Courseiva

SOA-C02 Networking and Content Delivery Practice Question

Which THREE components are required to establish a site-to-site VPN connection between an AWS VPC and an on-premises network? (Choose three.)

⚠ Common exam trap

Test-takers frequently think a transit gateway is required for site-to-site VPN, but it is only needed when you want to centralize routing across multiple VPCs or use advanced features like route propagation; a single VPC-to-on-premises VPN works with just a VGW, CGW, and VPN connection.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Customer gateway (CGW)

A customer gateway (CGW) is required because it represents the on-premises side of the site-to-site VPN connection. It provides the public IP address and BGP ASN (if dynamic routing is used) of the on-premises VPN device, allowing AWS to establish IPsec tunnels with the correct endpoint.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Customer gateway (CGW)

    Why this is correct

    The Customer Gateway (CGW) is a logical object in AWS that represents the on-premises VPN device or software application. It stores the public IP address of the customer-side router and, if BGP is used, the Border Gateway Protocol Autonomous System Number (ASN). It is mandatory because the AWS-side virtual private gateway needs a defined peer endpoint to establish the IPsec tunnels, and route propagation depends on this object. Without the CGW, there is no specified remote device to encrypt traffic to.

  • ✗

    Transit gateway

    Why it's wrong here

    Transit gateway is not a required component for a direct site-to-site VPN between a single VPC and an on-premises network. A VPN connection can be terminated directly on a virtual private gateway attached to one VPC, making the transit gateway unnecessary overhead. It only becomes useful when you need to centrally connect multiple VPCs and on-premises networks, as it acts as a hub router for inter-VPC and VPN traffic. In the scenario of a basic site-to-site VPN, including a transit gateway adds complexity and cost without adding required function.

  • ✓

    VPN connection

    Why this is correct

    The VPN connection is the AWS resource that represents the actual IPsec tunnel configuration linking the virtual private gateway and the customer gateway. It contains the parameters for the two tunnel endpoints, including pre-shared keys, encryption and integrity algorithms, and the routing options (static or BGP). This object is required because both gateways are inert until they are connected by an active VPN connection, which is what establishes the encrypted tunnel and controls which CIDRs are routed over it. Without this, the VGW and CGW have no logical binding and no traffic can flow.

  • ✓

    Virtual private gateway (VGW)

    Why this is correct

    Virtual private gateway is the AWS-managed VPN concentrator that attaches to a VPC and provides the AWS-side endpoint for IPsec tunnels. It is required to create a site-to-site VPN connection because it is the target for the VPN tunnels, and VPC route tables use it to direct traffic destined for the on-premises network. The VGW also handles BGP peering when dynamic routing is configured and propagates routes to the VPC. Without a VGW, there is nothing on the AWS side to terminate the encrypted tunnels, so the VPN connection cannot be completed.

  • ✗

    AWS Direct Connect

    Why it's wrong here

    AWS Direct Connect is an entirely separate service that establishes a dedicated physical network connection over a private, low-latency link rather than over the public internet. It does not replace or fulfill the logical objects required for an IPsec VPN; you still need the gateways and VPN connection if you want a site-to-site VPN, while Direct Connect itself is a distinct product for private connectivity. It is not a required component and is in fact mutually exclusive with VPN setup—you could use Direct Connect entirely without ever creating a VPN. Including it as a required component is incorrect because the question asks specifically about the site-to-site VPN architecture.

Quick reference

VPN Protocol Comparison

ProtocolPortEncryptionAuthenticationUse Case
IKEv2 / IPsecUDP 500 / 4500AES-256Certificates / PSKSite-to-site & remote access
SSL / TLS VPNTCP 443TLS 1.3Certificates / MFAClientless remote access
L2TP / IPsecUDP 1701AES (IPsec)PSK / CertificatesLegacy remote access
WireGuardUDP 51820ChaCha20Public keysModern high-performance VPN
PPTPTCP 1723MPPE (weak)MS-CHAPv2Legacy — avoid in production

PPTP is considered insecure. IKEv2/IPsec and SSL VPN are the current recommended options.

About these practice questions

One of 1,169 original SOA-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SOA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SOA-C02 exam.