Courseiva

SOA-C02 Networking and Content Delivery Practice Question

Which THREE components are required to set up a site-to-site VPN connection between a VPC and an on-premises network? (Choose three.)

⚠ Common exam trap

Candidates often confuse a NAT Gateway or Internet Gateway as necessary for VPN connectivity, but neither is involved in IPsec tunnel establishment; the correct components are the virtual private gateway (or transit gateway), the VPN connection, and the customer gateway.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Virtual private gateway or transit gateway

A virtual private gateway or transit gateway is required as the AWS-side VPN concentrator that terminates the VPN tunnels and routes traffic between the VPC and the on-premises network. It provides the target for the VPN connection and must be attached to the VPC to enable site-to-site VPN functionality.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Virtual private gateway or transit gateway

    Why this is correct

    The virtual private gateway (VGW) or transit gateway (TGW) serves as the AWS-side endpoint for a site-to-site VPN connection. It must be attached to a VPC (or a transit gateway for centralized connectivity) and terminates the IPsec tunnels from the on-premises network. Without this component, there is no target for the VPN traffic on AWS, making it a mandatory piece.

  • ✗

    NAT Gateway

    Why it's wrong here

    A NAT Gateway enables instances in a private subnet to initiate outbound internet traffic, but it does not accept inbound VPN connections and cannot terminate IPsec tunnels. Site-to-site VPN requires a VPN endpoint on the AWS side, not a NAT device. A NAT Gateway is purely for network address translation and has no role in encrypting or routing VPN traffic between on-premises and AWS.

  • ✓

    VPN connection

    Why this is correct

    The VPN connection is a logical object in AWS that links the customer gateway on the on-premises side to the virtual private gateway or transit gateway on the AWS side. It defines the tunnel settings, including encryption parameters and routing options, and it typically consists of two tunnels for high availability. The VPN connection is what actually establishes the secure IPsec session, so it is essential.

  • ✓

    Customer gateway

    Why this is correct

    A customer gateway is a resource that describes the on-premises VPN device's public IP address and, if BGP is enabled, the BGP ASN. It acts as the remote peer for the AWS VPN endpoint, allowing AWS to establish the IPsec tunnels. Since it represents the physical or software VPN device at the customer's data center, it is required for site-to-site connectivity.

  • ✗

    Internet gateway

    Why it's wrong here

    An internet gateway (IGW) provides outbound and inbound internet access to a VPC, but it is not used for site-to-site VPN termination. The VPN traffic follows a path that is terminated by the virtual private gateway, even though it traverses the public internet. Adding an IGW does not help establish a VPN connection, and AWS VPN does not require an IGW on the VPC.

About these practice questions

This SOA-C02 question is part of Courseiva's 1,169-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SOA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SOA-C02 exam.