Courseiva
Network ImplementationmediumMultiple ChoiceObjective-mapped

ANS-C01 Network Implementation Practice Question

A company has set up a site-to-site VPN connection between its on-premises network and AWS. The tunnel status shows 'UP' on both sides, but traffic from on-premises cannot reach EC2 instances in the VPC. What is the most likely cause?

⚠ Common exam trap

The trap here is that candidates see 'tunnel status UP' and assume routing is automatically configured, but AWS requires explicit route table entries for the VPC to forward traffic to the VGW, and the exam tests this separation of control plane (tunnel) and data plane (routing).

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

The VPC route tables do not have a route pointing to the virtual private gateway for the on-premises CIDR.

The most likely cause is that the VPC route tables lack a route pointing to the virtual private gateway (VGW) for the on-premises CIDR. Even though the VPN tunnel is UP (indicating Phase 1 and Phase 2 IPsec SAs are established), traffic from on-premises cannot reach EC2 instances if the VPC does not know how to forward return traffic back through the VGW. Without this route, the VPC drops inbound packets or sends them to the internet gateway instead of the VPN tunnel.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • The pre-shared keys are mismatched.

    Why it's wrong here

    A pre-shared key mismatch would prevent the tunnel from establishing.

  • The VPC route tables do not have a route pointing to the virtual private gateway for the on-premises CIDR.

    Why this is correct

    Without a route to the virtual private gateway, traffic from the VPC to on-premises will not be forwarded.

  • The VPN tunnel has been idle for too long and needs to be re-initiated.

    Why it's wrong here

    The tunnel status shows 'UP', so it is not idle.

  • The security group associated with the EC2 instances does not allow inbound traffic from the VPN gateway.

    Why it's wrong here

    Security groups are stateful and evaluate inbound rules; however, the primary issue is likely routing.

Visual reference

192.168.1.0 /24 256 addresses (254 usable) 192.168.1.0 /25 Subnet A 128 addr (126 usable) 192.168.1.128 /25 Subnet B 128 addr (126 usable) Borrowing 1 bit from host portion creates 2 subnets (/25)

Quick reference

VPN Protocol Comparison

ProtocolPortEncryptionAuthenticationUse Case
IKEv2 / IPsecUDP 500 / 4500AES-256Certificates / PSKSite-to-site & remote access
SSL / TLS VPNTCP 443TLS 1.3Certificates / MFAClientless remote access
L2TP / IPsecUDP 1701AES (IPsec)PSK / CertificatesLegacy remote access
WireGuardUDP 51820ChaCha20Public keysModern high-performance VPN
PPTPTCP 1723MPPE (weak)MS-CHAPv2Legacy — avoid in production

PPTP is considered insecure. IKEv2/IPsec and SSL VPN are the current recommended options.

About these practice questions

One of 1,621 original ANS-C01 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This ANS-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the ANS-C01 exam.