Courseiva
Network Security, Compliance and GovernancehardMultiple ChoiceObjective-mapped

ANS-C01 Network Security, Compliance and Governance Practice Question

A company is using AWS Client VPN for remote access. They want to ensure that only clients with a valid client certificate can connect, and that traffic is routed through a centralized inspection VPC. The VPN endpoint is configured with mutual authentication using server and client certificates. The route table in the VPN VPC has a default route pointing to an AWS Network Firewall endpoint in the inspection VPC. Users report that they can connect to the VPN but cannot access any internal resources. The network engineer checks the Client VPN endpoint configuration and confirms that the authorization rules allow access to the internal CIDR (10.0.0.0/8). What is the most likely cause?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

The route table in the VPN VPC has a default route (0.0.0.0/0) pointing to the Network Firewall, but the Network Firewall's route table needs a route back to the VPN VPC for the client CIDR, which is missing.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • The route table in the VPN VPC has a default route (0.0.0.0/0) pointing to the Network Firewall, but the Network Firewall's route table needs a route back to the VPN VPC for the client CIDR, which is missing.

    Why this is correct

    For traffic to flow, the inspection VPC must have a route back to the VPN VPC for the client CIDR. If the Network Firewall's route table (or the inspection VPC's route table) does not have a route for the client CIDR pointing to the VPN VPC's attachment (e.g., Transit Gateway), return traffic is dropped.

  • The client certificate is not associated with the same CA as the server certificate, causing TLS handshake failure.

    Why it's wrong here

    If authentication failed, users would not be able to connect. The stem says users can connect, so TLS handshake is successful.

  • The subnet route table in the VPN VPC does not have a route for the client CIDR (assigned by the VPN) pointing to the VPN endpoint's network interface.

    Why it's wrong here

    The VPN endpoint automatically handles routing for the client CIDR. The route table in the VPN VPC needs a route for the client CIDR to the VPN endpoint's ENI, but this is typically added automatically. However, if missing, return traffic would not reach clients. But the issue is clients cannot access internal resources, not that they cannot receive responses.

  • The AWS Network Firewall in the inspection VPC is blocking traffic from the VPN client CIDR because it does not have a rule allowing it.

    Why it's wrong here

    The Network Firewall might be blocking traffic, but the stem says centralized inspection VPC. However, the most common issue is that the route table in the VPN VPC is not sending traffic to the Network Firewall correctly.

Visual reference

192.168.1.0 /24 256 addresses (254 usable) 192.168.1.0 /25 Subnet A 128 addr (126 usable) 192.168.1.128 /25 Subnet B 128 addr (126 usable) Borrowing 1 bit from host portion creates 2 subnets (/25)

About these practice questions

One of 1,621 original ANS-C01 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This ANS-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the ANS-C01 exam.