ANS-C01 Network Design Practice Question
A company needs to connect its on-premises data center to AWS using a dedicated, low-latency connection. Which AWS service should be used?
⚠ Common exam trap
Many exam-takers confuse AWS Site-to-Site VPN as a dedicated connection, but it is encrypted over the public internet and does not guarantee low latency or dedicated bandwidth, unlike Direct Connect.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
AWS Direct Connect
AWS Direct Connect is the correct choice because it provides a dedicated, private, low-latency network connection from an on-premises data center directly to AWS, bypassing the public internet. This service uses industry-standard 802.1Q VLANs to create virtual interfaces, ensuring consistent performance and reduced latency for mission-critical workloads.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
AWS Direct Connect
Why this is correct
Direct Connect provides a dedicated, low-latency connection from on-premises to AWS.
- ✗
AWS Transit Gateway
Why it's wrong here
Transit Gateway is for connecting VPCs and VPNs, not a direct dedicated connection.
- ✗
AWS Site-to-Site VPN
Why it's wrong here
AWS Site-to-Site VPN uses the public internet to establish encrypted tunnels, so it cannot provide the dedicated, low-latency connection the scenario demands; the correct service, AWS Direct Connect, delivers a private physical link that bypasses the internet entirely. This option is tempting because Site-to-Site VPN is the standard choice for secure, encrypted connectivity over the internet, and it would be correct if the requirement were for a cost-effective, encrypted link without the need for dedicated bandwidth or consistent latency.
- ✗
VPC Peering
Why it's wrong here
VPC Peering fails because it connects two VPCs within AWS, not an on-premises data centre to AWS. It cannot establish the required dedicated, low-latency connection from an on-premises location. This option is tempting as it provides private network connectivity, but it is specifically designed for connecting two separate Amazon VPCs to allow resources in each to communicate directly, making it suitable for inter-VPC communication scenarios within the AWS cloud, such as shared services across accounts.
Visual reference
Go deeper
Related to this question
About these practice questions
One of 1,621 original ANS-C01 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This ANS-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the ANS-C01 exam.