Courseiva

SOA-C02 Networking and Content Delivery Practice Question

A company uses AWS Direct Connect to connect its on-premises data center to AWS. The data center has multiple VLANs that need to connect to separate VPCs in AWS. The company wants to maintain isolation between the VPCs while maximizing bandwidth utilization. Which solution should the SysOps administrator recommend?

⚠ Common exam trap

Candidates often assume multiple VPCs require multiple Direct Connect connections, but AWS allows multiple private virtual interfaces on a single connection, each with its own VLAN ID, to achieve isolation and maximize bandwidth utilization.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Configure a single Direct Connect connection with multiple private virtual interfaces, each tagged with a different VLAN ID and associated with a different VPC.

A single Direct Connect connection can support multiple private virtual interfaces (VIFs), each tagged with a unique 802.1Q VLAN ID. This allows the on-premises data center to connect to separate VPCs while maintaining traffic isolation via VLAN tagging, and it maximizes bandwidth utilization by sharing the single connection's capacity across all VIFs.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Use AWS Transit Gateway to connect all VPCs and the Direct Connect gateway, then configure route tables to isolate traffic.

    Why it's wrong here

    AWS Transit Gateway operates at Layer 3 and does not provide 802.1Q VLAN tagging or the ability to multiplex multiple private VIFs over a single Direct Connect connection. To use Transit Gateway with Direct Connect, you would instead create a single transit VIF to the Direct Connect gateway and attach the gateway to the Transit Gateway, which then requires VPC attachments and route table configuration. This approach does not satisfy the requirement of using VLAN-tagged private virtual interfaces for per-VPC isolation, and it adds unnecessary complexity while still consuming only one VIF on the connection.

  • ✓

    Configure a single Direct Connect connection with multiple private virtual interfaces, each tagged with a different VLAN ID and associated with a different VPC.

    Why this is correct

    A single AWS Direct Connect connection supports multiple private virtual interfaces, each configured with a unique 802.1Q VLAN tag on the customer router and a distinct BGP session. Each private VIF is associated with a separate Virtual Private Gateway or through a Direct Connect Gateway, enabling isolated, dedicated connectivity to a specific VPC over the same physical fiber. This design maximizes bandwidth utilization by sharing the underlying port while maintaining Layer 2 isolation between VPCs, and it is the standard, cost-effective way to connect one on-premises network to multiple VPCs.

  • ✗

    Provision multiple Direct Connect connections, one for each VPC, and use a different VLAN on each connection.

    Why it's wrong here

    Provisioning a separate Direct Connect connection for each VPC multiplies the cost of physical ports, cross-connects, and monthly port hours without any technical benefit, because a single connection can carry multiple private VIFs. Additionally, VLAN tagging is meaningful only when multiple VIFs share one physical connection; using a different VLAN on separate connections does not improve isolation or performance, as each connection is already independent. This over-provisioning contradicts the principle of maximizing bandwidth utilization and is unnecessary for connecting multiple VPCs.

  • ✗

    Establish a single Direct Connect connection and use IPsec VPN tunnels over it to connect to each VPC.

    Why it's wrong here

    Using IPsec VPN tunnels over a single Direct Connect connection would introduce encryption overhead, thereby reducing the effective bandwidth available and failing to maximise bandwidth utilisation as required by the scenario. This approach is typically employed when an organisation has strict compliance requirements for end-to-end encryption of all traffic, even over a dedicated private link, prioritising data confidentiality over raw throughput. It provides an additional layer of security for sensitive data in transit.

Visual reference

Switch VLAN 10 Sales (192.168.10.0/24) PC-A PC-B VLAN 20 HR (192.168.20.0/24) PC-C PC-D Router VLANs isolate traffic — inter-VLAN routing requires a Layer 3 device

About these practice questions

One of 1,169 original SOA-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SOA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SOA-C02 exam.