer noopener\">AWS PrivateLink<\/a>)<\/li><\/ul>\n\n\n\n<h5 class=\"wp-block-heading\"><strong>Domain 2: Network Implementation (26%)<\/strong><\/h5>\n\n\n\n<p><strong>Task Statement 2.1: Implement routing and connectivity between on-premises networks and the AWS Cloud.<\/strong><\/p>\n\n\n\n<p>Knowledge of:<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li>Routing protocols (for example, static, dynamic) <strong>(AWS Documentation:<\/strong> <a href=\"https:\/\/docs.aws.amazon.com\/vpn\/latest\/s2svpn\/VPNRoutingTypes.html\" target=\"_blank\" rel=\"noreferrer noopener\">Site-to-Site VPN routing options<\/a>)<\/li><li>VPNs (for example, security, accelerated VPN) <strong>(AWS Documentation:<\/strong> <a href=\"https:\/\/docs.aws.amazon.com\/vpn\/latest\/s2svpn\/accelerated-vpn.html\" target=\"_blank\" rel=\"noreferrer noopener\">Accelerated Site-to-Site VPN connections<\/a>)<\/li><li>Layer 1 and types of hardware to use (for example, Letter of Authorization [LOA] documents, colocation facilities, Direct Connect) <strong>(AWS Documentation:<\/strong> <a href=\"https:\/\/docs.aws.amazon.com\/directconnect\/latest\/UserGuide\/getting_started.html\" target=\"_blank\" rel=\"noreferrer noopener\">Classic<\/a>, <a href=\"https:\/\/docs.aws.amazon.com\/directconnect\/latest\/UserGuide\/Colocation.html\" target=\"_blank\" rel=\"noreferrer noopener\">Requesting cross connects at AWS Direct Connect locations<\/a>)<\/li><li>Layer 2 and layer 3 (for example, VLANs, IP addressing, gateways, routing, switching) <strong>(AWS Documentation:<\/strong> <a href=\"https:\/\/aws.amazon.com\/blogs\/apn\/amazon-vpc-for-on-premises-network-engineers-part-one\/\" target=\"_blank\" rel=\"noreferrer noopener\">Amazon VPC for On-Premises Network Engineers<\/a>, <a href=\"https:\/\/docs.aws.amazon.com\/vpc\/latest\/userguide\/route-table-options.html\" target=\"_blank\" rel=\"noreferrer noopener\">Example routing options<\/a>)<\/li><li>Traffic management and SD-WAN (for example, Transit Gateway Connect) <strong>(AWS Documentation:<\/strong> <a href=\"https:\/\/aws.amazon.com\/blogs\/networking-and-content-delivery\/simplify-sd-wan-connectivity-with-aws-transit-gateway-connect\/\" target=\"_blank\" rel=\"noreferrer noopener\">Simplify SD-WAN connectivity with AWS Transit Gateway Connect<\/a>)<\/li><li>DNS (for example, conditional forwarding, hosted zones, resolvers) <strong>(AWS Documentation:<\/strong> <a href=\"https:\/\/docs.aws.amazon.com\/Route53\/latest\/DeveloperGuide\/resolver.html\" target=\"_blank\" rel=\"noreferrer noopener\">Resolving DNS queries between VPCs and your network<\/a>, <a href=\"https:\/\/docs.aws.amazon.com\/Route53\/latest\/DeveloperGuide\/resolver-rules-managing.html\" target=\"_blank\" rel=\"noreferrer noopener\">Managing forwarding rules<\/a>)<\/li><li>Security appliances (for example, firewalls) <strong>(AWS Documentation:<\/strong> <a href=\"https:\/\/docs.aws.amazon.com\/network-firewall\/latest\/developerguide\/what-is-aws-network-firewall.html\" target=\"_blank\" rel=\"noreferrer noopener\">AWS Network Firewall<\/a>)<\/li><li>Load balancing (for example, layer 4 compared with layer 7, reverse proxies, layer 3) <strong>(AWS Documentation:<\/strong> <a href=\"https:\/\/aws.amazon.com\/elasticloadbalancing\/features\/\" target=\"_blank\" rel=\"noreferrer noopener\">Elastic Load Balancing features<\/a>)<\/li><li>Infrastructure automation <strong>(AWS Documentation:<\/strong> <a href=\"https:\/\/docs.aws.amazon.com\/whitepapers\/latest\/running-containerized-microservices\/infrastructure-automation.html\" target=\"_blank\" rel=\"noreferrer noopener\">Infrastructure Automation<\/a>)<\/li><li>AWS Organizations and AWS Resource Access Manager (AWS RAM) (for example, multiaccount Transit Gateway, Direct Connect, Amazon VPC, Route 53) <strong>(AWS Documentation:<\/strong> <a href=\"https:\/\/docs.aws.amazon.com\/ram\/latest\/userguide\/shareable.html\" target=\"_blank\" rel=\"noreferrer noopener\">Shareable AWS resources<\/a>)<\/li><li>Test connectivity (for example, Route Analyzer, Reachability Analyzer) <strong>(AWS Documentation:<\/strong> <a href=\"https:\/\/docs.aws.amazon.com\/vpc\/latest\/reachability\/what-is-reachability-analyzer.html\" target=\"_blank\" rel=\"noreferrer noopener\">VPC Reachability Analyzer<\/a>)<\/li><li>Networking services of VPCs <strong>(AWS Documentation:<\/strong> <a href=\"https:\/\/docs.aws.amazon.com\/vpc\/latest\/userguide\/what-is-amazon-vpc.html\" target=\"_blank\" rel=\"noreferrer noopener\">Amazon VPC<\/a>)<\/li><\/ul>\n\n\n\n<p>Skills in:<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li>Configuring the physical network requirements for hybrid connectivity solutions <strong>(AWS Documentation:<\/strong> <a href=\"https:\/\/docs.aws.amazon.com\/whitepapers\/latest\/hybrid-connectivity\/hybrid-network-connection.html\" target=\"_blank\" rel=\"noreferrer noopener\">Hybrid network connection<\/a>)<\/li><li>Configuring static or dynamic routing protocols to work with hybrid connectivity solutions <strong>(AWS Documentation:<\/strong> <a href=\"https:\/\/aws.amazon.com\/blogs\/networking-and-content-delivery\/simplify-sd-wan-connectivity-with-aws-transit-gateway-connect\/\" target=\"_blank\" rel=\"noreferrer noopener\">Simplify SD-WAN connectivity with AWS Transit Gateway Connect<\/a>)<\/li><li>Configuring existing on-premises networks to connect with the AWS Cloud <strong>(AWS Documentation:<\/strong> <a href=\"https:\/\/docs.aws.amazon.com\/vpn\/latest\/clientvpn-admin\/scenario-onprem.html\" target=\"_blank\" rel=\"noreferrer noopener\">Access to an on-premises network<\/a>)<\/li><li>Configuring existing on-premises name resolution with the AWS Cloud <strong>(AWS Documentation:<\/strong> <a href=\"https:\/\/docs.aws.amazon.com\/prescriptive-guidance\/latest\/patterns\/set-up-integrated-dns-resolution-for-hybrid-networks-in-amazon-route-53.html\" target=\"_blank\" rel=\"noreferrer noopener\">Set up integrated DNS resolution for hybrid networks in Amazon Route 53<\/a>)<\/li><li>Configuring and implementing load balancing solutions <strong>(AWS Documentation:<\/strong> <a href=\"https:\/\/docs.aws.amazon.com\/elasticloadbalancing\/latest\/application\/create-application-load-balancer.html\" target=\"_blank\" rel=\"noreferrer noopener\">Create an Application Load Balancer<\/a>)<\/li><li>Configuring network monitoring and logging for AWS services <strong>(AWS Documentation:<\/strong> <a href=\"https:\/\/docs.aws.amazon.com\/network-firewall\/latest\/developerguide\/logging-monitoring.html\" target=\"_blank\" rel=\"noreferrer noopener\">Logging and monitoring in AWS Network Firewall<\/a>)<\/li><li>Testing and validating connectivity between environments <strong>(AWS Documentation:<\/strong> <a href=\"https:\/\/docs.aws.amazon.com\/prescriptive-guidance\/latest\/migration-replatforming-cots-applications\/testing-validating-application.html\" target=\"_blank\" rel=\"noreferrer noopener\">Testing and validating your applications<\/a>)<\/li><\/ul>\n\n\n\n<p><strong>Task Statement 2.2: Implement routing and connectivity across multiple AWS accounts, Regions, and VPCs to support different connectivity patterns.<\/strong><\/p>\n\n\n\n<p>Knowledge of:<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li>Inter-VPC and multi-account connectivity (for example, VPC peering, Transit Gateway, VPN, third-party vendors, SD-WAN, multiprotocol label switching [MPLS]) <strong>(AWS Documentation:<\/strong> <a href=\"https:\/\/docs.aws.amazon.com\/whitepapers\/latest\/aws-vpc-connectivity-options\/amazon-vpc-to-amazon-vpc-connectivity-options.html\" target=\"_blank\" rel=\"noreferrer noopener\">Amazon VPC-to-Amazon VPC connectivity options<\/a>, <a href=\"https:\/\/aws.amazon.com\/blogs\/networking-and-content-delivery\/simplify-sd-wan-connectivity-with-aws-transit-gateway-connect\/\" target=\"_blank\" rel=\"noreferrer noopener\">Simplify SD-WAN connectivity with AWS Transit Gateway Connect<\/a>)<\/li><li>Private application connectivity (for example, PrivateLink) <strong>(AWS Documentation:<\/strong> <a href=\"https:\/\/docs.aws.amazon.com\/vpc\/latest\/userguide\/endpoint-services-overview.html\" target=\"_blank\" rel=\"noreferrer noopener\">Connect your VPC to services using AWS PrivateLink<\/a>)<\/li><li>Methods of expanding AWS networking connectivity (for example, Organizations, AWS RAM) <strong>(AWS Documentation:<\/strong> <a href=\"https:\/\/docs.aws.amazon.com\/organizations\/latest\/userguide\/services-that-can-integrate-ram.html\" target=\"_blank\" rel=\"noreferrer noopener\">AWS Resource Access Manager and AWS Organizations<\/a>)<\/li><li>Host and service name resolution for applications and clients (for example, DNS) <strong>(AWS Documentation:<\/strong> <a href=\"https:\/\/docs.aws.amazon.com\/Route53\/latest\/DeveloperGuide\/resolver.html\" target=\"_blank\" rel=\"noreferrer noopener\">Resolving DNS queries between VPCs and your network<\/a>)<\/li><li>Infrastructure automation <strong>(AWS Documentation:<\/strong> <a href=\"https:\/\/docs.aws.amazon.com\/whitepapers\/latest\/running-containerized-microservices\/infrastructure-automation.html\" target=\"_blank\" rel=\"noreferrer noopener\">Infrastructure Automation<\/a>)<\/li><li>Authentication and authorization (for example, SAML, Active Directory) <strong>(AWS Documentation:<\/strong> <a href=\"https:\/\/docs.aws.amazon.com\/IAM\/latest\/UserGuide\/id_roles_providers_saml.html\" target=\"_blank\" rel=\"noreferrer noopener\">About SAML 2.0-based federation<\/a>, <a href=\"https:\/\/docs.aws.amazon.com\/IAM\/latest\/UserGuide\/id_roles_providers_saml_3rd-party.html\" target=\"_blank\" rel=\"noreferrer noopener\">Integrating third-party SAML solution providers with AWS<\/a>)<\/li><li>Security (for example, security groups, network ACLs, AWS Network Firewall) <strong>(AWS Documentation:<\/strong> <a href=\"https:\/\/docs.aws.amazon.com\/vpc\/latest\/userguide\/vpc-network-acls.html\" target=\"_blank\" rel=\"noreferrer noopener\">Control traffic to subnets using Network ACLs<\/a>, <a href=\"https:\/\/docs.aws.amazon.com\/vpc\/latest\/userguide\/VPC_SecurityGroups.html\" target=\"_blank\" rel=\"noreferrer noopener\">Control traffic to resources using security groups<\/a>)<\/li><li>Test connectivity (for example, Route Analyzer, Reachability Analyzer, tooling) <strong>(AWS Documentation:<\/strong> <a href=\"https:\/\/docs.aws.amazon.com\/vpc\/latest\/reachability\/what-is-reachability-analyzer.html\" target=\"_blank\" rel=\"noreferrer noopener\">VPC Reachability Analyzer<\/a>)<\/li><\/ul>\n\n\n\n<p>Skills in:<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li>Configuring network connectivity architectures by using AWS services in a single-VPC or multiVPC design (for example, DHCP, routing, security groups) <strong>(AWS Documentation:<\/strong> <a href=\"https:\/\/docs.aws.amazon.com\/quickstart\/latest\/vpc\/architecture.html\" target=\"_blank\" rel=\"noreferrer noopener\">Architecture<\/a>, <a href=\"https:\/\/docs.aws.amazon.com\/vpc\/latest\/userguide\/VPC_SecurityGroups.html\" target=\"_blank\" rel=\"noreferrer noopener\">Control traffic to resources using security groups<\/a>)<\/li><li>Configuring hybrid connectivity with existing third-party vendor solutions <strong>(AWS Documentation:<\/strong> <a href=\"https:\/\/docs.aws.amazon.com\/securityhub\/latest\/userguide\/securityhub-partner-providers.html\" target=\"_blank\" rel=\"noreferrer noopener\">Available third-party partner product integrations<\/a>, <a href=\"https:\/\/docs.aws.amazon.com\/whitepapers\/latest\/building-scalable-secure-multi-vpc-network-infrastructure\/hybrid-connectivity.html\" target=\"_blank\" rel=\"noreferrer noopener\">Hybrid connectivity<\/a>)<\/li><li>Configuring a hub-and-spoke network architecture (for example, Transit Gateway, transit VPC) <strong>(AWS Documentation:<\/strong> <a href=\"https:\/\/docs.aws.amazon.com\/whitepapers\/latest\/building-scalable-secure-multi-vpc-network-infrastructure\/transit-vpc-solution.html\" target=\"_blank\" rel=\"noreferrer noopener\">Transit VPC solution<\/a>)<\/li><li>Configuring a DNS solution to make hybrid connectivity possible <strong>(AWS Documentation:<\/strong> <a href=\"https:\/\/docs.aws.amazon.com\/prescriptive-guidance\/latest\/patterns\/set-up-integrated-dns-resolution-for-hybrid-networks-in-amazon-route-53.html\" target=\"_blank\" rel=\"noreferrer noopener\">Set up integrated DNS resolution for hybrid networks in Amazon Route 53<\/a>)<\/li><li>Implementing security between network boundaries <\/li><li>Configuring network monitoring and logging by using AWS solutions <strong>(AWS Documentation:<\/strong> <a href=\"https:\/\/docs.aws.amazon.com\/config\/latest\/developerguide\/security-logging-and-monitoring.html\" target=\"_blank\" rel=\"noreferrer noopener\">Logging and Monitoring in AWS Config<\/a>)<\/li><\/ul>\n\n\n\n<p><strong>Task Statement 2.3: Implement complex hybrid and multi-account DNS architectures.<\/strong><\/p>\n\n\n\n<p>Knowledge of:<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li>When to use private hosted zones and public hosted zones <strong>(AWS Documentation:<\/strong> <a href=\"https:\/\/docs.aws.amazon.com\/Route53\/latest\/DeveloperGuide\/hosted-zones-private.html\" target=\"_blank\" rel=\"noreferrer noopener\">Working with private hosted zones<\/a>)<\/li><li>Methods to alter traffic management (for example, based on latency, geography, weighting) <strong>(AWS Documentation:<\/strong> <a href=\"https:\/\/docs.aws.amazon.com\/Route53\/latest\/DeveloperGuide\/routing-policy.html\" target=\"_blank\" rel=\"noreferrer noopener\">Choosing a routing policy<\/a>, <a href=\"https:\/\/docs.aws.amazon.com\/Route53\/latest\/DeveloperGuide\/TutorialLBRMultipleEC2InRegion.html\" target=\"_blank\" rel=\"noreferrer noopener\">Using latency and weighted records in Amazon Route&nbsp;53<\/a>)<\/li><li>DNS delegation and forwarding (for example, conditional forwarding) <strong>(AWS Documentation:<\/strong> <a href=\"https:\/\/docs.aws.amazon.com\/Route53\/latest\/DeveloperGuide\/resolver-rules-managing.html\" target=\"_blank\" rel=\"noreferrer noopener\">Managing forwarding rules<\/a>)<\/li><li>Different DNS record types (for example, A, AAAA, TXT, pointer records, alias records) <strong>(AWS Documentation:<\/strong> <a href=\"https:\/\/docs.aws.amazon.com\/Route53\/latest\/DeveloperGuide\/ResourceRecordTypes.html\" target=\"_blank\" rel=\"noreferrer noopener\">Supported DNS record types<\/a>)<\/li><li>DNSSEC<\/li><li>How to share DNS services between accounts (for example, AWS RAM) <strong>(AWS Documentation:<\/strong> <a href=\"https:\/\/docs.aws.amazon.com\/ram\/latest\/userguide\/shareable.html\" target=\"_blank\" rel=\"noreferrer noopener\">Shareable AWS resources<\/a>)<\/li><li>Requirements and implementation options for outbound and inbound endpoints <strong>(AWS Documentation:<\/strong> <a href=\"https:\/\/docs.aws.amazon.com\/Route53\/latest\/DeveloperGuide\/resolver-getting-started.html\" target=\"_blank\" rel=\"noreferrer noopener\">Getting started with Route 53 Resolver<\/a>)<\/li><\/ul>\n\n\n\n<p>Skills in:<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li>Configuring DNS zones and conditional forwarding <strong>(AWS Documentation:<\/strong> <a href=\"https:\/\/docs.aws.amazon.com\/managedservices\/latest\/onboardingguide\/configure-conditional-forwarder.html\" target=\"_blank\" rel=\"noreferrer noopener\">Configure the conditional forwarder<\/a>)<\/li><li>Configuring traffic management by using DNS solutions <strong>(AWS Documentation:<\/strong> <a href=\"https:\/\/docs.aws.amazon.com\/Route53\/latest\/DeveloperGuide\/traffic-flow.html\" target=\"_blank\" rel=\"noreferrer noopener\">Using traffic flow to route DNS traffic<\/a>)<\/li><li>Configuring DNS for hybrid networks <strong>(AWS Documentation:<\/strong> <a href=\"https:\/\/docs.aws.amazon.com\/prescriptive-guidance\/latest\/patterns\/set-up-integrated-dns-resolution-for-hybrid-networks-in-amazon-route-53.html\" target=\"_blank\" rel=\"noreferrer noopener\">Set up integrated DNS resolution for hybrid networks in Amazon Route 53<\/a>)<\/li><li>Configuring appropriate DNS records <strong>(AWS Documentation:<\/strong> <a href=\"https:\/\/docs.aws.amazon.com\/Route53\/latest\/DeveloperGuide\/ResourceRecordTypes.html\" target=\"_blank\" rel=\"noreferrer noopener\">Supported DNS record types<\/a>)<\/li><li>Configuring DNSSEC on Route 53 <strong>(AWS Documentation:<\/strong> <a href=\"https:\/\/docs.aws.amazon.com\/Route53\/latest\/DeveloperGuide\/domain-configure-dnssec.html\" target=\"_blank\" rel=\"noreferrer noopener\">Configuring DNSSEC for a domain<\/a>, <a href=\"https:\/\/docs.aws.amazon.com\/Route53\/latest\/DeveloperGuide\/dns-configuring-dnssec.html\" target=\"_blank\" rel=\"noreferrer noopener\">Configuring DNSSEC signing in Amazon Route&nbsp;53<\/a>)<\/li><li>Configuring DNS within a centralized or distributed network architecture <strong>(AWS Documentation:<\/strong> <a href=\"https:\/\/docs.aws.amazon.com\/prescriptive-guidance\/latest\/patterns\/set-up-integrated-dns-resolution-for-hybrid-networks-in-amazon-route-53.html\" target=\"_blank\" rel=\"noreferrer noopener\">Set up integrated DNS resolution for hybrid networks in Amazon Route 53<\/a>)<\/li><li>Configuring DNS monitoring and logging on Route 53 <strong>(AWS Documentation:<\/strong> <a href=\"https:\/\/docs.aws.amazon.com\/Route53\/latest\/DeveloperGuide\/logging-monitoring.html\" target=\"_blank\" rel=\"noreferrer noopener\">Logging and monitoring in Amazon Route&nbsp;53<\/a>)<\/li><\/ul>\n\n\n\n<p><strong>Task Statement 2.4: Automate and configure network infrastructure.<\/strong><\/p>\n\n\n\n<p>Knowledge of:<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li>Infrastructure as code (IaC) (for example, AWS Cloud Development Kit [AWS CDK], AWS CloudFormation, AWS CLI, AWS SDK, APIs) <strong>(AWS Documentation:<\/strong> <a href=\"https:\/\/docs.aws.amazon.com\/cdk\/v2\/guide\/home.html\" target=\"_blank\" rel=\"noreferrer noopener\">AWS CDK<\/a>)<\/li><li>Event-driven network automation <strong>(AWS Documentation:<\/strong> <a href=\"https:\/\/aws.amazon.com\/blogs\/compute\/getting-started-with-event-driven-architecture\/\" target=\"_blank\" rel=\"noreferrer noopener\">Getting Started with Event-Driven Architecture<\/a>)<\/li><li>Common problems of using hardcoded instructions in IaC templates when provisioning cloud networking resources <strong>(AWS Documentation:<\/strong> <a href=\"https:\/\/docs.aws.amazon.com\/AWSCloudFormation\/latest\/UserGuide\/best-practices.html\" target=\"_blank\" rel=\"noreferrer noopener\">AWS CloudFormation best practices<\/a>)<\/li><\/ul>\n\n\n\n<p>Skills in:<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li>Creating and managing repeatable network configurations <strong>(AWS Documentation:<\/strong> <a href=\"https:\/\/docs.aws.amazon.com\/AWSEC2\/latest\/UserGuide\/best-practices-for-configuring-network-interfaces.html\" target=\"_blank\" rel=\"noreferrer noopener\">Best practices for configuring network interfaces<\/a>)<\/li><li>Integrating event-driven networking functions <strong>(AWS Documentation:<\/strong> <a href=\"https:\/\/aws.amazon.com\/blogs\/compute\/getting-started-with-event-driven-architecture\/\" target=\"_blank\" rel=\"noreferrer noopener\">Getting Started with Event-Driven Architecture<\/a>)<\/li><li>Integrating hybrid network automation options with AWS native IaC<\/li><li>Eliminating risk and achieving efficiency in a cloud networking environment while maintaining the lowest possible cost<\/li><li>Automating the process of optimizing cloud network resources with IaC <strong>(AWS Documentation:<\/strong> <a href=\"https:\/\/docs.aws.amazon.com\/whitepapers\/latest\/cloud-automation-5g-network\/cloud-automation-areas.html\" target=\"_blank\" rel=\"noreferrer noopener\">Cloud automation areas<\/a>)<\/li><\/ul>\n\n\n\n<h5 class=\"wp-block-heading\"><strong>Domain 3: Network Management and Operations (20%)<\/strong><\/h5>\n\n\n\n<p><strong>Task Statement 3.1: Maintain routing and connectivity on AWS and hybrid networks.<\/strong><\/p>\n\n\n\n<p>Knowledge of:<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li>Industry-standard routing protocols that are used in AWS hybrid networks (for example, BGP over Direct Connect) <strong>(AWS Documentation:<\/strong> <a href=\"https:\/\/docs.aws.amazon.com\/directconnect\/latest\/UserGuide\/routing-and-bgp.html\" target=\"_blank\" rel=\"noreferrer noopener\">Routing policies and BGP communities<\/a>)<\/li><li>Connectivity methods for AWS and hybrid networks (for example, Direct Connect gateway, Transit Gateway, VIFs) <strong>(AWS Documentation:<\/strong> <a href=\"https:\/\/docs.aws.amazon.com\/whitepapers\/latest\/building-scalable-secure-multi-vpc-network-infrastructure\/direct-connect.html\" target=\"_blank\" rel=\"noreferrer noopener\">AWS Direct Connect&nbsp;<\/a>, <a href=\"https:\/\/docs.aws.amazon.com\/directconnect\/latest\/UserGuide\/direct-connect-transit-gateways.html\" target=\"_blank\" rel=\"noreferrer noopener\">Transit gateway associations<\/a>)<\/li><li>How limits and quotas affect AWS networking services (for example, bandwidth limits, route limits) <strong>(AWS Documentation:<\/strong> <a href=\"https:\/\/docs.aws.amazon.com\/vpc\/latest\/tgw\/transit-gateway-quotas.html\" target=\"_blank\" rel=\"noreferrer noopener\">Quotas for your transit gateways<\/a>, <a href=\"https:\/\/docs.aws.amazon.com\/vpc\/latest\/userguide\/amazon-vpc-limits.html\" target=\"_blank\" rel=\"noreferrer noopener\">Amazon VPC quotas<\/a>)<\/li><li>Available private and public access methods for custom services (for example, PrivateLink, VPC peering) <strong>(AWS Documentation:<\/strong> <a href=\"https:\/\/docs.aws.amazon.com\/vpc\/latest\/userguide\/vpc-peering.html\" target=\"_blank\" rel=\"noreferrer noopener\">Connect VPCs using VPC peering<\/a>, <a href=\"https:\/\/docs.aws.amazon.com\/vpc\/latest\/userguide\/endpoint-services-overview.html\" target=\"_blank\" rel=\"noreferrer noopener\">Connect your VPC to services using AWS PrivateLink<\/a>)<\/li><li>Available inter-Regional and intra-Regional communication patterns <strong>(AWS Documentation:<\/strong> <a href=\"https:\/\/docs.aws.amazon.com\/prescriptive-guidance\/latest\/patterns\/automate-the-setup-of-inter-region-peering-with-aws-transit-gateway.html\" target=\"_blank\" rel=\"noreferrer noopener\">Automate the setup of inter-Region peering with AWS Transit Gateway<\/a>)<\/li><\/ul>\n\n\n\n<p>Skills in:<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li>Managing routing protocols for AWS and hybrid connectivity options (for example, over a Direct Connect connection, VPN) <strong>(AWS Documentation:<\/strong> <a href=\"https:\/\/docs.aws.amazon.com\/vpc\/latest\/userguide\/vpn-connections.html\" target=\"_blank\" rel=\"noreferrer noopener\">Connect your VPC to remote networks using AWS Virtual Private Network<\/a>)<\/li><li>Maintaining private access to custom services (for example, PrivateLink, VPC peering) <strong>(AWS Documentation:<\/strong> <a href=\"https:\/\/docs.aws.amazon.com\/vpc\/latest\/userguide\/vpc-peering.html\" target=\"_blank\" rel=\"noreferrer noopener\">Connect VPCs using VPC peering<\/a>, <a href=\"https:\/\/docs.aws.amazon.com\/vpc\/latest\/userguide\/endpoint-services-overview.html\" target=\"_blank\" rel=\"noreferrer noopener\">Connect your VPC to services using AWS PrivateLink<\/a>)<\/li><li>Using route tables to direct traffic appropriately (for example, automatic propagation, BGP) <strong>(AWS Documentation:<\/strong> <a href=\"https:\/\/docs.aws.amazon.com\/vpc\/latest\/userguide\/VPC_Route_Tables.html\" target=\"_blank\" rel=\"noreferrer noopener\">Configure route tables<\/a>)<\/li><li>Setting up private access or public access to AWS services (for example, Direct Connect, VPN) <strong>(AWS Documentation:<\/strong> <a href=\"https:\/\/docs.aws.amazon.com\/vpc\/latest\/userguide\/vpn-connections.html\" target=\"_blank\" rel=\"noreferrer noopener\">Connect your VPC to remote networks using AWS Virtual Private Network<\/a>)<\/li><li>Optimizing routing over dynamic and static routing protocols (for example, summarizing routes, CIDR overlap)<\/li><\/ul>\n\n\n\n<p><strong>Task Statement 3.2: Monitor and analyze network traffic to troubleshoot and optimize connectivity patterns.<\/strong><\/p>\n\n\n\n<p>Knowledge of:<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li>Network performance metrics and reachability constraints (for example, routing, packet size) <strong>(AWS Documentation:<\/strong> <a href=\"https:\/\/docs.aws.amazon.com\/AWSEC2\/latest\/UserGuide\/monitoring-network-performance-ena.html\" target=\"_blank\" rel=\"noreferrer noopener\">Monitor network performance for your EC2 instance<\/a>)<\/li><li>Appropriate logs and metrics to assess network performance and reachability issues (for example, packet loss) <strong>(AWS Documentation:<\/strong> <a href=\"https:\/\/aws.amazon.com\/premiumsupport\/knowledge-center\/troubleshoot-vpn-packet-loss\/\" target=\"_blank\" rel=\"noreferrer noopener\">troubleshoot packet loss on my VPN<\/a>, <a href=\"https:\/\/aws.amazon.com\/premiumsupport\/knowledge-center\/network-issue-vpc-onprem-ig\/\" target=\"_blank\" rel=\"noreferrer noopener\">troubleshoot network performance issues<\/a>)<\/li><li>Tools to collect and analyze logs and metrics (for example, CloudWatch, VPC Flow Logs, VPC Traffic Mirroring) <strong>(AWS Documentation:<\/strong> <a href=\"https:\/\/docs.aws.amazon.com\/vpc\/latest\/userguide\/flow-logs.html\" target=\"_blank\" rel=\"noreferrer noopener\">Logging IP traffic using VPC Flow Logs<\/a>, <a href=\"https:\/\/docs.aws.amazon.com\/vpc\/latest\/mirroring\/what-is-traffic-mirroring.html\" target=\"_blank\" rel=\"noreferrer noopener\">Traffic Mirroring<\/a>)<\/li><li>Tools to analyze routing patterns and issues (for example, Reachability Analyzer, Transit Gateway Network Manager) <strong>(AWS Documentation:<\/strong> <a href=\"https:\/\/docs.aws.amazon.com\/vpc\/latest\/tgwnm\/route-analyzer.html\" target=\"_blank\" rel=\"noreferrer noopener\">Route Analyzer<\/a>)<\/li><\/ul>\n\n\n\n<p>Skills in:<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li>Analyzing tool output to assess network performance and troubleshoot connectivity (for example, VPC Flow Logs, Amazon CloudWatch Logs) <strong>(AWS Documentation:<\/strong> <a href=\"https:\/\/docs.aws.amazon.com\/vpc\/latest\/userguide\/flow-logs.html\" target=\"_blank\" rel=\"noreferrer noopener\">Logging IP traffic using VPC Flow Logs<\/a>)<\/li><li>Mapping or understanding network topology (for example, Transit Gateway Network Manager) <strong>(AWS Documentation:<\/strong> <a href=\"https:\/\/docs.aws.amazon.com\/vpc\/latest\/tgwnm\/what-is-network-manager.html\" target=\"_blank\" rel=\"noreferrer noopener\">Network Manager<\/a>, <a href=\"https:\/\/docs.aws.amazon.com\/vpc\/latest\/tgwnm\/network-manager-getting-started.html\" target=\"_blank\" rel=\"noreferrer noopener\">AWS Network Manager for Transit Gateway networks<\/a>)<\/li><li>Analyzing packets to identify issues in packet shaping (for example, VPC Traffic Mirroring) <strong>(AWS Documentation:<\/strong> <a href=\"https:\/\/aws.amazon.com\/blogs\/networking-and-content-delivery\/using-vpc-traffic-mirroring-to-monitor-and-secure-your-aws-infrastructure\/\" target=\"_blank\" rel=\"noreferrer noopener\">Using VPC Traffic Mirroring to monitor and secure your AWS infrastructure<\/a>, <a href=\"https:\/\/docs.aws.amazon.com\/vpc\/latest\/mirroring\/what-is-traffic-mirroring.html\" target=\"_blank\" rel=\"noreferrer noopener\">Traffic Mirroring<\/a>)<\/li><li>Troubleshooting connectivity issues that are caused by network misconfiguration (for example, Reachability Analyzer) <strong>(AWS Documentation:<\/strong> <a href=\"https:\/\/docs.aws.amazon.com\/vpc\/latest\/reachability\/what-is-reachability-analyzer.html\" target=\"_blank\" rel=\"noreferrer noopener\">VPC Reachability Analyzer<\/a>)<\/li><li>Verifying that a network configuration meets network design requirements (for example, Reachability Analyzer) <strong>(AWS Documentation:<\/strong> <a href=\"https:\/\/docs.aws.amazon.com\/vpc\/latest\/reachability\/getting-started.html\" target=\"_blank\" rel=\"noreferrer noopener\">Getting started with VPC Reachability Analyzer<\/a>)<\/li><li>Automating the verification of connectivity intent as a network configuration changes (for example, Reachability Analyzer)<\/li><li>Troubleshooting packet size mismatches in a VPC to restore network connectivity <strong>(AWS Documentation:<\/strong> <a href=\"https:\/\/aws.amazon.com\/premiumsupport\/knowledge-center\/network-issue-vpc-onprem-ig\/\" target=\"_blank\" rel=\"noreferrer noopener\">troubleshoot network performance issues<\/a>)<\/li><\/ul>\n\n\n\n<p><strong>Task Statement 3.3: Optimize AWS networks for performance, reliability, and cost-effectiveness.<\/strong><\/p>\n\n\n\n<p>Knowledge of:<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li>Situations in which a VPC peer or a transit gateway are appropriate <strong>(AWS Documentation:<\/strong> <a href=\"https:\/\/docs.aws.amazon.com\/vpc\/latest\/tgw\/what-is-transit-gateway.html\" target=\"_blank\" rel=\"noreferrer noopener\">transit gateway<\/a>, <a href=\"https:\/\/docs.aws.amazon.com\/vpc\/latest\/tgw\/tgw-peering.html\" target=\"_blank\" rel=\"noreferrer noopener\">Transit gateway peering attachments<\/a>)<\/li><li>Different methods to reduce bandwidth utilization (for example, unicast compared with multicast, CloudFront) <strong>(AWS Documentation:<\/strong> <a href=\"https:\/\/docs.aws.amazon.com\/AmazonCloudFront\/latest\/DeveloperGuide\/usage-charts.html\" target=\"_blank\" rel=\"noreferrer noopener\">CloudFront usage reports<\/a>, <a href=\"https:\/\/docs.aws.amazon.com\/AmazonCloudFront\/latest\/DeveloperGuide\/IntroductionUseCases.html\" target=\"_blank\" rel=\"noreferrer noopener\">CloudFront use cases<\/a>)<\/li><li>Cost-effective connectivity options for data transfer between a VPC and on-premises environments <strong>(AWS Documentation:<\/strong> <a href=\"https:\/\/docs.aws.amazon.com\/wellarchitected\/latest\/hybrid-networking-lens\/cost-optimization-pillar.html\" target=\"_blank\" rel=\"noreferrer noopener\">Cost optimization pillar<\/a>)<\/li><li>Different types of network interfaces on AWS <strong>(AWS Documentation:<\/strong> <a href=\"https:\/\/docs.aws.amazon.com\/AWSEC2\/latest\/UserGuide\/using-eni.html\" target=\"_blank\" rel=\"noreferrer noopener\">Elastic network interfaces<\/a>)<\/li><li>High-availability features in Route 53 (for example, DNS load balancing using health checks with latency and weighted record sets) <strong>(AWS Documentation:<\/strong> <a href=\"https:\/\/docs.aws.amazon.com\/Route53\/latest\/DeveloperGuide\/dns-failover.html\" target=\"_blank\" rel=\"noreferrer noopener\">Creating Amazon Route&nbsp;53 health checks and configuring DNS failover<\/a>)<\/li><li>Availability of options from Route 53 that provide reliability <strong>(AWS Documentation:<\/strong> <a href=\"https:\/\/aws.amazon.com\/route53\/faqs\/\" target=\"_blank\" rel=\"noreferrer noopener\">Amazon Route 53 FAQs<\/a>)<\/li><li>Load balancing and traffic distribution patterns <strong>(AWS Documentation:<\/strong> <a href=\"https:\/\/aws.amazon.com\/elasticloadbalancing\/features\/\" target=\"_blank\" rel=\"noreferrer noopener\">Elastic Load Balancing features<\/a>, <a href=\"https:\/\/docs.aws.amazon.com\/autoscaling\/ec2\/userguide\/autoscaling-load-balancer.html\" target=\"_blank\" rel=\"noreferrer noopener\">Use Elastic Load Balancing to distribute traffic<\/a>)<\/li><li>VPC subnet optimization <strong>(AWS Documentation:<\/strong> <a href=\"https:\/\/docs.aws.amazon.com\/vpc\/latest\/userguide\/configure-subnets.html\" target=\"_blank\" rel=\"noreferrer noopener\">Subnets for your VPC<\/a>)<\/li><li>Frame size optimization for bandwidth across different connection types <strong>(AWS Documentation:<\/strong> <a href=\"https:\/\/aws.amazon.com\/ec2\/instance-types\/\" target=\"_blank\" rel=\"noreferrer noopener\">Amazon EC2 Instance Types<\/a>)<\/li><\/ul>\n\n\n\n<p>Skills in:<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li>Optimizing for network throughput <strong>(AWS Documentation:<\/strong> <a href=\"https:\/\/docs.aws.amazon.com\/AWSEC2\/latest\/WindowsGuide\/ec2-instance-network-bandwidth.html\" target=\"_blank\" rel=\"noreferrer noopener\">Amazon EC2 instance network bandwidth<\/a>)<\/li><li>Selecting the right network interface for the best performance (for example, elastic network interface, Elastic Network Adapter [ENA], Elastic Fabric Adapter [EFA])  <strong>(AWS Documentation:<\/strong> <a href=\"https:\/\/docs.aws.amazon.com\/AWSEC2\/latest\/UserGuide\/efa.html\" target=\"_blank\" rel=\"noreferrer noopener\">Elastic Fabric Adapter<\/a>)<\/li><li>Choosing between VPC peering, proxy patterns, or a transit gateway connection based on analysis of the network requirements provided <strong>(AWS Documentation:<\/strong> <a href=\"https:\/\/docs.aws.amazon.com\/vpc\/latest\/tgw\/tgw-best-design-practices.html\" target=\"_blank\" rel=\"noreferrer noopener\">Transit gateway design best practices<\/a>, <a href=\"https:\/\/docs.aws.amazon.com\/prescriptive-guidance\/latest\/patterns\/automate-the-setup-of-inter-region-peering-with-aws-transit-gateway.html\" target=\"_blank\" rel=\"noreferrer noopener\">Automate the setup of inter-Region peering<\/a>)<\/li><li>Implementing a solution on an appropriate network connectivity service (for example, VPC peering, Transit Gateway, VPN connection) to meet network requirements  <strong>(AWS Documentation:<\/strong> <a href=\"https:\/\/docs.aws.amazon.com\/whitepapers\/latest\/building-scalable-secure-multi-vpc-network-infrastructure\/transit-vpc-solution.html\" target=\"_blank\" rel=\"noreferrer noopener\">Transit VPC solution<\/a>)<\/li><li>Implementing a multicast capability within a VPC and on-premises environments <strong>(AWS Documentation:<\/strong> <a href=\"https:\/\/docs.aws.amazon.com\/vpc\/latest\/tgw\/working-with-multicast.html\" target=\"_blank\" rel=\"noreferrer noopener\">Working with multicast<\/a>)<\/li><li>Creating Route 53 public hosted zones and private hosted zones and records to optimize application availability (for example, private zonal DNS entry to route traffic to multiple Availability Zones)<\/li><li>Updating and optimizing subnets for auto-scaling configurations to support the increased application load <strong>(AWS Documentation:<\/strong> <a href=\"https:\/\/docs.aws.amazon.com\/autoscaling\/ec2\/APIReference\/API_UpdateAutoScalingGroup.html\" target=\"_blank\" rel=\"noreferrer noopener\">UpdateAutoScalingGroup<\/a>)<\/li><li>Updating and optimizing subnets to prevent the depletion of available IP addresses within a VPC (for example, secondary CIDR) <strong>(AWS Documentation:<\/strong> <a href=\"https:\/\/docs.aws.amazon.com\/vpc\/latest\/userguide\/configure-subnets.html\" target=\"_blank\" rel=\"noreferrer noopener\">Subnets for your VPC<\/a>)<\/li><li>Configuring jumbo frame support across connection types <strong>(AWS Documentation:<\/strong> <a href=\"https:\/\/docs.aws.amazon.com\/AWSEC2\/latest\/UserGuide\/network_mtu.html\" target=\"_blank\" rel=\"noreferrer noopener\">Network maximum transmission unit (MTU) for your EC2 instance<\/a>)<\/li><li>Optimizing network connectivity by using Global Accelerator to improve network performance and application availability <strong>(AWS Documentation:<\/strong> <a href=\"https:\/\/docs.aws.amazon.com\/global-accelerator\/latest\/dg\/what-is-global-accelerator.html\" target=\"_blank\" rel=\"noreferrer noopener\">AWS Global Accelerator<\/a>)<\/li><\/ul>\n\n\n\n<h5 class=\"wp-block-heading\"><strong>Domain 4: Network Security, Compliance, and Governance (24%)<\/strong><\/h5>\n\n\n\n<p><strong>Task Statement 4.1: Implement and maintain network features to meet security and compliance needs and requirements.<\/strong><\/p>\n\n\n\n<p>Knowledge of:<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li>Different threat models based on application architecture<\/li><li>Common security threats <strong>(AWS Documentation:<\/strong> <a href=\"https:\/\/docs.aws.amazon.com\/whitepapers\/latest\/aws-overview\/security-and-compliance.html\" target=\"_blank\" rel=\"noreferrer noopener\">Security and compliance<\/a>)<\/li><li>Mechanisms to secure different application flows<\/li><li>AWS network architecture that meets security and compliance requirements<\/li><\/ul>\n\n\n\n<p>Skills in:<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li>Securing inbound traffic flows into AWS (for example, AWS WAF, AWS Shield, Network Firewall) <strong>(AWS Documentation:<\/strong> <a href=\"https:\/\/docs.aws.amazon.com\/waf\/latest\/developerguide\/what-is-aws-waf.html\" target=\"_blank\" rel=\"noreferrer noopener\">AWS WAF, AWS Shield, and AWS Firewall Manager<\/a>)<\/li><li>Securing outbound traffic flows from AWS (for example, Network Firewall, proxies, Gateway Load Balancers) <strong>(AWS Documentation:<\/strong> <a href=\"https:\/\/docs.aws.amazon.com\/network-firewall\/latest\/developerguide\/architectures.html\" target=\"_blank\" rel=\"noreferrer noopener\">AWS Network Firewall example architectures with routing<\/a>)<\/li><li>Securing inter-VPC traffic within an account or across multiple accounts (for example, security groups, network ACLs, VPC endpoint policies) <strong>(AWS Documentation:<\/strong> <a href=\"https:\/\/docs.aws.amazon.com\/vpc\/latest\/userguide\/VPC_Security.html\" target=\"_blank\" rel=\"noreferrer noopener\">Internetwork traffic privacy in Amazon VPC<\/a>)<\/li><li>Implementing an AWS network architecture to meet security and compliance requirements (for example, untrusted network, perimeter VPC, three-tier architecture) <strong>(AWS Documentation:<\/strong> <a href=\"https:\/\/docs.aws.amazon.com\/quickstart\/latest\/vpc\/architecture.html\" target=\"_blank\" rel=\"noreferrer noopener\">Architecture<\/a>)<\/li><li>Developing a threat model and identifying appropriate mitigation strategies for a given network architecture<\/li><li>Testing compliance with the initial requirements (for example, failover test, resiliency) <strong>(AWS Documentation:<\/strong> <a href=\"https:\/\/docs.aws.amazon.com\/directconnect\/latest\/UserGuide\/resiliency_failover.html\" target=\"_blank\" rel=\"noreferrer noopener\">AWS Direct Connect Failover Test<\/a>)<\/li><li>Automating security incident reporting and alerting using AWS <strong>(AWS Documentation:<\/strong> <a href=\"https:\/\/docs.aws.amazon.com\/whitepapers\/latest\/aws-security-incident-response-guide\/automating-incident-response.html\" target=\"_blank\" rel=\"noreferrer noopener\">Automating Incident Response<\/a>)<\/li><\/ul>\n\n\n\n<p><strong>Task Statement 4.2: Validate and audit security by using network monitoring and logging services.<\/strong><\/p>\n\n\n\n<p>Knowledge of:<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li>Network monitoring and logging services that are available in AWS (for example, CloudWatch, AWS CloudTrail, VPC Traffic Mirroring, VPC Flow Logs, Transit Gateway Network Manager) <strong>(AWS Documentation:<\/strong> <a href=\"https:\/\/docs.aws.amazon.com\/vpc\/latest\/userguide\/flow-logs.html\" target=\"_blank\" rel=\"noreferrer noopener\">Logging IP traffic using VPC Flow Logs<\/a>)<\/li><li>Alert mechanisms (for example, CloudWatch alarms) <strong>(AWS Documentation:<\/strong> <a href=\"https:\/\/docs.aws.amazon.com\/AmazonCloudWatch\/latest\/monitoring\/AlarmThatSendsEmail.html\" target=\"_blank\" rel=\"noreferrer noopener\">Using Amazon CloudWatch alarms<\/a>)<\/li><li>Log creation in different AWS services (for example, VPC flow logs, load balancer access logs, CloudFront access logs) <strong>(AWS Documentation:<\/strong> <a href=\"https:\/\/docs.aws.amazon.com\/AmazonCloudFront\/latest\/DeveloperGuide\/AccessLogs.html\" target=\"_blank\" rel=\"noreferrer noopener\">Configuring and using standard logs (access logs)<\/a>)<\/li><li>Log delivery mechanisms (for example, Amazon Kinesis, Route 53, CloudWatch) <strong>(AWS Documentation:<\/strong> <a href=\"https:\/\/docs.aws.amazon.com\/Route53\/latest\/DeveloperGuide\/logging-monitoring.html\" target=\"_blank\" rel=\"noreferrer noopener\">Logging and monitoring in Amazon Route&nbsp;53<\/a>, <a href=\"https:\/\/docs.aws.amazon.com\/firehose\/latest\/dev\/writing-with-cloudwatch-logs.html\" target=\"_blank\" rel=\"noreferrer noopener\">Writing to Kinesis Data Firehose Using CloudWatch Logs<\/a>)<\/li><li>Mechanisms to audit network security configurations (for example, security groups, AWS Firewall Manager, AWS Trusted Advisor) <strong>(AWS Documentation:<\/strong> <a href=\"https:\/\/docs.aws.amazon.com\/waf\/latest\/developerguide\/security-group-policies.html\" target=\"_blank\" rel=\"noreferrer noopener\">Security group policies<\/a>)<\/li><\/ul>\n\n\n\n<p>Skills in:<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li>Creating and analyzing a VPC flow log (including base and extended fields of flow logs) <strong>(AWS Documentation:<\/strong> <a href=\"https:\/\/docs.aws.amazon.com\/vpc\/latest\/userguide\/flow-logs.html\" target=\"_blank\" rel=\"noreferrer noopener\">Logging IP traffic using VPC Flow Logs<\/a>, <a href=\"https:\/\/docs.aws.amazon.com\/vpc\/latest\/userguide\/flow-logs-records-examples.html\" target=\"_blank\" rel=\"noreferrer noopener\">Flow log record examples<\/a>)<\/li><li>Creating and analyzing network traffic mirroring (for example, using VPC Traffic Mirroring) <strong>(AWS Documentation:<\/strong> <a href=\"https:\/\/aws.amazon.com\/blogs\/networking-and-content-delivery\/using-vpc-traffic-mirroring-to-monitor-and-secure-your-aws-infrastructure\/\" target=\"_blank\" rel=\"noreferrer noopener\">Using VPC Traffic Mirroring to monitor and secure your AWS infrastructure<\/a>, <a href=\"https:\/\/docs.aws.amazon.com\/vpc\/latest\/mirroring\/what-is-traffic-mirroring.html\" target=\"_blank\" rel=\"noreferrer noopener\">Traffic Mirroring<\/a>)<\/li><li>Implementing automated alarms by using CloudWatch <strong>(AWS Documentation:<\/strong> <a href=\"https:\/\/docs.aws.amazon.com\/AWSEC2\/latest\/UserGuide\/using-cloudwatch-createalarm.html\" target=\"_blank\" rel=\"noreferrer noopener\">Create a CloudWatch alarm for an instance<\/a>)<\/li><li>Implementing customized metrics by using CloudWatch <strong>(AWS Documentation:<\/strong> <a href=\"https:\/\/docs.aws.amazon.com\/AmazonCloudWatch\/latest\/monitoring\/publishingMetrics.html\" target=\"_blank\" rel=\"noreferrer noopener\">Publishing custom metrics<\/a>, <a href=\"https:\/\/docs.aws.amazon.com\/managedservices\/latest\/userguide\/custom-cloudwatch-events.html\" target=\"_blank\" rel=\"noreferrer noopener\">Creating custom CloudWatch metrics and alarms<\/a>)<\/li><li>Correlating and analyzing information across single or multiple AWS log sources <strong>(AWS Documentation:<\/strong> <a href=\"https:\/\/docs.aws.amazon.com\/prescriptive-guidance\/latest\/implementing-logging-monitoring-cloudwatch\/cloudwatch-search-analysis.html\" target=\"_blank\" rel=\"noreferrer noopener\">Searching and analyzing logs in CloudWatch<\/a>)<\/li><li>Implementing log delivery solutions <strong>(AWS Documentation:<\/strong> <a href=\"https:\/\/docs.aws.amazon.com\/AmazonCloudWatch\/latest\/logs\/AWS-logs-and-resource-policy.html\" target=\"_blank\" rel=\"noreferrer noopener\">Enabling logging from certain AWS services<\/a>)<\/li><li>Implementing a network audit strategy across single or multiple AWS network services and accounts (for example, Firewall Manager, security groups, network ACLs)  <strong>(AWS Documentation:<\/strong> <a href=\"https:\/\/docs.aws.amazon.com\/waf\/latest\/developerguide\/security-group-policies.html\" target=\"_blank\" rel=\"noreferrer noopener\">Security group policies<\/a>)<\/li><\/ul>\n\n\n\n<p><strong>Task Statement 4.3: Implement and maintain the confidentiality of data and communications of the network.<\/strong><\/p>\n\n\n\n<p>Knowledge of:<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li>Network encryption options that are available on AWS <strong>(AWS Documentation:<\/strong> <a href=\"https:\/\/docs.aws.amazon.com\/AmazonS3\/latest\/userguide\/UsingEncryption.html\" target=\"_blank\" rel=\"noreferrer noopener\">Protecting data using encryption<\/a>)<\/li><li>VPN connectivity over Direct Connect <strong>(AWS Documentation:<\/strong> <a href=\"https:\/\/docs.aws.amazon.com\/whitepapers\/latest\/aws-vpc-connectivity-options\/aws-direct-connect-vpn.html\" target=\"_blank\" rel=\"noreferrer noopener\">AWS Direct Connect + VPN<\/a>)<\/li><li>Encryption methods for data in transit (for example, IPsec) <strong>(AWS Documentation:<\/strong> <a href=\"https:\/\/docs.aws.amazon.com\/whitepapers\/latest\/logical-separation\/encrypting-data-at-rest-and--in-transit.html\" target=\"_blank\" rel=\"noreferrer noopener\">Encrypting Data-at-Rest and -in-Transit<\/a>)<\/li><li>Network encryption under the AWS shared responsibility model Network encryption under the AWS <strong>(AWS Documentation:<\/strong> <a href=\"https:\/\/docs.aws.amazon.com\/whitepapers\/latest\/aws-risk-and-compliance\/shared-responsibility-model.html\" target=\"_blank\" rel=\"noreferrer noopener\">shared responsibility model<\/a>)<\/li><li>Security methods for DNS communications (for example, DNSSEC) <strong>(AWS Documentation:<\/strong> <a href=\"https:\/\/docs.aws.amazon.com\/Route53\/latest\/DeveloperGuide\/domain-configure-dnssec.html\" target=\"_blank\" rel=\"noreferrer noopener\">Configuring DNSSEC for a domain<\/a>)<\/li><\/ul>\n\n\n\n<p>Skills in:<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li>Implementing network encryption methods to meet application compliance requirements (for example, IPsec, TLS) <strong>(AWS Documentation:<\/strong> <a href=\"https:\/\/docs.aws.amazon.com\/wellarchitected\/latest\/security-pillar\/protecting-data-in-transit.html\" target=\"_blank\" rel=\"noreferrer noopener\">Protecting Data in Transit<\/a>)<\/li><li>Implementing encryption solutions to secure data in transit (for example, CloudFront, Application Load Balancers and Network Load Balancers, VPN over Direct Connect, AWS managed databases, Amazon S3, custom solutions on Amazon EC2, Transit Gateway) <strong>(AWS Documentation:<\/strong> <a href=\"https:\/\/docs.aws.amazon.com\/securityhub\/latest\/userguide\/securityhub-standards-fsbp-controls.html\" target=\"_blank\" rel=\"noreferrer noopener\">AWS Foundational Security Best Practices controls<\/a>, <a href=\"https:\/\/docs.aws.amazon.com\/whitepapers\/latest\/aws-overview\/networking-services.html\" target=\"_blank\" rel=\"noreferrer noopener\">Networking and Content Delivery<\/a>, <a href=\"https:\/\/docs.aws.amazon.com\/prescriptive-guidance\/latest\/patterns\/connect-to-application-migration-service-data-and-control-planes-over-a-private-network.html\" target=\"_blank\" rel=\"noreferrer noopener\">Connect to Application Migration Service data<\/a>)<\/li><li>Implementing a certificate management solution by using a certificate authority (for example, ACM, AWS Certificate Manager Private Certificate Authority [ACM PCA]) <strong>(AWS Documentation:<\/strong> <a href=\"https:\/\/docs.aws.amazon.com\/acm-pca\/latest\/userguide\/PcaWelcome.html\" target=\"_blank\" rel=\"noreferrer noopener\">ACM Private CA<\/a>)<\/li><li>Implementing secure DNS communications <strong>(AWS Documentation:<\/strong> <a href=\"https:\/\/docs.aws.amazon.com\/whitepapers\/latest\/building-scalable-secure-multi-vpc-network-infrastructure\/dns.html\" target=\"_blank\" rel=\"noreferrer noopener\">DNS<\/a>)<\/li><\/ul>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter size-full\"><a href=\"https:\/\/www.testpreptraining.ai\/aws-certified-advanced-networking-specialty-practice-exam\" target=\"_blank\" rel=\"noopener\"><img decoding=\"async\" width=\"961\" height=\"150\" src=\"https:\/\/www.testpreptraining.ai\/blog\/wp-content\/uploads\/2021\/11\/advanced-specialty.png\" alt=\"advanced networking specialty practice exam\" class=\"wp-image-20672\" srcset=\"https:\/\/www.testpreptraining.ai\/blog\/wp-content\/uploads\/2021\/11\/advanced-specialty.png 961w, https:\/\/www.testpreptraining.ai\/blog\/wp-content\/uploads\/2021\/11\/advanced-specialty-300x47.png 300w\" sizes=\"(max-width: 961px) 100vw, 961px\" \/><\/a><\/figure><\/div>\n\n\n\n<h4 class=\"wp-block-heading\"><strong>Step <\/strong> <strong>2. Major study areas to focus for AWS Advanced Specialty Exam<\/strong><\/h4>\n\n\n\n<h6 class=\"wp-block-heading\"><strong>Edge network services<\/strong><\/h6>\n\n\n\n<p>AWS edge computing services provide the infrastructure and software necessary for moving data processing and analysis as close to the endpoint as feasible. AWS Lambda is a computing service from Amazon Web Services that allows you to run code without having to create or manage servers. Lambda effortlessly grows from a few requests per day to thousands per second, running your code only when necessary.<\/p>\n\n\n\n<h6 class=\"wp-block-heading\"><strong>Hybrid network-connectivity options<\/strong><\/h6>\n\n\n\n<p>VPNs are used by many AWS customers to offer private communication between AWS infrastructure and on-premises services. AWS Direct Connect may be a better fit for use cases that require additional bandwidth, consistent network performance, or improved privacy. These networking options are frequently required in order to migrate to AWS. <\/p>\n\n\n\n<h6 class=\"wp-block-heading\"><strong>Inter-VPC connectivity options<\/strong><\/h6>\n\n\n\n<p>VPC peering is a straightforward approach to link several VPCs; however, hub-and-spoke network architectures employing AWS Transit Gateway offer significant operational efficiencies at scale. Transit Gateway opens up a world of design possibilities.<\/p>\n\n\n\n<h6 class=\"wp-block-heading\"><strong>Automating network management using AWS CloudFormation<\/strong><\/h6>\n\n\n\n<p>The capacity to automate and automatically construct and break down complete environments is known as infrastructure as code. It lets enterprises install infrastructure quickly, allowing them to operate with more agility. Moreover, it also increases resilience by allowing infrastructure to be rebuilt quickly. Infrastructure as code is what CloudFormation is all about. Further, it also allows you to control your network setup using simple JSON or YAML files.<\/p>\n\n\n\n<h6 class=\"wp-block-heading\"><strong>Security and compliance<\/strong><\/h6>\n\n\n\n<p>Many AWS clients set up infrastructure that is accessed by a worldwide user base. Secure access must be supported by network architects. However, AWS services are frequently combined to achieve these security objectives. CloudFront and AWS Web Application Firewall (WAF), for example, can protect against network threats that target multiple levels of the OSI model when used together.<\/p>\n\n\n\n<h6 class=\"wp-block-heading\"><strong>Methods for simplifying network management and troubleshooting<\/strong><\/h6>\n\n\n\n<p>In real-world applications, connectivity challenges arise when communication between peer VPCs is necessary, as well as when dealing with VPNs or Direct Connect to on-premises networks. AWS offers a number of data sources that help you gain a better understanding of your network&#8217;s activities. These can help with common network administration chores like network connection problems. Additionally, Traffic Mirroring is an Amazon VPC function that allows you to replicate network traffic from Amazon Elastic Compute Cloud (EC2) instances&#8217; elastic network interface.<\/p>\n\n\n\n<h6 class=\"wp-block-heading\"><strong>Network configuration options for high-performance applications<\/strong><\/h6>\n\n\n\n<p>Some application workloads, such as high-performance computing, may necessitate low-latency, high-bandwidth network connections between compute nodes. AWS offers a variety of setup choices to accommodate these workloads.  However, for obtaining the necessary network performance, high-performance computing workloads may require an operating system setup. <\/p>\n\n\n\n<h6 class=\"wp-block-heading\"><strong>Designs for reliability<\/strong><\/h6>\n\n\n\n<p>Designing systems that can automatically recover from failure is a design principle of the AWS Well-Architected Framework&#8217;s dependability pillar. Using network services like Amazon Route 53 and AWS Global Accelerator, network architects may create highly robust, multi-region architectures. These systems may identify failure and divert client traffic away from it, resulting in higher availability. <\/p>\n\n\n\n<h4 class=\"wp-block-heading\"><strong>Step 3. AWS recommended training<\/strong><\/h4>\n\n\n\n<p><a href=\"https:\/\/aws.amazon.com\/certification\/certified-advanced-networking-specialty\/\" target=\"_blank\" rel=\"noreferrer noopener\">AWS<\/a> recommends courses to help you develop and broaden your technical knowledge. You will be able to cover the various areas of the Advanced Networking Specialty exam with the assistance of an expert.<\/p>\n\n\n\n<h6 class=\"wp-block-heading\"><strong>AWS Certified Advanced Networking &#8211; Specialty Exam Readiness<\/strong><\/h6>\n\n\n\n<p>As a networking professional on AWS, you&#8217;ll create a safe, scalable, and highly available network architecture while addressing network security, hybrid IT connectivity, network interaction with other AWS services, routing approaches, and network troubleshooting needs. However, the suitable audience for this <a href=\"https:\/\/aws.amazon.com\/training\/classroom\/exam-readiness-aws-certified-advanced-networking-specialty\/\" target=\"_blank\" rel=\"noreferrer noopener\">course<\/a> are:<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li>Firstly, Data engineers<\/li><li>Then, Solutions architects<\/li><li>Lastly, Network engineers<\/li><\/ul>\n\n\n\n<h6 class=\"wp-block-heading\"><strong>AWS Network Learning Plan<\/strong><\/h6>\n\n\n\n<p>You won&#8217;t have to worry if you&#8217;re starting in the proper location or taking the right courses with the <a href=\"https:\/\/aws.amazon.com\/training\/learn-about\/advanced-networking\/\" target=\"_blank\" rel=\"noreferrer noopener\">AWS Networking Learning Plan<\/a>. However, in this, you&#8217;ll be taken through an AWS-recommended curriculum that you may complete at your own speed. Complete the whole plan or select the classes that appeal to you. Further, you will:<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li>Firstly, be better equipped to develop and manage network designs for all AWS services when you finish this plan. <\/li><li>Secondly, have abilities that will assist you to get into cloud architecture and network engineering jobs. <\/li><li>Lastly, get a better understanding of Amazon Web Features (AWS) services such as Amazon Route 53, Amazon Direct Connect, and Amazon Virtual Private Cloud.<\/li><\/ul>\n\n\n\n<h6 class=\"wp-block-heading\"><strong>AWS Ramp-Up Guide<\/strong><\/h6>\n\n\n\n<p>This downloadable <a href=\"https:\/\/aws.amazon.com\/training\/learn-about\/advanced-networking\/\" target=\"_blank\" rel=\"noreferrer noopener\">guide<\/a> was created by AWS specialists to help you navigate the wide array of tools and material available to help you improve your networking skills. However, you may utilize this guide at your own speed, whether you choose to read articles, examine PDFs, or take digital courses. Further, it will assist you in comprehending all of your learning alternatives and determining which are the most appropriate for you depending on your knowledge and ability level.<\/p>\n\n\n\n<h4 class=\"wp-block-heading\"><strong>Step 4. Using AWS Exam Practice tests<\/strong><\/h4>\n\n\n\n<p>This is yet another important component of the study guide that will not only assist you in identifying your weak regions but also in developing a strong revision level. To put it another way, utilizing the practice examinations will help you improve your answer skills while also saving time. There are, however, a number of free sample examinations available to assist you in getting started with AWS Advanced Networking Specialty practice exams. Once you&#8217;ve gone over a section or a few subjects, you can take mock examinations as part of your review.<\/p>\n\n\n\n<p><em>However, above we understood the process of passing the exam. But, what to do afterwards? Let&#8217;s find out!<\/em><\/p>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>How to start career as an Advanced Networking Specialist?<\/strong><\/h3>\n\n\n\n<p>Amazon Web Services was one of the pioneers of the cloud computing revolution. AWS is one of the market&#8217;s oldest and most successful cloud computing businesses, and it must earn the respect of the organization. As a result, starting your career with the AWS certification will benefit you. However, in order to provide clarity, we will discuss certain steps to take in order to obtain a strong start as an Advanced Networking Specialist.<\/p>\n\n\n\n<h5 class=\"wp-block-heading\"><strong>1. Gain hands-on experience<\/strong><\/h5>\n\n\n\n<p>This is an important step for acquiring a good and high-paid job in the market. That is to say, if you have the necessary expertise as well as an AWS certification, no company can refuse you. However, the most effective method to do so is to begin working on a project. Start working on your own project using the skills and information you gained while completing the advanced networking specialty exam. Furthermore, this may be used as an assignment to assess your abilities, as well as a benefit during the interview to demonstrate your abilities to the company.<\/p>\n\n\n\n<h5 class=\"wp-block-heading\"><strong>2. Preparing for the job interview<\/strong><\/h5>\n\n\n\n<p>The next stage is to secure a top position in the industry after passing the AWS certification and acquiring hands-on experience. You should also be aware that getting an AWS Advanced Networking Specialist certification is the most effective way to advance your networking career. According to a survey, AWS Architects at the entry-level make roughly \u20b9480,000 per year. The average AWS Architects pay is \u20b91,800,000 per year when he progresses to the mid-level. Senior AWS Architects may make upwards of \u20b93,000,000 each year. Talking about the interview process, the first and the most important thing is to stay confident during the interview. Secondly, for preparing you have to go through the theoretical part as well as the project you have worked on. Further, to apply for the Advanced Networking Specialist job role, some of the top companies you can look for include:<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li><em>Accenture<\/em><\/li><li><em>Deloitte<\/em><\/li><li><em>nVent<\/em><\/li><li><em>amdocs<\/em><\/li><li><em>HP<\/em><\/li><li><em>NTT Data<\/em><\/li><\/ul>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>Final Words<\/strong><\/h3>\n\n\n\n<p>The AWS Certified Advanced Networking \u2013 Specialty certification allows IT, engineers, to demonstrate their understanding of how to construct cost-effective, secure, and performant networks on AWS by validating their expertise. Preparing for a certification exam is a great method to solidify your understanding of any technology. So, start preparing for the exam, take the training courses, pass the exam, and achieve your dream role.<\/p>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter\"><a href=\"https:\/\/www.testpreptraining.ai\/aws-certified-advanced-networking-specialty-free-practice-test\" target=\"_blank\" rel=\"noopener\"><img decoding=\"async\" src=\"https:\/\/www.testpreptraining.ai\/tutorial\/wp-content\/uploads\/2020\/07\/AWS-Free-Practice-tests.png\" alt=\"AWS Certified Advanced Networking Specialty Free Practice tests\"\/><\/a><\/figure><\/div>\n","protected":false},"excerpt":{"rendered":"<p>The AWS certification is well-known for offering the greatest IT infrastructure services for cloud computing firms and businesses. As a result, the company has increased energy efficiency by lowering capital infrastructure expenditures and variable costs as it develops. However, when it comes to AWS certifications, the demand for the AWS Certified Advanced Networking &#8211; Specialty&#8230;<\/p>\n","protected":false},"author":2,"featured_media":20666,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[31],"tags":[3542,3543,3544,1210,3545,1212],"class_list":["post-20665","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-aws","tag-aws-advanced-networking-specialist","tag-aws-advanced-networking-specialist-exam","tag-aws-advanced-networking-specialist-job-role","tag-aws-advanced-networking-speciality-exam","tag-aws-advanced-networking-specialty-exam-guide","tag-aws-advanced-networking-specialty-free-practice-tests"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v21.7 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>How to start your career as an AWS Advanced Networking Specialist? - Blog<\/title>\n<meta name=\"description\" content=\"Enhance your networking skills by preparing and passing the AWS Advanced Networking Specialty exam. Become AWS Certified Professional Now!\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.testpreptraining.ai\/blog\/how-to-start-your-career-as-an-aws-advanced-networking-specialist\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"How to start your career as an AWS Advanced Networking Specialist? - Blog\" \/>\n<meta property=\"og:description\" content=\"Enhance your networking skills by preparing and passing the AWS Advanced Networking Specialty exam. Become AWS Certified Professional Now!\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.testpreptraining.ai\/blog\/how-to-start-your-career-as-an-aws-advanced-networking-specialist\/\" \/>\n<meta property=\"og:site_name\" content=\"Blog\" \/>\n<meta property=\"article:published_time\" content=\"2021-11-28T05:30:00+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2022-09-14T11:47:31+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.testpreptraining.ai\/blog\/wp-content\/uploads\/2021\/11\/AWS-Advanced-Networking-Specialist.png\" \/>\n\t<meta property=\"og:image:width\" content=\"750\" \/>\n\t<meta property=\"og:image:height\" content=\"400\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/png\" \/>\n<meta name=\"author\" content=\"Pulkit Dheer\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Pulkit Dheer\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"26 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\/\/www.testpreptraining.ai\/blog\/how-to-start-your-career-as-an-aws-advanced-networking-specialist\/\",\"url\":\"https:\/\/www.testpreptraining.ai\/blog\/how-to-start-your-career-as-an-aws-advanced-networking-specialist\/\",\"name\":\"How to start your career as an AWS Advanced Networking Specialist? - Blog\",\"isPartOf\":{\"@id\":\"https:\/\/www.testpreptraining.ai\/blog\/#website\"},\"datePublished\":\"2021-11-28T05:30:00+00:00\",\"dateModified\":\"2022-09-14T11:47:31+00:00\",\"author\":{\"@id\":\"https:\/\/www.testpreptraining.ai\/blog\/#\/schema\/person\/0931136793896e849443990eb08ddb21\"},\"description\":\"Enhance your networking skills by preparing and passing the AWS Advanced Networking Specialty exam. Become AWS Certified Professional Now!\",\"breadcrumb\":{\"@id\":\"https:\/\/www.testpreptraining.ai\/blog\/how-to-start-your-career-as-an-aws-advanced-networking-specialist\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/www.testpreptraining.ai\/blog\/how-to-start-your-career-as-an-aws-advanced-networking-specialist\/\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/www.testpreptraining.ai\/blog\/how-to-start-your-career-as-an-aws-advanced-networking-specialist\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/www.testpreptraining.ai\/blog\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"How to start your career as an AWS Advanced Networking Specialist?\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/www.testpreptraining.ai\/blog\/#website\",\"url\":\"https:\/\/www.testpreptraining.ai\/blog\/\",\"name\":\"Learning Resources\",\"description\":\"Testprep Training Blogs\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/www.testpreptraining.ai\/blog\/?s={search_term_string}\"},\"query-input\":\"required name=search_term_string\"}],\"inLanguage\":\"en-US\"},{\"@type\":\"Person\",\"@id\":\"https:\/\/www.testpreptraining.ai\/blog\/#\/schema\/person\/0931136793896e849443990eb08ddb21\",\"name\":\"Pulkit Dheer\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/www.testpreptraining.ai\/blog\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/162b67a9229d8169c3c928e0ada4e252be835b0d89b1eaff259f320e4a2fd630?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/162b67a9229d8169c3c928e0ada4e252be835b0d89b1eaff259f320e4a2fd630?s=96&d=mm&r=g\",\"caption\":\"Pulkit Dheer\"},\"description\":\"With a background in Engineering and a great enthusiasm for writing, Pulkit focuses on intensive research to create targeted content. He brings his years of learning and experience to his current role. With a zeal towards technological research and powerful use of words dedicated to inspire and help professionals onset their career.\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"How to start your career as an AWS Advanced Networking Specialist? - Blog","description":"Enhance your networking skills by preparing and passing the AWS Advanced Networking Specialty exam. Become AWS Certified Professional Now!","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.testpreptraining.ai\/blog\/how-to-start-your-career-as-an-aws-advanced-networking-specialist\/","og_locale":"en_US","og_type":"article","og_title":"How to start your career as an AWS Advanced Networking Specialist? - Blog","og_description":"Enhance your networking skills by preparing and passing the AWS Advanced Networking Specialty exam. Become AWS Certified Professional Now!","og_url":"https:\/\/www.testpreptraining.ai\/blog\/how-to-start-your-career-as-an-aws-advanced-networking-specialist\/","og_site_name":"Blog","article_published_time":"2021-11-28T05:30:00+00:00","article_modified_time":"2022-09-14T11:47:31+00:00","og_image":[{"width":750,"height":400,"url":"https:\/\/www.testpreptraining.ai\/blog\/wp-content\/uploads\/2021\/11\/AWS-Advanced-Networking-Specialist.png","type":"image\/png"}],"author":"Pulkit Dheer","twitter_card":"summary_large_image","twitter_misc":{"Written by":"Pulkit Dheer","Est. reading time":"26 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/www.testpreptraining.ai\/blog\/how-to-start-your-career-as-an-aws-advanced-networking-specialist\/","url":"https:\/\/www.testpreptraining.ai\/blog\/how-to-start-your-career-as-an-aws-advanced-networking-specialist\/","name":"How to start your career as an AWS Advanced Networking Specialist? - Blog","isPartOf":{"@id":"https:\/\/www.testpreptraining.ai\/blog\/#website"},"datePublished":"2021-11-28T05:30:00+00:00","dateModified":"2022-09-14T11:47:31+00:00","author":{"@id":"https:\/\/www.testpreptraining.ai\/blog\/#\/schema\/person\/0931136793896e849443990eb08ddb21"},"description":"Enhance your networking skills by preparing and passing the AWS Advanced Networking Specialty exam. Become AWS Certified Professional Now!","breadcrumb":{"@id":"https:\/\/www.testpreptraining.ai\/blog\/how-to-start-your-career-as-an-aws-advanced-networking-specialist\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.testpreptraining.ai\/blog\/how-to-start-your-career-as-an-aws-advanced-networking-specialist\/"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/www.testpreptraining.ai\/blog\/how-to-start-your-career-as-an-aws-advanced-networking-specialist\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.testpreptraining.ai\/blog\/"},{"@type":"ListItem","position":2,"name":"How to start your career as an AWS Advanced Networking Specialist?"}]},{"@type":"WebSite","@id":"https:\/\/www.testpreptraining.ai\/blog\/#website","url":"https:\/\/www.testpreptraining.ai\/blog\/","name":"Learning Resources","description":"Testprep Training Blogs","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.testpreptraining.ai\/blog\/?s={search_term_string}"},"query-input":"required name=search_term_string"}],"inLanguage":"en-US"},{"@type":"Person","@id":"https:\/\/www.testpreptraining.ai\/blog\/#\/schema\/person\/0931136793896e849443990eb08ddb21","name":"Pulkit Dheer","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.testpreptraining.ai\/blog\/#\/schema\/person\/image\/","url":"https:\/\/secure.gravatar.com\/avatar\/162b67a9229d8169c3c928e0ada4e252be835b0d89b1eaff259f320e4a2fd630?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/162b67a9229d8169c3c928e0ada4e252be835b0d89b1eaff259f320e4a2fd630?s=96&d=mm&r=g","caption":"Pulkit Dheer"},"description":"With a background in Engineering and a great enthusiasm for writing, Pulkit focuses on intensive research to create targeted content. He brings his years of learning and experience to his current role. With a zeal towards technological research and powerful use of words dedicated to inspire and help professionals onset their career."}]}},"_links":{"self":[{"href":"https:\/\/www.testpreptraining.ai\/blog\/wp-json\/wp\/v2\/posts\/20665","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.testpreptraining.ai\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.testpreptraining.ai\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.testpreptraining.ai\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.testpreptraining.ai\/blog\/wp-json\/wp\/v2\/comments?post=20665"}],"version-history":[{"count":15,"href":"https:\/\/www.testpreptraining.ai\/blog\/wp-json\/wp\/v2\/posts\/20665\/revisions"}],"predecessor-version":[{"id":27183,"href":"https:\/\/www.testpreptraining.ai\/blog\/wp-json\/wp\/v2\/posts\/20665\/revisions\/27183"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.testpreptraining.ai\/blog\/wp-json\/wp\/v2\/media\/20666"}],"wp:attachment":[{"href":"https:\/\/www.testpreptraining.ai\/blog\/wp-json\/wp\/v2\/media?parent=20665"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.testpreptraining.ai\/blog\/wp-json\/wp\/v2\/categories?post=20665"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.testpreptraining.ai\/blog\/wp-json\/wp\/v2\/tags?post=20665"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}