Courseiva
Infrastructure Security →hardMultiple Choice

SCS-C02 Infrastructure Security Practice Question

A company is designing a hybrid cloud architecture with an AWS Direct Connect connection. The company wants to ensure that traffic to and from the VPC goes through the Direct Connect connection and not over the internet. Which configuration should be used?

⚠ Common exam trap

Test-takers frequently confuse VPC Endpoints (which provide private access to AWS services) with the mechanism needed to route general VPC-to-on-premises traffic through Direct Connect, leading them to select Option A instead of understanding that a VGW and proper route table entries are required.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Attach a Virtual Private Gateway to the VPC and update the route tables to point to the Direct Connect virtual interface.

A Virtual Private Gateway (VGW) is the AWS-side anchor for an AWS Direct Connect private virtual interface (VIF). By attaching the VGW to the VPC and updating the VPC route tables to point the destination CIDR (e.g., the on-premises network) to the Direct Connect VIF, all traffic between the VPC and the on-premises network is forced through the Direct Connect link, bypassing the internet entirely.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Create a VPC Endpoint for each AWS service.

    Why it's wrong here

    VPC endpoints provide private connectivity only to AWS services (such as S3 or DynamoDB) from within the VPC, not to an on-premises data center. They do not alter the VPC route tables for traffic destined to on-premises CIDR blocks, nor do they involve a Virtual Private Gateway or Direct Connect. Therefore, they cannot force any hybrid traffic to traverse Direct Connect, so this option is incorrect.

  • ✗

    Set up a VPN connection over the internet as a backup.

    Why it's wrong here

    A VPN over the internet still uses the public internet as the underlying transport, and merely adding it as a backup does not prevent the VPC from sending traffic directly over the internet via an internet gateway. Without route table entries that force all on-premises-bound traffic through the VPN tunnel (or through Direct Connect when available), normal traffic can still egress over the public path. Even if the VPN is preferred, it is not the same as Direct Connect and does not guarantee that internet routing is disabled.

  • ✓

    Attach a Virtual Private Gateway to the VPC and update the route tables to point to the Direct Connect virtual interface.

    Why this is correct

    Forcing traffic through Direct Connect requires a Virtual Private Gateway (VGW) attached to the VPC and a private virtual interface (VIF) connecting the Direct Connect connection to that VGW. Once the VGW is attached, you update each subnet's route table with a static route pointing to the on-premises CIDR via the VGW, and you must also enable route propagation from the VGW so that routes are advertised. This ensures that any packet bound for the on-premises network is sent to the VGW and then over the Direct Connect private VIF, bypassing the internet entirely.

  • ✗

    Configure the Direct Connect connection and assign public IPs to instances.

    Why it's wrong here

    Assigning public IP addresses to instances actually encourages traffic to use the internet, because instances with public IPs can reach the internet through an internet gateway, and sources on the internet can route back to them over the public path. Direct Connect private virtual interfaces operate at the private IP layer and require a Virtual Private Gateway and route table entries; addresses must be private and non-overlapping with the VPC CIDR. This option does not establish a private path, does not change routing, and could actively cause traffic to traverse the internet, so it is incorrect.

Visual reference

192.168.1.0 /24 256 addresses (254 usable) 192.168.1.0 /25 Subnet A 128 addr (126 usable) 192.168.1.128 /25 Subnet B 128 addr (126 usable) Borrowing 1 bit from host portion creates 2 subnets (/25)

About these practice questions

One of 1,205 original SCS-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.