ANS-C01 Network Design Practice Question
A company has multiple VPCs connected via AWS Transit Gateway. One VPC contains a shared services endpoint (e.g., Amazon S3) using a VPC Gateway Endpoint. How can other VPCs access this endpoint?
⚠ Common exam trap
Many exam-takers assume Transit Gateway can route traffic to a Gateway Endpoint in another VPC, but Gateway Endpoints are not transitive and cannot be used as a target in Transit Gateway route tables, requiring each VPC to have its own endpoint.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create Gateway Endpoints in each VPC that needs access
A VPC Gateway Endpoint is a regional service that uses route table entries to direct traffic to AWS services like S3 or DynamoDB without leaving the AWS network. Since Gateway Endpoints are not transitive across VPCs, each VPC that needs to access the shared S3 endpoint must have its own Gateway Endpoint created in that VPC, with the appropriate route table entries pointing to the endpoint. The Transit Gateway does not propagate Gateway Endpoint routes, so other VPCs cannot reach the endpoint through the Transit Gateway alone.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Create Gateway Endpoints in each VPC that needs access
Why this is correct
Each VPC must have its own Gateway Endpoint for S3.
- ✗
Use AWS PrivateLink to access the S3 endpoint
Why it's wrong here
PrivateLink is for Interface Endpoints, not Gateway Endpoints.
- ✗
Configure Direct Connect to access the endpoint
Why it's wrong here
Direct Connect does not help with Gateway Endpoint access.
- ✗
Create a route in Transit Gateway pointing to the endpoint
Why it's wrong here
Transit Gateway cannot route to Gateway Endpoints.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
One of 1,621 original ANS-C01 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This ANS-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the ANS-C01 exam.