Courseiva
Network Management and OperationshardMultiple ChoiceObjective-mapped

ANS-C01 Network Management and Operations Practice Question

A company is using AWS Client VPN for remote access. Users can authenticate and establish a VPN connection, but they cannot access resources in the VPC. The Client VPN endpoint is associated with a subnet in the VPC. The security group for the Client VPN endpoint allows all traffic. What is the most likely cause?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

There is no authorization rule to allow access to the VPC CIDR.

AWS Client VPN requires an authorization rule to specify which networks clients can access. Without an authorization rule allowing access to the VPC CIDR, traffic from clients is dropped even if the security group allows all traffic. The endpoint is associated with a subnet, so option B is incorrect. The subnet's route table automatically has a route for the VPC CIDR locally, so option C is incorrect. Since users can authenticate and establish a connection, the server certificate is valid, making option D incorrect.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • There is no authorization rule to allow access to the VPC CIDR.

    Why this is correct

    Authorization rules define which networks VPN clients can access; without it, traffic is blocked.

  • The Client VPN endpoint is not associated with the correct subnet.

    Why it's wrong here

    If associated with an incorrect subnet, clients may not get IP addresses, but the connection would likely fail.

  • The route table for the subnet does not have a route to the Client VPN endpoint.

    Why it's wrong here

    The endpoint is in the subnet; the route is auto-added by the endpoint association.

  • The Client VPN endpoint's server certificate is expired.

    Why it's wrong here

    An expired certificate would prevent the connection from establishing.

Visual reference

192.168.1.0 /24 256 addresses (254 usable) 192.168.1.0 /25 Subnet A 128 addr (126 usable) 192.168.1.128 /25 Subnet B 128 addr (126 usable) Borrowing 1 bit from host portion creates 2 subnets (/25)

About these practice questions

One of 1,621 original ANS-C01 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

2 more ways this is tested on ANS-C01

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. A company uses AWS Client VPN to provide remote access to its corporate network. Users report that they can connect to the VPN but cannot reach resources in the VPC. The VPN is configured with mutual authentication and authorization rules. What should the network engineer verify first?

easy
  • A.The security group associated with the VPN endpoint allows inbound traffic from the client CIDR
  • B.The server certificate is valid and trusted by the client
  • C.The client CIDR range does not overlap with the VPC CIDR
  • D.The authorization rules grant access to the target network

Why D: AWS Client VPN uses authorization rules to control which groups of clients can access specific target networks (e.g., subnets in the VPC). Even if the VPN connection is established, without proper authorization rules granting access to the target network, traffic will not be forwarded to the VPC resources. Option A is incorrect because the security group associated with the VPN endpoint controls inbound traffic to the endpoint itself, not traffic between clients and VPC resources. Option B is incorrect because if the client can connect, the server certificate is valid and trusted. Option C is incorrect because while overlapping CIDR ranges can cause routing issues, the fact that the connection succeeds indicates that the client CIDR range is valid and does not overlap with the VPC CIDR.

Variation 2. A company is using AWS Client VPN to provide remote access to its VPC. Users report that they can connect but cannot access any resources. The VPN is configured with a security group that allows all traffic. What should the administrator check?

easy
  • A.The client VPN security group inbound rules
  • B.The client VPN endpoint certificate
  • C.The client VPN route table
  • D.The client VPN authorization rules

Why D: Client VPN uses an authorization rule to allow access to specific networks. Without an authorization rule, even if the security group allows traffic, the VPN will not forward traffic.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This ANS-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the ANS-C01 exam.