ANS-C01 Network Management and Operations Practice Question
A network engineer is configuring an AWS Site-to-Site VPN connection between a VPC and an on-premises network. The engineer creates a customer gateway, VPN connection, and virtual private gateway. The VPN tunnel status shows 'down'. Which configuration step is most likely missing?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Configure the on-premises router with the correct pre-shared key and tunnel IP addresses
The VPN tunnel status will remain down if the on-premises router is not configured with the correct pre-shared key and tunnel IP addresses as specified in the AWS VPN tunnel configuration. While attaching the VPN connection to the virtual private gateway (option A) is necessary, it is typically done during creation. Option B (enable route propagation) and option C (add static route) are related to routing, not tunnel establishment. Therefore, the most likely missing step is configuring the on-premises router.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Attach the VPN connection to the virtual private gateway
Why it's wrong here
This is already done when creating the VPN connection.
- ✗
Enable route propagation on the virtual private gateway
Why it's wrong here
Route propagation is for routing, not tunnel establishment.
- ✗
Add a static route to the VPN connection in the route table
Why it's wrong here
Not required for tunnel status.
- ✓
Configure the on-premises router with the correct pre-shared key and tunnel IP addresses
Why this is correct
The on-premises device must have matching parameters.
Visual reference
Go deeper
Related to this question
About these practice questions
Courseiva writes every ANS-C01 question from scratch — 1,621 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on ANS-C01
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. A network engineer is setting up a site-to-site VPN connection between an on-premises network and AWS. After configuring the customer gateway, virtual private gateway, and VPN tunnel, the tunnel status shows 'DOWN'. Which step should the engineer take FIRST to troubleshoot?
easy- A.Verify that route propagation is enabled on the VPC route table
- B.Enable detailed CloudWatch metrics on the VPN connection
- C.Test connectivity by pinging an EC2 instance in the VPC
- ✓ D.Check the on-premises VPN device configuration for mismatched parameters
Why D: The first troubleshooting step when a VPN tunnel is down is to check the on-premises VPN device configuration for mismatched parameters (e.g., pre-shared keys, encryption algorithms, etc.). Option A is incorrect because route propagation is relevant only after the tunnel is up; it does not cause the tunnel to be down. Option B is incorrect because CloudWatch metrics provide monitoring after the tunnel is established, not initial troubleshooting. Option C is incorrect because pinging an EC2 instance requires the tunnel to be up; it will fail if the tunnel is down.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This ANS-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the ANS-C01 exam.