SOA-C02 Networking and Content Delivery Practice Question
A company has two VPCs in the same AWS region. VPC A hosts a web application, and VPC B hosts a database. The SysOps administrator needs to enable private IP communication between the two VPCs without using the public internet. The administrator wants a simple, low-cost solution that uses the AWS network backbone. Which AWS service should be used?
⚠ Common exam trap
Many exam-takers choose AWS Transit Gateway because it is a powerful networking hub, but the question explicitly asks for a simple, low-cost solution for only two VPCs, making VPC Peering the correct choice despite Transit Gateway's broader capabilities.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
VPC Peering
VPC Peering allows direct, private IP connectivity between two VPCs using the AWS network backbone without traversing the public internet. It is the simplest and most cost-effective solution for connecting exactly two VPCs in the same region, as there are no additional hourly charges beyond data transfer costs, and no intermediate devices or bandwidth limitations are introduced.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
VPC Peering
Why this is correct
VPC Peering establishes a direct, logical connection between exactly two VPCs, using a 1:1 relationship that relies on AWS's existing routing infrastructure—no gateways, virtual appliances, or dedicated physical lines are required. Traffic between the peered VPCs uses private IPv4 or IPv6 addresses and stays entirely on the AWS global network, avoiding public-internet exposure and providing low, predictable latency. It is cost-effective for a pair of VPCs because there is no hourly fee or minimum revenue commitment; you pay only for inter-VPC data transfer, which is usually significantly cheaper than traffic traversing the internet. Although VPC peering is non-transitive, that property is irrelevant for a two-VPC architecture, making it the simplest and most operationally efficient solution for this requirement.
- ✗
AWS Transit Gateway
Why it's wrong here
Transit Gateway introduces unnecessary complexity and cost for a two-VPC peering scenario, as it requires a central hub router and additional attachments, whereas VPC peering provides direct, low-cost connectivity using the AWS backbone without such overhead. It is tempting because Transit Gateway is designed for hub-and-spoke architectures with many VPCs, where it simplifies routing and centralised management—making it the correct choice for large-scale multi-VPC topologies, but not for a simple two-VPC requirement.
- ✗
AWS Direct Connect
Why it's wrong here
AWS Direct Connect is a dedicated physical network connection that links an on-premises data center or colocation facility to AWS via a private circuit, typically delivered through a Direct Connect partner or location. It is designed exclusively for hybrid-cloud workloads where you need reliable, high-bandwidth, low-latency connectivity from your own infrastructure to AWS resources. Using Direct Connect for VPC-to-VPC traffic would force you to hairpin data through an external router on-premises, which is not only architecturally nonsensical but also introduces unnecessary physical infrastructure, carrier costs, and latency. Direct Connect does not provide a mechanism to connect two VPCs directly; instead, it attaches to a virtual private gateway for one VPC at a time, and inter-VPC communication would require complex routing that defeats the purpose of private AWS backbone connectivity.
- ✗
AWS Site-to-Site VPN
Why it's wrong here
AWS Site-to-Site VPN creates an encrypted IPsec tunnel between a VPN device on an on-premises network and a virtual private gateway attached to an AWS VPC, with traffic traversing the public internet. For VPC-to-VPC communication, you would need to establish two separate VPN connections—one from each VPC to some external VPN endpoint—and route all inter-VPC traffic through that external location, which is convoluted, introduces significant latency, and incurs hourly connection charges for each VPN tunnel. Unlike VPC peering, which uses AWS's private backbone, a Site-to-Site VPN relies on the public internet, so traffic is exposed to encryption overhead and potential variability in network performance. Even in the unlikely scenario where both VPCs are configured with VPN connections to the same endpoint, the architecture would be far more expensive and complex than a simple peering connection, making it an inappropriate choice for same-region inter-VPC connectivity.
Visual reference
Go deeper
Related to this question
About these practice questions
One of 1,169 original SOA-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SOA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SOA-C02 exam.