SCS-C02 Infrastructure Security Practice Question
Which THREE components are required to set up a client VPN for remote access to a VPC? (Choose 3.)
⚠ Common exam trap
Many exam-takers confuse the components required for a site-to-site VPN (Virtual Private Gateway and Customer Gateway) with those needed for a client-based VPN, leading candidates to incorrectly select B or C instead of the correct client VPN-specific components.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Client VPN endpoint
A Client VPN endpoint is required as the entry point for remote clients to connect to the VPC. It manages authentication, encryption (using TLS 1.2), and routing for client connections. Without this component, there is no VPN server to accept and authenticate client traffic.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Client VPN endpoint
Why this is correct
The Client VPN endpoint is the central AWS server component that clients connect to; it is configured with a server certificate, authentication methods (such as mutual TLS, SAML, or Active Directory), and connection parameters like client CIDR ranges and DNS settings. It serves as the termination point for TLS-based VPN sessions and is a required component because without it, there is nothing for remote clients to establish a tunnel with. All other components (like target network associations and authorization rules) are configured on this endpoint.
- ✗
Virtual Private Gateway
Why it's wrong here
A Virtual Private Gateway (VGW) is the AWS-side router used for Site-to-Site VPN connections, attaching to a VPC and terminating IPsec tunnels from a Customer Gateway. Client VPN does not use a VGW because it is a client-to-site VPN over TLS, not a site-to-site IPsec VPN. Thus, a VGW is not part of the three required components for a Client VPN setup.
- ✗
Customer Gateway
Why it's wrong here
A Customer Gateway is a resource used exclusively for AWS Site-to-Site VPN, representing the on-premises router or device on the other end of a static IPsec tunnel. Client VPN does not involve any on-premises gateway because clients are individual remote users connecting from arbitrary IP addresses. Therefore, a Customer Gateway is not one of the three required components for a Client VPN setup.
- ✓
Authorization rule
Why this is correct
An authorization rule is a mandatory component that defines which specific IAM users or groups are allowed to access which destination networks (CIDR ranges) through the Client VPN endpoint. Each rule maps a user or group to a target network CIDR, and if no rule exists, all traffic is denied even if the client successfully authenticates. This fine-grained control is what makes the VPN secure and is required for any actual traffic to flow.
- ✓
Target network association
Why this is correct
A target network association is a required configuration step for an AWS Client VPN endpoint: you must associate the endpoint with at least one VPC subnet so that the VPN has a network path into the VPC. This association creates an elastic network interface in the specified subnet, enabling the VPN endpoint to route traffic and enforce authorization rules. Without it, the endpoint exists but cannot reach any resources, so it is essential.
Go deeper
Related to this question
About these practice questions
This SCS-C02 question is part of Courseiva's 1,205-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.