Courseiva
Network DesigneasyMultiple ChoiceObjective-mapped

ANS-C01 Site-to-Site VPN Practice Question

A company wants to ensure that traffic between two VPCs in the same region is encrypted and does not traverse the public internet. Which solution meets these requirements?

⚠ Common exam trap

A common mistake is selecting VPC Peering because it provides a private connection, but it does not encrypt traffic. The question requires encryption, so VPC Peering alone is insufficient.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Establish an AWS Site-to-Site VPN connection between the VPCs [CORRECT]

A Site-to-Site VPN connection (Option D) is correct because it uses IPsec tunnels to encrypt traffic between VPCs, and the traffic stays within AWS's private network infrastructure, never traversing the public internet. VPC Peering (Option A) does not encrypt traffic; it only provides a private Layer 3 connection with no encryption. Transit Gateway (Option C) routes traffic but lacks built-in encryption without additional VPN attachments. VPC Endpoints (Option B) are used for accessing AWS services privately, not for inter-VPC routing.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Configure VPC Peering between the two VPCs

    Why it's wrong here

    VPC Peering provides a private connection but does not encrypt traffic, so it fails the encryption requirement.

  • Create VPC Endpoints in each VPC for the other VPC's CIDR

    Why it's wrong here

    Incorrect: VPC Endpoints are used to privately connect a VPC to supported AWS services, not for routing traffic between two VPCs.

  • Use an AWS Transit Gateway to route traffic between the VPCs

    Why it's wrong here

    Incorrect: Transit Gateway provides routing but does not natively encrypt traffic. To encrypt, you must attach VPN connections, which would be a separate solution.

  • Establish an AWS Site-to-Site VPN connection between the VPCs [CORRECT]

    Why this is correct

    A Site-to-Site VPN uses IPsec encryption and stays within AWS's private network, meeting both requirements.

Quick reference

VPN Protocol Comparison

ProtocolPortEncryptionAuthenticationUse Case
IKEv2 / IPsecUDP 500 / 4500AES-256Certificates / PSKSite-to-site & remote access
SSL / TLS VPNTCP 443TLS 1.3Certificates / MFAClientless remote access
L2TP / IPsecUDP 1701AES (IPsec)PSK / CertificatesLegacy remote access
WireGuardUDP 51820ChaCha20Public keysModern high-performance VPN
PPTPTCP 1723MPPE (weak)MS-CHAPv2Legacy — avoid in production

PPTP is considered insecure. IKEv2/IPsec and SSL VPN are the current recommended options.

About these practice questions

One of 1,621 original ANS-C01 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This ANS-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the ANS-C01 exam.