ANS-C01 Network Implementation Practice Question
A company has a Direct Connect connection with a public virtual interface (VIF) to access AWS public services. They want to ensure that all traffic to Amazon S3 from on-premises uses the Direct Connect connection instead of the internet. Which configuration is required?
⚠ Common exam trap
A common mix-up: candidates confuse public VIFs with private VIFs, assuming a private VIF is needed for any AWS service access, or they think a VPN or Direct Connect gateway is required to secure or direct S3 traffic, when in fact a public VIF with proper route filtering is the correct and simplest solution.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use the public virtual interface and configure a route filter to only accept routes for the S3 service.
A public virtual interface (VIF) provides direct connectivity to AWS public services, including Amazon S3, over the Direct Connect link. By default, the public VIF advertises a default route or specific AWS public prefixes; you must configure a route filter to accept only the S3 service prefixes (e.g., from the S3 service-specific prefix list) to ensure all S3 traffic uses the Direct Connect connection instead of the internet. This prevents any other public traffic from using the link and enforces the desired routing behavior.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Establish a VPN connection over the Direct Connect private VIF and route S3 traffic through the VPN.
Why it's wrong here
This adds unnecessary overhead and does not leverage the public VIF for direct access.
- ✓
Use the public virtual interface and configure a route filter to only accept routes for the S3 service.
Why this is correct
A public VIF provides access to AWS public services, and route filters can restrict which prefixes are advertised.
- ✗
Create a private virtual interface and attach it to the VPC.
Why it's wrong here
A private VIF provides connectivity to VPC private IP addresses, not AWS public services like S3.
- ✗
Create a Direct Connect gateway and associate the public VIF with it.
Why it's wrong here
Direct Connect gateway is for private VIFs to connect to multiple VPCs, not for public VIFs.
Visual reference
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
One of 1,621 original ANS-C01 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This ANS-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the ANS-C01 exam.