Courseiva
Network ImplementationmediumMultiple ChoiceObjective-mapped

ANS-C01 Network Implementation Practice Question

A company has a Direct Connect connection with a public virtual interface (VIF) to access AWS public services. They want to ensure that all traffic to Amazon S3 from on-premises uses the Direct Connect connection instead of the internet. Which configuration is required?

⚠ Common exam trap

A common mix-up: candidates confuse public VIFs with private VIFs, assuming a private VIF is needed for any AWS service access, or they think a VPN or Direct Connect gateway is required to secure or direct S3 traffic, when in fact a public VIF with proper route filtering is the correct and simplest solution.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Use the public virtual interface and configure a route filter to only accept routes for the S3 service.

A public virtual interface (VIF) provides direct connectivity to AWS public services, including Amazon S3, over the Direct Connect link. By default, the public VIF advertises a default route or specific AWS public prefixes; you must configure a route filter to accept only the S3 service prefixes (e.g., from the S3 service-specific prefix list) to ensure all S3 traffic uses the Direct Connect connection instead of the internet. This prevents any other public traffic from using the link and enforces the desired routing behavior.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Establish a VPN connection over the Direct Connect private VIF and route S3 traffic through the VPN.

    Why it's wrong here

    This adds unnecessary overhead and does not leverage the public VIF for direct access.

  • Use the public virtual interface and configure a route filter to only accept routes for the S3 service.

    Why this is correct

    A public VIF provides access to AWS public services, and route filters can restrict which prefixes are advertised.

  • Create a private virtual interface and attach it to the VPC.

    Why it's wrong here

    A private VIF provides connectivity to VPC private IP addresses, not AWS public services like S3.

  • Create a Direct Connect gateway and associate the public VIF with it.

    Why it's wrong here

    Direct Connect gateway is for private VIFs to connect to multiple VPCs, not for public VIFs.

Visual reference

Source Router + ACL permit 10.0.0.0/8 deny any Server 10.0.0.5 ✓ 192.168.1.1 ✗ dropped ACLs evaluate top-down; first match wins — implicit deny all at end

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

One of 1,621 original ANS-C01 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This ANS-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the ANS-C01 exam.