Courseiva
Cloud Technology and ServicesmediumMultiple ChoiceObjective-mapped

CLF-C02 Cloud Technology and Services Practice Question

A company runs a data-intensive workload in a colocation facility and wants to establish a dedicated, private network connection to its Amazon VPC. The connection must bypass the public internet to provide consistent high throughput and low latency. The company also wants to avoid data transfer costs associated with internet-based connections. Which AWS service should the company use?

⚠ Common exam trap

Test-takers frequently confuse AWS Site-to-Site VPN with a private connection, but VPNs still traverse the public internet and cannot guarantee the consistent performance or cost savings of a dedicated physical link like Direct Connect.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

AWS Direct Connect

AWS Direct Connect is the correct service because it provides a dedicated, private network connection from an on-premises or colocation facility directly to an Amazon VPC, bypassing the public internet entirely. This ensures consistent high throughput, low latency, and eliminates data transfer costs associated with internet-based connections, as traffic flows over a private physical link.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • AWS Site-to-Site VPN

    Why it's wrong here

    Incorrect. AWS Site-to-Site VPN creates a secure connection over the public internet between an on-premises network and a VPC. While encrypted, it does not provide a dedicated private circuit and is subject to internet variability in latency and throughput. It is not designed to bypass the public internet.

    When this WOULD be correct

    A company needs to securely connect its on-premises network to AWS over the internet with encryption, and is willing to accept variable throughput and latency, while prioritizing cost savings over dedicated bandwidth.

  • AWS Direct Connect

    Why this is correct

    Correct. AWS Direct Connect establishes a dedicated private connection between an on-premises data center and AWS. This connection bypasses the public internet, resulting in more consistent network performance, lower latency, and potentially lower data transfer costs. It is the appropriate service for the described requirements.

  • AWS VPN CloudHub

    Why it's wrong here

    Incorrect. AWS VPN CloudHub is a hub-and-spoke VPN model that connects multiple on-premises sites to a virtual private gateway using internet-based VPN tunnels. It does not provide a dedicated private connection to AWS and still relies on the public internet.

    When this WOULD be correct

    A company has multiple branch offices with existing VPN connections to AWS and wants to enable inter-site communication through a central hub in AWS. The question would specify using existing VPN connections and needing a hub-and-spoke model.

  • AWS Transit Gateway

    Why it's wrong here

    Incorrect. AWS Transit Gateway is a network transit hub that simplifies connectivity between multiple VPCs and on-premises networks. However, it is not a connection service itself; it requires an underlying connection such as Direct Connect or Site-to-Site VPN to link on-premises networks. It does not directly provide the dedicated private link.

    When this WOULD be correct

    A company has multiple VPCs and on-premises networks that need to be interconnected with centralized management. They want to simplify routing and reduce peering complexity. In this scenario, AWS Transit Gateway would be the correct answer because it acts as a hub to connect all networks.

Option-by-option analysis

Why each answer is right or wrong

Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The CLF-C02 exam frequently reuses these exact scenarios with slightly different constraints.

AWS Direct ConnectCorrect answer

Why this is correct

Correct. AWS Direct Connect establishes a dedicated private connection between an on-premises data center and AWS. This connection bypasses the public internet, resulting in more consistent network performance, lower latency, and potentially lower data transfer costs. It is the appropriate service for the described requirements.

AWS Site-to-Site VPNWrong answer — click to see why

Why this is wrong here

AWS Site-to-Site VPN uses the public internet to establish encrypted tunnels, so it does not bypass the public internet and cannot guarantee consistent high throughput and low latency like a dedicated private connection.

★ When this WOULD be the correct answer

A company needs to securely connect its on-premises network to AWS over the internet with encryption, and is willing to accept variable throughput and latency, while prioritizing cost savings over dedicated bandwidth.

Why candidates choose this

Candidates may confuse VPN with a dedicated connection, assuming that encryption implies a private link, or they may overlook the requirement to bypass the public internet.

AWS VPN CloudHubWrong answer — click to see why

Why this is wrong here

AWS VPN CloudHub is a hub-and-spoke VPN topology that connects multiple remote sites via the internet, not a dedicated private connection. It does not bypass the public internet or provide consistent high throughput and low latency like Direct Connect.

★ When this WOULD be the correct answer

A company has multiple branch offices with existing VPN connections to AWS and wants to enable inter-site communication through a central hub in AWS. The question would specify using existing VPN connections and needing a hub-and-spoke model.

Why candidates choose this

Candidates may confuse CloudHub as a dedicated connection solution because it involves VPNs and 'hub' terminology, but it still relies on the public internet and lacks the private, dedicated nature of Direct Connect.

AWS Transit GatewayWrong answer — click to see why

Why this is wrong here

AWS Transit Gateway is a network transit hub to interconnect VPCs and on-premises networks, but it does not provide a dedicated private connection itself; it requires an underlying connection like AWS Direct Connect or VPN. The question specifically asks for a dedicated private network connection that bypasses the public internet, which Transit Gateway alone cannot fulfill.

★ When this WOULD be the correct answer

A company has multiple VPCs and on-premises networks that need to be interconnected with centralized management. They want to simplify routing and reduce peering complexity. In this scenario, AWS Transit Gateway would be the correct answer because it acts as a hub to connect all networks.

Why candidates choose this

Candidates may confuse Transit Gateway as a direct replacement for Direct Connect because it can integrate with Direct Connect, but they overlook that Transit Gateway is a routing service, not a physical connection.

Analysis generated from the official CLF-C02blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”

About these practice questions

One of 988 original CLF-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CLF-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CLF-C02 exam.