Courseiva
Cloud Technology and ServicesmediumMultiple ChoiceObjective-mapped

CLF-C02 Cloud Technology and Services Practice Question

A company operates multiple Amazon VPCs across several AWS accounts for different business units. The company also has an on-premises data center connected to AWS via AWS Direct Connect. The network team wants to simplify the connectivity between all VPCs and the on-premises network. Currently, they manage individual VPC peering connections, which is becoming complex as more VPCs are added. They need a single network hub that can scale to connect hundreds of VPCs and the on-premises network, with centralized routing management. Which AWS service should the network team use?

⚠ Common exam trap

AWS often tests the misconception that VPC peering can be used as a hub-and-spoke solution, but candidates must remember that VPC peering is non-transitive and requires a full mesh, whereas Transit Gateway provides transitive routing and centralized management.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

AWS Transit Gateway

AWS Transit Gateway acts as a single, scalable network hub that connects multiple VPCs and on-premises networks via Direct Connect, using a centralized routing table. This eliminates the need for complex, meshed VPC peering connections and provides transitive routing across all attached networks, which directly addresses the requirement for a hub that scales to hundreds of VPCs.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • AWS Transit Gateway

    Why this is correct

    AWS Transit Gateway is a central hub that connects VPCs and on-premises networks. It supports hub-and-spoke topology, scales to hundreds of VPCs, and works with Direct Connect and VPNs. This meets the requirement for simplified, scalable connectivity with centralized routing.

  • Amazon VPC peering

    Why it's wrong here

    Amazon VPC peering creates a one-to-one connection between two VPCs. To connect many VPCs, you would need a full mesh of peering connections, which does not scale well and increases complexity. It also cannot directly connect to on-premises networks via Direct Connect.

    When this WOULD be correct

    When a company needs to connect a small number of VPCs (e.g., 2-5) with simple, direct connectivity and does not require centralized routing or integration with on-premises networks. The question would specify a limited number of VPCs and no need for hub-and-spoke architecture.

  • AWS PrivateLink

    Why it's wrong here

    AWS PrivateLink provides private connectivity to services hosted on AWS by exposing endpoints within a VPC. It is designed for accessing specific services, not for routing traffic between multiple VPCs or connecting to on-premises networks.

    When this WOULD be correct

    A company needs to expose a service privately from one VPC to multiple consumer VPCs without VPC peering or transit gateway, ensuring traffic does not traverse the public internet. PrivateLink would be the correct answer.

  • AWS Site-to-Site VPN

    Why it's wrong here

    AWS Site-to-Site VPN connects on-premises networks to a single VPC. While it can be part of a hybrid solution, it does not interconnect multiple VPCs. Managing multiple VPN connections to each VPC does not simplify the architecture.

    When this WOULD be correct

    A company needs to connect a single VPC to an on-premises data center over the internet with encrypted tunnels, and does not require inter-VPC connectivity or a hub-and-spoke architecture.

Option-by-option analysis

Why each answer is right or wrong

Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The CLF-C02 exam frequently reuses these exact scenarios with slightly different constraints.

AWS Transit GatewayCorrect answer

Why this is correct

AWS Transit Gateway is a central hub that connects VPCs and on-premises networks. It supports hub-and-spoke topology, scales to hundreds of VPCs, and works with Direct Connect and VPNs. This meets the requirement for simplified, scalable connectivity with centralized routing.

Amazon VPC peeringWrong answer — click to see why

Why this is wrong here

VPC peering requires managing individual connections between each pair of VPCs, which does not scale to hundreds of VPCs and lacks centralized routing management. It also does not natively integrate with on-premises networks via Direct Connect.

★ When this WOULD be the correct answer

When a company needs to connect a small number of VPCs (e.g., 2-5) with simple, direct connectivity and does not require centralized routing or integration with on-premises networks. The question would specify a limited number of VPCs and no need for hub-and-spoke architecture.

Why candidates choose this

Candidates may think VPC peering is the default way to connect VPCs and overlook its scalability limitations, especially when the question mentions 'simplify connectivity' without explicitly stating the need for a hub.

AWS PrivateLinkWrong answer — click to see why

Why this is wrong here

AWS PrivateLink is used for private connectivity between VPCs and services, not for routing traffic between multiple VPCs or to on-premises networks. It does not provide a hub-and-spoke architecture or centralized routing management.

★ When this WOULD be the correct answer

A company needs to expose a service privately from one VPC to multiple consumer VPCs without VPC peering or transit gateway, ensuring traffic does not traverse the public internet. PrivateLink would be the correct answer.

Why candidates choose this

Candidates may confuse PrivateLink's ability to connect VPCs privately with the need for a network hub, overlooking that PrivateLink only supports point-to-point service connections, not full mesh or hub-and-spoke routing.

AWS Site-to-Site VPNWrong answer — click to see why

Why this is wrong here

AWS Site-to-Site VPN connects individual VPCs to on-premises networks but does not provide a centralized hub for inter-VPC connectivity or simplify peering complexity across multiple VPCs and accounts.

★ When this WOULD be the correct answer

A company needs to connect a single VPC to an on-premises data center over the internet with encrypted tunnels, and does not require inter-VPC connectivity or a hub-and-spoke architecture.

Why candidates choose this

Candidates may confuse Site-to-Site VPN with Transit Gateway because both can connect on-premises networks, but Site-to-Site VPN lacks the centralized routing and multi-VPC aggregation capabilities needed for this scenario.

Analysis generated from the official CLF-C02blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”

About these practice questions

One of 988 original CLF-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CLF-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CLF-C02 exam.