Courseiva
Network Management and OperationsmediumMultiple ChoiceObjective-mapped

ANS-C01 Network Management and Operations Practice Question

A company uses AWS Transit Gateway to connect multiple VPCs and on-premises networks. After adding a new VPC attachment, traffic from the on-premises network cannot reach the new VPC. The on-premises BGP route table shows the prefixes of the new VPC as received. What should the engineer check?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Verify that the new VPC attachment is associated with the Transit Gateway route table that has the on-premises routes.

For traffic from an on-premises network to reach a new VPC via Transit Gateway, the new VPC attachment must be associated with a Transit Gateway route table that contains a route (static or propagated) pointing to the on-premises network. Without this association, the Transit Gateway will not forward traffic to the new VPC even if the on-premises BGP route table has learned the VPC prefixes. Option A is incorrect because the on-premises router already receives the VPC prefixes via BGP, so advertising is not the issue. Option B is incorrect: the VPC's route table controls outbound traffic from the VPC, but inbound traffic from on-premises is governed by the Transit Gateway route table. Option D is irrelevant because DNS resolution does not affect IP routing.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Verify that the on-premises router is advertising the correct prefix to AWS.

    Why it's wrong here

    The on-premises has the routes, so this is not the issue.

  • Verify that the new VPC has a route to the Transit Gateway in its route table.

    Why it's wrong here

    The VPC needs a route to the TGW, but the issue is from on-premises to VPC.

  • Verify that the new VPC attachment is associated with the Transit Gateway route table that has the on-premises routes.

    Why this is correct

    Transit Gateway route tables control connectivity between attachments.

  • Verify that the new VPC's DNS resolution is enabled.

    Why it's wrong here

    DNS resolution is not related to routing.

Visual reference

Client Recursive Resolver Root DNS (13 root servers) TLD DNS (.com, .org, …) Authoritative example.com query IP addr answer

About these practice questions

This ANS-C01 question is part of Courseiva's 1,621-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This ANS-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the ANS-C01 exam.