Courseiva
Network ImplementationeasyMultiple ChoiceObjective-mapped

ANS-C01 Network Implementation Practice Question

A company wants to use AWS Direct Connect to establish a dedicated network connection from their on-premises data center to AWS. They need to connect to a VPC in the us-east-1 region. Which of the following is a required step in the setup process?

⚠ Common exam trap

AWS often tests the misconception that a Transit Gateway is mandatory for Direct Connect, but the correct requirement is a Virtual Private Gateway attached to the VPC, not a Transit Gateway.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Create a private virtual interface and attach it to a Virtual Private Gateway.

To establish a Direct Connect connection to a VPC, you must create a private virtual interface (VIF) and attach it to a Virtual Private Gateway (VGW) that is attached to the VPC. The private VIF carries traffic over the dedicated connection and uses BGP to exchange routes between the on-premises network and the VPC via the VGW. This is the core requirement for routing traffic from the Direct Connect link into a VPC.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Attach a Transit Gateway to the VPC.

    Why it's wrong here

    Transit Gateway is not required for a single VPC connection.

  • Configure CloudFront to route traffic through the Direct Connect.

    Why it's wrong here

    CloudFront is a CDN service, not used for Direct Connect routing.

  • Create a site-to-site VPN connection as a backup.

    Why it's wrong here

    VPN backup is optional, not required.

  • Create a private virtual interface and attach it to a Virtual Private Gateway.

    Why this is correct

    This is the standard procedure for Direct Connect private VIF.

About these practice questions

One of 1,621 original ANS-C01 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on ANS-C01

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. A company is setting up a Direct Connect connection to AWS. They have a virtual private gateway (VGW) attached to their VPC. They need to establish a single logical connection over the Direct Connect link to access all subnets in the VPC. Which resource should they create on the Direct Connect virtual interface?

easy
  • A.A private virtual interface (VIF) with a BGP session to the VGW.
  • B.A hosted virtual interface (VIF) provided by an AWS Partner.
  • C.A public virtual interface (VIF) with a BGP session to the VGW.
  • D.A transit virtual interface (VIF) to the VGW.

Why A: A private virtual interface (VIF) is the correct resource because it allows you to connect your on-premises network directly to a VPC via a Direct Connect link. By associating the private VIF with a virtual private gateway (VGW) and establishing a BGP session, you create a single logical connection that provides Layer 3 access to all subnets in the VPC, as the VGW handles routing between the Direct Connect link and the VPC's route tables.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This ANS-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the ANS-C01 exam.