SOA-C02 Networking and Content Delivery Practice Question
A company has two Amazon VPCs in the same AWS Region with non-overlapping CIDR blocks. The SysOps administrator needs to establish private connectivity between the two VPCs with high throughput and minimal cost. Which solution should the administrator implement?
⚠ Common exam trap
Many exam-takers choose AWS Transit Gateway because they assume it is required for any multi-VPC connectivity, but VPC peering is simpler and cheaper for connecting exactly two VPCs with non-overlapping CIDRs.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
VPC peering
VPC peering is the correct solution because it establishes private connectivity between two VPCs in the same AWS Region using the AWS backbone network, with no bandwidth limits and no single point of failure. It incurs no additional cost beyond data transfer charges, making it the most cost-effective option for high-throughput connectivity between two VPCs with non-overlapping CIDR blocks.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
AWS Transit Gateway
Why it's wrong here
While AWS Transit Gateway can connect two VPCs, it introduces a hub-and-spoke architecture with hourly per-attachment costs and data-processing fees. You would need to create a transit gateway, attach both VPCs, and configure route tables, which is unnecessary for a simple two-VPC connection. VPC peering provides the same private connectivity with lower latency, no extra hop, and no hourly charge.
- ✓
VPC peering
Why this is correct
VPC peering is the natural choice for connecting two VPCs in the same region because it creates a private, point-to-point connection using the AWS global network, with no gateways, VPNs, or physical devices. Since the CIDR blocks do not overlap, route tables are straightforward—just add routes pointing to the peering connection ID. It is highly available, incurs no per-hour fee (only data transfer costs), and is specifically designed for this exact scenario.
- ✗
AWS Direct Connect
Why it's wrong here
AWS Direct Connect is a dedicated physical connection from an on-premises location into AWS, not a VPC-to-VPC service. Even with Direct Connect, you would need a Virtual Private Gateway and either a transit VPC or VPN to relay traffic between the two VPCs, adding complexity and cost. It exists to reduce network expenses for hybrid workloads, not to provide inter-VPC communication within a region.
- ✗
AWS VPN CloudHub
Why it's wrong here
VPN CloudHub is a hub-and-spoke VPN topology that lets remote branch offices with customer gateways connect to a single Virtual Private Gateway attached to one VPC, enabling inter-site communication over encrypted tunnels. It does not provide native VPC-to-VPC peering; to connect the two VPCs you would have to route through an on-premises VPN, which adds unnecessary latency and complexity. It is purpose-built for multi-site VPN connectivity, not direct private VPC linking.
Visual reference
Go deeper
Related to this question
About these practice questions
Courseiva writes every SOA-C02 question from scratch — 1,169 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SOA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SOA-C02 exam.