How to Control Which VPCs Can Communicate Using Transit Gateway Route Tables
A company is setting up AWS Transit Gateway with multiple VPC attachments and an AWS Direct Connect Gateway. The company wants to control which VPCs can communicate with each other and with the on-premises network. Which TWO actions should the company take to implement this?
Quick Answer
The answer is to create separate Transit Gateway route tables for different groups of VPCs. This is correct because Transit Gateway route tables control traffic between VPCs and on-premises networks by defining which attachments can route to each other; isolating VPCs into distinct route tables prevents unwanted inter-VPC communication while allowing selective connectivity through the Direct Connect Gateway association. On the AWS Certified Advanced Networking Specialty ANS-C01 exam, this concept tests your understanding of how route tables act as the central policy engine for traffic flow, with a common trap being to confuse VPC peering or Security Groups as the control mechanism—remember that Transit Gateway uses route tables, not security groups, for inter-VPC routing. A key memory tip is to think of each Transit Gateway route table as a separate "room" in a building, where only attachments in the same room can see each other unless you add a specific route to another room.
⚠ Common exam trap
The ANS-C01 exam often tests the misconception that security groups can be used to filter traffic between VPCs at the Transit Gateway level, but security groups only apply to individual EC2 instances or ENIs, not to network transit paths like Transit Gateway attachments.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Associate the Direct Connect Gateway with the Transit Gateway.
To route traffic from on-premises networks through AWS Direct Connect to VPCs attached to a Transit Gateway, the Direct Connect Gateway must be associated with the Transit Gateway. This association creates a dedicated attachment that enables the Transit Gateway to exchange routes with the Direct Connect Gateway, allowing seamless connectivity between on-premises and VPC resources.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Associate the Direct Connect Gateway with the Transit Gateway.
Why this is correct
This enables on-premises connectivity through the transit gateway.
- ✗
Establish VPC peering connections between VPCs that need to communicate.
Why it's wrong here
Transit Gateway replaces the need for VPC peering.
- ✗
Use security groups to control traffic between VPCs.
Why it's wrong here
Security groups are instance-level and not used for inter-VPC traffic control in Transit Gateway.
- ✗
Configure Transit Gateway peering attachments for inter-region connectivity.
Why it's wrong here
The question does not mention inter-region; intra-region connectivity is handled by the transit gateway itself.
- ✓
Create separate Transit Gateway route tables for different groups of VPCs.
Why this is correct
Route tables enable segmentation and control of traffic flow.
Go deeper
Related to this question
About these practice questions
This ANS-C01 question is part of Courseiva's 1,621-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on ANS-C01
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. A company has set up a transit gateway with attachments to VPC-A and VPC-B. The transit gateway route table shows routes to both VPCs and a blackhole for 0.0.0.0/0. VPC-A's public subnet route table sends 10.1.0.0/16 traffic to the transit gateway. However, an EC2 instance in VPC-A's public subnet cannot reach an instance in VPC-B. What is the most likely cause?
medium- ✓ A.VPC-B's route table does not have a route to VPC-A's CIDR via the transit gateway.
- B.VPC-A's route table does not have a route to the transit gateway.
- C.The transit gateway route table does not have a route for 10.0.0.0/16.
- D.The blackhole route in the transit gateway is blocking traffic between VPCs.
Why A: For traffic to flow from VPC-A to VPC-B via a transit gateway, both VPCs must have routes in their route tables pointing to the transit gateway for the other VPC's CIDR. Since VPC-A's route table sends 10.1.0.0/16 (VPC-B's CIDR) to the transit gateway, but VPC-B's route table lacks a return route to VPC-A's CIDR via the transit gateway, the return traffic from VPC-B is dropped, causing connectivity failure.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This ANS-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the ANS-C01 exam.