CLF-C02 Cloud Technology and Services Practice Question
A company has two separate VPCs — one for development workloads and one for a shared services environment — and wants EC2 instances in both VPCs to communicate with each other using private IP addresses without traffic traversing the public internet. Which AWS feature enables this?
⚠ Common exam trap
It's easy for candidates to confuse VPC Peering with a NAT Gateway or Internet Gateway, mistakenly thinking those services can bridge two VPCs, when in fact they are designed for internet-bound traffic, not private VPC-to-VPC connectivity.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
VPC Peering
VPC Peering enables direct network connectivity between two VPCs using private IP addresses, with traffic routed entirely within the AWS network backbone. This allows EC2 instances in the development VPC and the shared services VPC to communicate without traversing the public internet, as traffic stays within the AWS global infrastructure.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Internet Gateway
Why it's wrong here
An Internet Gateway is a horizontally scaled, redundant VPC component that enables communication between a VPC and the public internet, supporting IPv4 and IPv6. It performs no address translation itself; it is the target for internet-bound route entries in a VPC route table, allowing instances with public IPs to send and receive traffic. Because it is designed to face the internet, it cannot establish private, internal links between VPCs — VPC-to-VPC traffic must be routed via a VPC peering connection or a transit gateway, not through an IGW.
- ✗
NAT Gateway
Why it's wrong here
A NAT Gateway is a managed service that enables instances in a private subnet to initiate outbound traffic to the internet while preventing unsolicited inbound connections from the internet, using source network address translation. It only supports outbound IPv4 traffic and does not create any connection between VPCs; it is attached to a single VPC and its subnet. Since it translates private source IPs to a public IP for internet-bound traffic, it cannot forward traffic to another VPC's private IP range. Thus, it is irrelevant for VPC-to-VPC private connectivity.
- ✓
VPC Peering
Why this is correct
VPC Peering creates a one-to-one networking relationship between two VPCs, using AWS's private global network, that allows instances in either VPC to communicate with each other as if they were on the same network, using private IPv4 or IPv6 addresses. The peering connection is not a gateway or VPN; it is a simple, layer-3 connection that requires no additional hardware, and there is no single point of failure or bandwidth bottleneck. It can be established between VPCs in the same account, across accounts, or across regions, but note that transitive peering is not supported — if VPC A peers with B and B peers with C, A cannot communicate with C via B. This is the correct solution for directly connecting two VPCs in a private, non-internet-routed fashion.
- ✗
AWS Direct Connect
Why it's wrong here
AWS Direct Connect is a dedicated, physical network connection that extends an on-premises data center to AWS, typically used for hybrid cloud workloads. It does not, by itself, connect two AWS VPCs; rather, it links a customer's local network to a VPC via virtual interfaces. Even when combined with a Direct Connect Gateway to reach multiple VPCs, it still requires additional routing configuration and does not provide the simple, private VPC-to-VPC peering that a customer would expect. Therefore, it is not the correct service for directly connecting two VPCs.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CLF-C02 question from scratch — 993 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CLF-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CLF-C02 exam.