Courseiva
Network Management and OperationsmediumMultiple SelectObjective-mapped

ANS-C01 Network Management and Operations Practice Question

A company is designing a multi-VPC architecture using AWS Transit Gateway. They need to ensure that traffic between VPCs is encrypted and that only specific VPCs can communicate with each other. Which two services should they use together? (Choose TWO.)

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

AWS Transit Gateway

AWS Transit Gateway provides transitive routing between VPCs, enabling scalable connectivity. AWS Network Firewall provides centralized stateful inspection and filtering of traffic between VPCs, allowing you to enforce policies that require traffic to be encrypted (e.g., by blocking non-encrypted flows). While Network Firewall itself does not perform encryption, it can inspect and drop unencrypted traffic to meet encryption requirements.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • AWS PrivateLink

    Why it's wrong here

    AWS PrivateLink is used for private connectivity to services, not for inter-VPC routing or encryption.

  • AWS Direct Connect

    Why it's wrong here

    AWS Direct Connect is a dedicated network connection from on-premises to AWS, not for VPC-to-VPC encryption.

  • AWS Transit Gateway

    Why this is correct

    AWS Transit Gateway provides transitive routing between VPCs, forming the connectivity backbone.

  • AWS VPN CloudHub

    Why it's wrong here

    AWS VPN CloudHub is used for VPN connectivity between remote sites, not for VPC-to-VPC encryption.

  • AWS Network Firewall

    Why this is correct

    AWS Network Firewall can inspect and filter traffic between VPCs, but does not perform encryption; it can drop unencrypted traffic to enforce encryption policies.

Visual reference

Source Router + ACL permit 10.0.0.0/8 deny any Server 10.0.0.5 ✓ 192.168.1.1 ✗ dropped ACLs evaluate top-down; first match wins — implicit deny all at end

About these practice questions

Courseiva writes every ANS-C01 question from scratch — 1,621 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This ANS-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the ANS-C01 exam.