ANS-C01 Network Management and Operations Practice Question
A company has a Direct Connect connection with a private VIF and a public VIF. The private VIF is used to access VPC resources, and the public VIF is used to access AWS public services. Recently, the company enabled AWS Global Accelerator for its application. The network team notices that traffic to the application via Global Accelerator is not using the Direct Connect connection but is going over the internet. What should the team do to ensure traffic uses the Direct Connect public VIF?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Configure a VPN connection over the Direct Connect public VIF to route Global Accelerator traffic
Global Accelerator uses static anycast IP addresses that are not directly reachable over a Direct Connect public VIF. The public VIF provides access to AWS public services via the Direct Connect connection, but Global Accelerator IPs are not advertised over the BGP session. To route on-premises traffic to Global Accelerator through Direct Connect, you must establish a VPN connection over the public VIF. This VPN tunnel encapsulates the traffic and sends it over the Direct Connect link, ensuring it does not traverse the public internet. Option B is incorrect because you cannot advertise Global Accelerator IPs from your on-premises router; they are owned and advertised by AWS. Option C is incorrect because a Direct Connect gateway is used for private VIFs and does not integrate with Global Accelerator. Option D is incorrect because a private VIF is for accessing VPC resources, not public services like Global Accelerator.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Configure a VPN connection over the Direct Connect public VIF to route Global Accelerator traffic
Why this is correct
Use a VPN over the public VIF to control routing, but Global Accelerator traffic typically goes over internet; however, using a VPN can force traffic via Direct Connect.
- ✗
Advertise the Global Accelerator IP addresses on the on-premises router to route traffic via the public VIF
Why it's wrong here
Global Accelerator IPs are not advertisable via BGP; they are anycast.
- ✗
Attach a Direct Connect gateway to the Global Accelerator
Why it's wrong here
Global Accelerator does not integrate with Direct Connect gateway.
- ✗
Create a private VIF for Global Accelerator traffic
Why it's wrong here
Private VIF is for VPC, not public services.
Go deeper
Related to this question
About these practice questions
One of 1,621 original ANS-C01 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This ANS-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the ANS-C01 exam.