Courseiva
Network DesignhardMultiple ChoiceObjective-mapped

ANS-C01 Local route precedence Practice Question

A company has a VPC with multiple subnets and an AWS Transit Gateway. They have a requirement to inspect traffic between subnets using a third-party firewall appliance that is deployed in a centralized inspection VPC. The firewall appliance must process all traffic between the VPC subnets, including traffic between subnets in the same Availability Zone. Which routing configuration achieves this?

⚠ Common exam trap

Candidates often assume that adding a route for the VPC CIDR to a Transit Gateway will override the implicit local route, but this is not possible. Intra-VPC traffic remains local.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

None of the options are correct.

None of the provided routing configurations can achieve this requirement because the local route for the VPC CIDR in any VPC route table cannot be overridden. Therefore, intra-VPC traffic will always use the local route and will not be sent to the Transit Gateway. To inspect traffic between subnets within the same VPC, alternative architectures such as a Gateway Load Balancer or a Transit Gateway with VPC peering between different VPCs must be used.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Create a VPC route table that routes all traffic (0.0.0.0/0) to the Transit Gateway.

    Why it's wrong here

    Routes 0.0.0.0/0 to the Transit Gateway, which only affects internet-bound traffic, not intra-VPC traffic. Does not inspect inter-subnet traffic.

  • Create a VPC route table that routes the VPC CIDR to the Transit Gateway and associate it with each subnet.

    Why it's wrong here

    Attempts to route the VPC CIDR to the Transit Gateway, but the local route takes precedence, so traffic stays within the VPC. This does not achieve inspection.

  • Use the main route table and add a route for the VPC CIDR to the Transit Gateway.

    Why it's wrong here

    Same as B but uses the main route table. The local route still overrides, so intra-VPC traffic is not inspected.

  • None of the options are correct.

    Why this is correct

    Same as B and C but associates custom route tables with each subnet. The local route still overrides, so intra-VPC traffic remains local.

Visual reference

192.168.1.0 /24 256 addresses (254 usable) 192.168.1.0 /25 Subnet A 128 addr (126 usable) 192.168.1.128 /25 Subnet B 128 addr (126 usable) Borrowing 1 bit from host portion creates 2 subnets (/25)

About these practice questions

Courseiva writes every ANS-C01 question from scratch — 1,621 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This ANS-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the ANS-C01 exam.