CLF-C02 Cloud Technology and Services Practice Question
A company operates multiple Amazon VPCs across several AWS accounts for different business units. The company also has an on-premises data center connected to AWS via AWS Direct Connect. The network team wants to simplify the connectivity between all VPCs and the on-premises network. Currently, they manage individual VPC peering connections, which is becoming complex as more VPCs are added. They need a single network hub that can scale to connect hundreds of VPCs and the on-premises network, with centralized routing management. Which AWS service should the network team use?
⚠ Common exam trap
AWS often tests the misconception that VPC peering can be used as a hub-and-spoke solution, but candidates must remember that VPC peering is non-transitive and requires a full mesh, whereas Transit Gateway provides transitive routing and centralized management.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
AWS Transit Gateway
AWS Transit Gateway acts as a single, scalable network hub that connects multiple VPCs and on-premises networks via Direct Connect, using a centralized routing table. This eliminates the need for complex, meshed VPC peering connections and provides transitive routing across all attached networks, which directly addresses the requirement for a hub that scales to hundreds of VPCs.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
AWS Transit Gateway
Why this is correct
AWS Transit Gateway is a central hub that connects VPCs and on-premises networks. It supports hub-and-spoke topology, scales to hundreds of VPCs, and works with Direct Connect and VPNs. This meets the requirement for simplified, scalable connectivity with centralized routing.
- ✗
Amazon VPC peering
Why it's wrong here
Amazon VPC peering creates a one-to-one connection between two VPCs. To connect many VPCs, you would need a full mesh of peering connections, which does not scale well and increases complexity. It also cannot directly connect to on-premises networks via Direct Connect.
When this WOULD be correct
When a company needs to connect a small number of VPCs (e.g., 2-5) with simple, direct connectivity and does not require centralized routing or integration with on-premises networks. The question would specify a limited number of VPCs and no need for hub-and-spoke architecture.
- ✗
AWS PrivateLink
Why it's wrong here
AWS PrivateLink provides private connectivity to services hosted on AWS by exposing endpoints within a VPC. It is designed for accessing specific services, not for routing traffic between multiple VPCs or connecting to on-premises networks.
When this WOULD be correct
A company needs to expose a service privately from one VPC to multiple consumer VPCs without VPC peering or transit gateway, ensuring traffic does not traverse the public internet. PrivateLink would be the correct answer.
- ✗
AWS Site-to-Site VPN
Why it's wrong here
AWS Site-to-Site VPN connects on-premises networks to a single VPC. While it can be part of a hybrid solution, it does not interconnect multiple VPCs. Managing multiple VPN connections to each VPC does not simplify the architecture.
When this WOULD be correct
A company needs to connect a single VPC to an on-premises data center over the internet with encrypted tunnels, and does not require inter-VPC connectivity or a hub-and-spoke architecture.
Option-by-option analysis
Why each answer is right or wrong
Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The CLF-C02 exam frequently reuses these exact scenarios with slightly different constraints.
✓AWS Transit GatewayCorrect answer▾
Why this is correct
AWS Transit Gateway is a central hub that connects VPCs and on-premises networks. It supports hub-and-spoke topology, scales to hundreds of VPCs, and works with Direct Connect and VPNs. This meets the requirement for simplified, scalable connectivity with centralized routing.
✗Amazon VPC peeringWrong answer — click to see why▾
Why this is wrong here
VPC peering requires managing individual connections between each pair of VPCs, which does not scale to hundreds of VPCs and lacks centralized routing management. It also does not natively integrate with on-premises networks via Direct Connect.
★ When this WOULD be the correct answer
When a company needs to connect a small number of VPCs (e.g., 2-5) with simple, direct connectivity and does not require centralized routing or integration with on-premises networks. The question would specify a limited number of VPCs and no need for hub-and-spoke architecture.
Why candidates choose this
Candidates may think VPC peering is the default way to connect VPCs and overlook its scalability limitations, especially when the question mentions 'simplify connectivity' without explicitly stating the need for a hub.
✗AWS PrivateLinkWrong answer — click to see why▾
Why this is wrong here
AWS PrivateLink is used for private connectivity between VPCs and services, not for routing traffic between multiple VPCs or to on-premises networks. It does not provide a hub-and-spoke architecture or centralized routing management.
★ When this WOULD be the correct answer
A company needs to expose a service privately from one VPC to multiple consumer VPCs without VPC peering or transit gateway, ensuring traffic does not traverse the public internet. PrivateLink would be the correct answer.
Why candidates choose this
Candidates may confuse PrivateLink's ability to connect VPCs privately with the need for a network hub, overlooking that PrivateLink only supports point-to-point service connections, not full mesh or hub-and-spoke routing.
✗AWS Site-to-Site VPNWrong answer — click to see why▾
Why this is wrong here
AWS Site-to-Site VPN connects individual VPCs to on-premises networks but does not provide a centralized hub for inter-VPC connectivity or simplify peering complexity across multiple VPCs and accounts.
★ When this WOULD be the correct answer
A company needs to connect a single VPC to an on-premises data center over the internet with encrypted tunnels, and does not require inter-VPC connectivity or a hub-and-spoke architecture.
Why candidates choose this
Candidates may confuse Site-to-Site VPN with Transit Gateway because both can connect on-premises networks, but Site-to-Site VPN lacks the centralized routing and multi-VPC aggregation capabilities needed for this scenario.
Analysis generated from the official CLF-C02blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”
Go deeper
Related to this question
About these practice questions
One of 988 original CLF-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CLF-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CLF-C02 exam.