Courseiva
Network Management and OperationsmediumMultiple ChoiceObjective-mapped

ANS-C01 Network Management and Operations Practice Question

A company uses AWS Transit Gateway to connect multiple VPCs and on-premises data centers. The network team notices that traffic between two VPCs is taking an unexpected path through the on-premises network instead of staying within the Transit Gateway. What is the most likely cause?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

The on-premises network is advertising more specific routes via BGP that override the Transit Gateway routes.

When using AWS Transit Gateway with VPN or Direct Connect, the on-premises network can advertise more specific BGP routes that override the default routes learned from the Transit Gateway. This causes traffic to take the path through the on-premises network instead of staying within the Transit Gateway. Option A is wrong because route tables are associated with the Transit Gateway attachments, not the VPCs themselves. Option B is wrong because the subnet route tables must point to the Transit Gateway for traffic to be routed correctly, but that would not cause traffic to go on-premises; rather, it would prevent traffic from reaching the Transit Gateway. Option D is wrong because VPC peering is not used with Transit Gateway in this scenario; conflicting routes could occur but the most likely cause is more specific BGP routes from on-premises.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • The Transit Gateway route table is not associated with the VPC attachments.

    Why it's wrong here

    Route tables are associated with attachments, but missing association would cause no connectivity, not suboptimal routing.

  • The VPC subnet route tables are not pointing to the Transit Gateway as the target.

    Why it's wrong here

    Subnet routing is separate; traffic still reaches Transit Gateway, but the issue is within Transit Gateway routing.

  • The on-premises network is advertising more specific routes via BGP that override the Transit Gateway routes.

    Why this is correct

    BGP routes from on-premises can be more specific and take precedence, causing traffic to be sent on-premises.

  • VPC peering connections are being used alongside Transit Gateway, creating conflicting routes.

    Why it's wrong here

    VPC peering is separate and would not cause Transit Gateway to route traffic on-premises.

Visual reference

192.168.1.0 /24 256 addresses (254 usable) 192.168.1.0 /25 Subnet A 128 addr (126 usable) 192.168.1.128 /25 Subnet B 128 addr (126 usable) Borrowing 1 bit from host portion creates 2 subnets (/25)

About these practice questions

Courseiva writes every ANS-C01 question from scratch — 1,621 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This ANS-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the ANS-C01 exam.