Courseiva
Network ImplementationhardMultiple ChoiceObjective-mapped

Transit Gateway with Direct Connect: Connect Multiple VPCs Using One Connection

A company has a Direct Connect connection with a private virtual interface (VIF) to a VPC. The on-premises network uses BGP to advertise routes to the VPC. The company wants to extend this connectivity to a second VPC in the same region without creating additional Direct Connect connections. Which solution should be used?

Quick Answer

The answer is to use a transit gateway and attach both VPCs and the Direct Connect private virtual interface. This is correct because a transit gateway acts as a central hub that can route traffic between multiple VPCs and an on-premises network over a single Direct Connect connection, eliminating the need for additional VIFs or VPN tunnels. On the AWS Certified Advanced Networking Specialty ANS-C01 exam, this scenario tests your understanding of how transit gateways simplify hybrid network architectures by consolidating connectivity, and it often appears as a trap where candidates mistakenly consider VPC peering—which cannot extend Direct Connect—or assume a second VIF is required. A common memory tip is to think of the transit gateway as a “network router in the cloud” that lets you attach many VPCs and one Direct Connect VIF to a single logical gateway, avoiding the complexity of multiple connections. Remember: one gateway, one VIF, many VPCs.

⚠ Common exam trap

The ANS-C01 exam often tests the misconception that a single Direct Connect private VIF can be directly associated with multiple VPCs, but in reality, a private VIF can only be associated with one VPC or one transit gateway, making the transit gateway the correct scaling solution.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Use a transit gateway and attach both VPCs and the Direct Connect private VIF.

A transit gateway allows you to centrally connect multiple VPCs and on-premises networks via a single Direct Connect private virtual interface. By attaching both VPCs and the Direct Connect private VIF to the transit gateway, the on-premises network can reach both VPCs without needing additional Direct Connect connections. This solution scales efficiently and supports transitive routing between all attached networks.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Create a second Direct Connect private VIF for the second VPC.

    Why it's wrong here

    Not needed; transit gateway can be used.

  • Set up a Site-to-Site VPN from the on-premises network to the second VPC.

    Why it's wrong here

    VPN adds complexity and cost.

  • Create a VPC peering connection between the two VPCs.

    Why it's wrong here

    VPC peering does not propagate Direct Connect routes.

  • Use a transit gateway and attach both VPCs and the Direct Connect private VIF.

    Why this is correct

    Transit gateway allows multiple VPCs to share Direct Connect.

About these practice questions

Courseiva writes every ANS-C01 question from scratch — 1,621 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

2 more ways this is tested on ANS-C01

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. A company has a Direct Connect connection with a private virtual interface to a VPC. They want to use the same Direct Connect connection to access another VPC in the same region. Which solution should they implement?

medium
  • A.Create a second private virtual interface to the second VPC.
  • B.Set up a Site-to-Site VPN over the Direct Connect connection to the second VPC.
  • C.Use a Transit Gateway and a transit virtual interface.
  • D.Order a second Direct Connect connection.

Why C: A Transit Gateway (TGW) allows you to attach multiple VPCs and a Direct Connect Gateway (DXGW) via a transit virtual interface (VIF). This enables a single Direct Connect connection to route traffic to multiple VPCs in the same region without additional physical connections or private VIFs. The TGW acts as a central hub, simplifying network architecture and reducing operational overhead.

Variation 2. A company has a Direct Connect connection with a private virtual interface (VIF) attached to a Virtual Private Gateway (VGW) that is associated with a single VPC (10.0.0.0/16). The on-premises network uses BGP to exchange routes. The company has recently acquired another company and needs to connect to their VPC (172.16.0.0/16) in the same region. They want to use the existing Direct Connect connection to access both VPCs. The network engineer creates a Transit Gateway, attaches both VPCs, and creates a transit virtual interface (VIF) to the Transit Gateway. The engineer also deletes the private VIF. However, after the change, on-premises users cannot reach either VPC. What should the engineer do to restore connectivity?

medium
  • A.Configure BGP on the on-premises router to peer with the Transit Gateway over the transit VIF.
  • B.Attach the VPCs to the Transit Gateway with different route tables.
  • C.Create a new private VIF to each VPC.
  • D.Enable route propagation on the Transit Gateway route tables.

Why A: When the private VIF was replaced with a transit VIF to the Transit Gateway, the on-premises router lost its BGP peering with the VGW. To restore connectivity, the on-premises router must be configured to establish BGP peering with the Transit Gateway over the transit VIF. This allows route exchange between on-premises and both VPCs attached to the Transit Gateway. Option A is correct. Option B is incorrect because attaching VPCs with different route tables is not the issue; the VPCs are already attached. Option C is incorrect because creating separate private VIFs would be unnecessary and defeats the purpose of using a Transit Gateway. Option D is incorrect because route propagation is already enabled by default when VPCs are attached to a Transit Gateway; the missing piece is the BGP session from on-premises.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This ANS-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the ANS-C01 exam.