Courseiva
Network DesignhardMultiple ChoiceObjective-mapped

ANS-C01 Network Design Practice Question

A company has a Direct Connect connection with a private VIF to a VPC. They want to extend connectivity to an on-premises data center that does not support BGP. What is the simplest way to achieve this?

⚠ Common exam trap

Many exam-takers assume Direct Connect Gateway alone can solve any on-premises routing issue, but it still requires BGP for route exchange, so the correct approach is to use a Transit Gateway with a static VPN to bypass the BGP requirement on the data center side.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Use AWS Site-to-Site VPN with static routing to a Transit Gateway

The on-premises data center does not support BGP, so a static routing approach is required. AWS Site-to-Site VPN with static routing to a Transit Gateway allows you to extend connectivity from the existing Direct Connect VPC to the non-BGP data center by using the Transit Gateway as a central hub, which can route traffic between the Direct Connect VIF and the VPN connection without requiring BGP on the data center side.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Use AWS Site-to-Site VPN with static routing to a Transit Gateway

    Why this is correct

    Transit Gateway supports VPN attachments with static routes, which does not require BGP on the on-premises side.

  • Create a VPC peering connection between the VPC and the on-premises network

    Why it's wrong here

    VPC peering does not support on-premises networks.

  • Create a Direct Connect Gateway and attach the VPC

    Why it's wrong here

    Direct Connect Gateway still requires BGP on the customer side.

  • Set up a VPN CloudHub with multiple VPN connections

    Why it's wrong here

    VPN CloudHub requires BGP for route exchange between multiple VPCs and on-premises networks, making it incompatible with a data center that lacks BGP support. This architecture is designed to hub-and-spoke several remote sites or VPCs into a central transit point. You would utilise this service when your primary requirement involves establishing a scalable mesh of site-to-site VPN connections across multiple geographically dispersed locations.

About these practice questions

Courseiva writes every ANS-C01 question from scratch — 1,621 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This ANS-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the ANS-C01 exam.