Courseiva
Network Management and OperationshardMultiple ChoiceObjective-mapped

ANS-C01 Network Management and Operations Practice Question

A company has a Direct Connect connection with a private VIF and a public VIF. The private VIF is used to access VPC resources, and the public VIF is used to access AWS public services. Recently, the company enabled AWS Global Accelerator for its application. The network team notices that traffic to the application via Global Accelerator is not using the Direct Connect connection but is going over the internet. What should the team do to ensure traffic uses the Direct Connect public VIF?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Configure a VPN connection over the Direct Connect public VIF to route Global Accelerator traffic

Global Accelerator uses static anycast IP addresses that are not directly reachable over a Direct Connect public VIF. The public VIF provides access to AWS public services via the Direct Connect connection, but Global Accelerator IPs are not advertised over the BGP session. To route on-premises traffic to Global Accelerator through Direct Connect, you must establish a VPN connection over the public VIF. This VPN tunnel encapsulates the traffic and sends it over the Direct Connect link, ensuring it does not traverse the public internet. Option B is incorrect because you cannot advertise Global Accelerator IPs from your on-premises router; they are owned and advertised by AWS. Option C is incorrect because a Direct Connect gateway is used for private VIFs and does not integrate with Global Accelerator. Option D is incorrect because a private VIF is for accessing VPC resources, not public services like Global Accelerator.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Configure a VPN connection over the Direct Connect public VIF to route Global Accelerator traffic

    Why this is correct

    Use a VPN over the public VIF to control routing, but Global Accelerator traffic typically goes over internet; however, using a VPN can force traffic via Direct Connect.

  • Advertise the Global Accelerator IP addresses on the on-premises router to route traffic via the public VIF

    Why it's wrong here

    Global Accelerator IPs are not advertisable via BGP; they are anycast.

  • Attach a Direct Connect gateway to the Global Accelerator

    Why it's wrong here

    Global Accelerator does not integrate with Direct Connect gateway.

  • Create a private VIF for Global Accelerator traffic

    Why it's wrong here

    Private VIF is for VPC, not public services.

About these practice questions

One of 1,621 original ANS-C01 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This ANS-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the ANS-C01 exam.