CLF-C02 Cloud Technology and Services Practice Question
Which AWS service allows you to create a private network connection between your on-premises data center and AWS without using the public internet?
⚠ Common exam trap
It's easy for candidates to confuse AWS VPN (which also creates a private tunnel) with a truly private connection, forgetting that VPNs still traverse the public internet, whereas Direct Connect uses a dedicated physical link that never touches the internet.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
AWS Direct Connect
AWS Direct Connect is the correct answer because it provides a dedicated, private network connection from your on-premises data center directly to AWS, bypassing the public internet entirely. This is achieved through a physical cross-connect at an AWS Direct Connect location, using industry-standard 802.1Q VLANs to maintain traffic isolation. Unlike VPN-based solutions, Direct Connect offers consistent network performance, lower latency, and higher bandwidth, making it ideal for hybrid workloads and large-scale data transfers.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
AWS VPN
Why it's wrong here
AWS Site-to-Site VPN establishes IPsec tunnels over the public internet to connect on-premises networks to Amazon VPC. While encrypted and often used as a fallback, it traverses the internet, so latency and bandwidth are variable, and it does not offer a private, dedicated physical path. This makes it incorrect for a scenario demanding a dedicated, low-latency connection.
- ✗
Amazon VPC Peering
Why it's wrong here
VPC peering is a one-to-one networking connection between two VPCs that enables traffic routing using private IPv4 or IPv6 addresses. It is an AWS-internal construct and cannot extend to an on-premises data center; there is no VPN tunnel, physical link, or carrier circuit involved. Therefore, it does not satisfy the need to reach AWS from a customer's on-premises environment.
- ✓
AWS Direct Connect
Why this is correct
AWS Direct Connect provides a dedicated, private network link between your data center and an AWS Direct Connect colocation facility, typically over standard Ethernet fiber optic cable. It bypasses the public internet entirely, ensuring consistent network performance, lower latency, and predictability for high-volume workloads. This aligns precisely with the scenario of establishing a private, dedicated connection from on-premises to AWS.
- ✗
AWS Transit Gateway
Why it's wrong here
AWS Transit Gateway is a central hub that interconnects VPCs and on-premises networks, simplifying routing and managing attachments, but it is not a physical connection service. It must rely on existing network paths, such as VPN tunnels or Direct Connect virtual interfaces, to provide the actual connectivity. Thus, Transit Gateway alone does not create a dedicated private link; it only orchestrates routes over links established by other services.
Visual reference
Go deeper
Related to this question
About these practice questions
This CLF-C02 question is part of Courseiva's 993-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CLF-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CLF-C02 exam.