ANS-C01 Network Security, Compliance and Governance Practice Question
A company has a hybrid network with an AWS Site-to-Site VPN connection to an on-premises data center. The network team wants to ensure that only encrypted traffic is sent over the internet between the two sites. The VPC has a virtual private gateway attached. When testing, they discover that some traffic is going over the internet without encryption. Which configuration change should be made to enforce encryption?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Add a static route in the VPC route table for the on-premises CIDR block pointing to the virtual private gateway.
Adding a static route in the VPC route table for the on-premises CIDR block pointing to the virtual private gateway ensures that all traffic destined for the on-premises network is routed through the VPN tunnel, enforcing encryption. Without this static route, traffic might be sent via an internet gateway if a more specific route exists or if route propagation is not properly configured. Option B is incorrect because disabling route propagation would remove dynamic routes from the VPN, but traffic could still go over the internet if there is a route to an internet gateway. Option C is incorrect because IPsec acceleration is about improving performance, not ensuring all traffic uses encryption; the tunnel already uses IPsec. Option D is incorrect because replacing the virtual private gateway with a transit gateway is not necessary; the issue is routing, not the gateway type.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Add a static route in the VPC route table for the on-premises CIDR block pointing to the virtual private gateway.
Why this is correct
A static route forces traffic destined for on-premises through the VPN tunnel, ensuring encryption.
- ✗
Disable route propagation on the VPC route table to remove any dynamic routes from the VPN.
Why it's wrong here
Disabling route propagation removes BGP-learned routes, but if there is a default route to an internet gateway, traffic may still go over the internet.
- ✗
Enable IPsec acceleration on the VPN tunnel to ensure all traffic is encrypted.
Why it's wrong here
IPsec acceleration improves throughput but does not enforce routing; traffic must still be routed through the VPN tunnel.
- ✗
Replace the virtual private gateway with a transit gateway and attach the VPN connection.
Why it's wrong here
A transit gateway is not required; the virtual private gateway can handle the VPN. The issue is routing, not the gateway type.
Visual reference
Quick reference
VPN Protocol Comparison
| Protocol | Port | Encryption | Authentication | Use Case |
|---|---|---|---|---|
| IKEv2 / IPsec | UDP 500 / 4500 | AES-256 | Certificates / PSK | Site-to-site & remote access |
| SSL / TLS VPN | TCP 443 | TLS 1.3 | Certificates / MFA | Clientless remote access |
| L2TP / IPsec | UDP 1701 | AES (IPsec) | PSK / Certificates | Legacy remote access |
| WireGuard | UDP 51820 | ChaCha20 | Public keys | Modern high-performance VPN |
| PPTP | TCP 1723 | MPPE (weak) | MS-CHAPv2 | Legacy — avoid in production |
PPTP is considered insecure. IKEv2/IPsec and SSL VPN are the current recommended options.
Go deeper
Related to this question
About these practice questions
Courseiva writes every ANS-C01 question from scratch — 1,621 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This ANS-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the ANS-C01 exam.