SOA-C02 Networking and Content Delivery Practice Question
Which THREE components are required to set up a site-to-site VPN connection between a VPC and an on-premises network? (Choose three.)
⚠ Common exam trap
Candidates often confuse a NAT Gateway or Internet Gateway as necessary for VPN connectivity, but neither is involved in IPsec tunnel establishment; the correct components are the virtual private gateway (or transit gateway), the VPN connection, and the customer gateway.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Virtual private gateway or transit gateway
A virtual private gateway or transit gateway is required as the AWS-side VPN concentrator that terminates the VPN tunnels and routes traffic between the VPC and the on-premises network. It provides the target for the VPN connection and must be attached to the VPC to enable site-to-site VPN functionality.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Virtual private gateway or transit gateway
Why this is correct
The virtual private gateway (VGW) or transit gateway (TGW) serves as the AWS-side endpoint for a site-to-site VPN connection. It must be attached to a VPC (or a transit gateway for centralized connectivity) and terminates the IPsec tunnels from the on-premises network. Without this component, there is no target for the VPN traffic on AWS, making it a mandatory piece.
- ✗
NAT Gateway
Why it's wrong here
A NAT Gateway enables instances in a private subnet to initiate outbound internet traffic, but it does not accept inbound VPN connections and cannot terminate IPsec tunnels. Site-to-site VPN requires a VPN endpoint on the AWS side, not a NAT device. A NAT Gateway is purely for network address translation and has no role in encrypting or routing VPN traffic between on-premises and AWS.
- ✓
VPN connection
Why this is correct
The VPN connection is a logical object in AWS that links the customer gateway on the on-premises side to the virtual private gateway or transit gateway on the AWS side. It defines the tunnel settings, including encryption parameters and routing options, and it typically consists of two tunnels for high availability. The VPN connection is what actually establishes the secure IPsec session, so it is essential.
- ✓
Customer gateway
Why this is correct
A customer gateway is a resource that describes the on-premises VPN device's public IP address and, if BGP is enabled, the BGP ASN. It acts as the remote peer for the AWS VPN endpoint, allowing AWS to establish the IPsec tunnels. Since it represents the physical or software VPN device at the customer's data center, it is required for site-to-site connectivity.
- ✗
Internet gateway
Why it's wrong here
An internet gateway (IGW) provides outbound and inbound internet access to a VPC, but it is not used for site-to-site VPN termination. The VPN traffic follows a path that is terminated by the virtual private gateway, even though it traverses the public internet. Adding an IGW does not help establish a VPN connection, and AWS VPN does not require an IGW on the VPC.
Go deeper
Related to this question
About these practice questions
This SOA-C02 question is part of Courseiva's 1,169-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SOA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SOA-C02 exam.