Courseiva
Network Security, Compliance and GovernancehardMultiple ChoiceObjective-mapped

ANS-C01 Network Security, Compliance and Governance Practice Question

A company has a hybrid network with an AWS Site-to-Site VPN connection to an on-premises data center. The network team wants to ensure that only encrypted traffic is sent over the internet between the two sites. The VPC has a virtual private gateway attached. When testing, they discover that some traffic is going over the internet without encryption. Which configuration change should be made to enforce encryption?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Add a static route in the VPC route table for the on-premises CIDR block pointing to the virtual private gateway.

Adding a static route in the VPC route table for the on-premises CIDR block pointing to the virtual private gateway ensures that all traffic destined for the on-premises network is routed through the VPN tunnel, enforcing encryption. Without this static route, traffic might be sent via an internet gateway if a more specific route exists or if route propagation is not properly configured. Option B is incorrect because disabling route propagation would remove dynamic routes from the VPN, but traffic could still go over the internet if there is a route to an internet gateway. Option C is incorrect because IPsec acceleration is about improving performance, not ensuring all traffic uses encryption; the tunnel already uses IPsec. Option D is incorrect because replacing the virtual private gateway with a transit gateway is not necessary; the issue is routing, not the gateway type.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Add a static route in the VPC route table for the on-premises CIDR block pointing to the virtual private gateway.

    Why this is correct

    A static route forces traffic destined for on-premises through the VPN tunnel, ensuring encryption.

  • Disable route propagation on the VPC route table to remove any dynamic routes from the VPN.

    Why it's wrong here

    Disabling route propagation removes BGP-learned routes, but if there is a default route to an internet gateway, traffic may still go over the internet.

  • Enable IPsec acceleration on the VPN tunnel to ensure all traffic is encrypted.

    Why it's wrong here

    IPsec acceleration improves throughput but does not enforce routing; traffic must still be routed through the VPN tunnel.

  • Replace the virtual private gateway with a transit gateway and attach the VPN connection.

    Why it's wrong here

    A transit gateway is not required; the virtual private gateway can handle the VPN. The issue is routing, not the gateway type.

Visual reference

192.168.1.0 /24 256 addresses (254 usable) 192.168.1.0 /25 Subnet A 128 addr (126 usable) 192.168.1.128 /25 Subnet B 128 addr (126 usable) Borrowing 1 bit from host portion creates 2 subnets (/25)

Quick reference

VPN Protocol Comparison

ProtocolPortEncryptionAuthenticationUse Case
IKEv2 / IPsecUDP 500 / 4500AES-256Certificates / PSKSite-to-site & remote access
SSL / TLS VPNTCP 443TLS 1.3Certificates / MFAClientless remote access
L2TP / IPsecUDP 1701AES (IPsec)PSK / CertificatesLegacy remote access
WireGuardUDP 51820ChaCha20Public keysModern high-performance VPN
PPTPTCP 1723MPPE (weak)MS-CHAPv2Legacy — avoid in production

PPTP is considered insecure. IKEv2/IPsec and SSL VPN are the current recommended options.

About these practice questions

Courseiva writes every ANS-C01 question from scratch — 1,621 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This ANS-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the ANS-C01 exam.