Courseiva
Network DesigneasyMultiple ChoiceObjective-mapped

ANS-C01 Network Design Practice Question

A company is using AWS Client VPN to allow remote employees to access resources in a VPC. The VPN is configured with a server certificate and mutual authentication. Some users report that they cannot connect to the VPN. What should the administrator check FIRST?

⚠ Common exam trap

AWS often tests the distinction between server-side and client-side authentication requirements in mutual TLS; the trap here is that candidates assume the issue is with the server certificate or network configuration, overlooking that each user must have a valid client certificate for mutual authentication to succeed.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Verify that each user has a valid client certificate installed on their device.

The question states that mutual authentication is configured, which requires both a server certificate and a valid client certificate on each user's device. Since some users cannot connect while others presumably can, the most likely issue is that the affected users lack a valid client certificate. The administrator should first verify that each user has a valid client certificate installed, as this is a common point of failure in mutual TLS authentication.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Check the security group associated with the VPN endpoint.

    Why it's wrong here

    Security groups control traffic post-connection.

  • Verify that the server certificate is uploaded to AWS Certificate Manager (ACM).

    Why it's wrong here

    Server certificate is needed, but if missing, no one can connect. The issue is specific to some users.

  • Confirm that the VPN endpoint is associated with all subnets in the VPC.

    Why it's wrong here

    Association affects routing, not authentication.

  • Verify that each user has a valid client certificate installed on their device.

    Why this is correct

    Correct: Mutual authentication requires client certificates.

About these practice questions

Courseiva writes every ANS-C01 question from scratch — 1,621 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This ANS-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the ANS-C01 exam.