ANS-C01 Network Design Practice Question
Which TWO of the following are valid methods to connect a VPC to an on-premises network? (Choose 2.)
⚠ Common exam trap
It's easy for candidates to confuse internet-facing connectivity options (internet gateway, NAT gateway) with hybrid connectivity methods, or mistakenly think VPC peering can extend to on-premises networks, when it is strictly limited to inter-VPC communication within AWS.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
AWS Site-to-Site VPN
AWS Site-to-Site VPN creates an encrypted tunnel between a VPC and an on-premises network using IPsec. It uses a virtual private gateway or transit gateway on the AWS side and a customer gateway device on-premises, enabling secure communication over the public internet.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
AWS Site-to-Site VPN
Why this is correct
Valid method.
- ✗
Internet gateway
Why it's wrong here
Internet gateway provides internet access, not private connectivity.
- ✗
NAT gateway
Why it's wrong here
NAT gateway provides outbound internet for private subnets.
- ✗
VPC peering
Why it's wrong here
VPC peering connects VPCs, not on-premises.
- ✓
AWS Direct Connect
Why this is correct
Valid method.
Quick reference
VPN Protocol Comparison
| Protocol | Port | Encryption | Authentication | Use Case |
|---|---|---|---|---|
| IKEv2 / IPsec | UDP 500 / 4500 | AES-256 | Certificates / PSK | Site-to-site & remote access |
| SSL / TLS VPN | TCP 443 | TLS 1.3 | Certificates / MFA | Clientless remote access |
| L2TP / IPsec | UDP 1701 | AES (IPsec) | PSK / Certificates | Legacy remote access |
| WireGuard | UDP 51820 | ChaCha20 | Public keys | Modern high-performance VPN |
| PPTP | TCP 1723 | MPPE (weak) | MS-CHAPv2 | Legacy — avoid in production |
PPTP is considered insecure. IKEv2/IPsec and SSL VPN are the current recommended options.
Go deeper
Related to this question
About these practice questions
One of 1,621 original ANS-C01 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on ANS-C01
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. Which TWO options are valid methods to connect a VPC to an on-premises network? (Choose two.)
hard- ✓ A.AWS Site-to-Site VPN
- B.Internet Gateway
- ✓ C.AWS Direct Connect
- D.VPC endpoint
- E.VPC peering
Why A: AWS Site-to-Site VPN creates an encrypted tunnel between a virtual private gateway or transit gateway in your VPC and a customer gateway device in your on-premises network. It uses IPsec (IKEv1 or IKEv2) to secure traffic over the public internet, making it a valid and common method for hybrid connectivity.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This ANS-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the ANS-C01 exam.