Courseiva

CCSP Cloud Platform and Infrastructure Security Practice Question

A cloud security team is implementing VPC peering between two VPCs in the same region. Which statement about VPC peering is correct?

⚠ Common exam trap

The trap here is conflating 'private connectivity' with 'encrypted connectivity' — candidates assume private automatically means encrypted, but VPC peering provides routing isolation, not cryptographic protection.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

VPC peering enables private IP connectivity across VPCs without internet

VPC peering creates a direct, private network route between two VPCs using their private IPv4 or IPv6 CIDR blocks, so instances communicate as if on the same network without traversing the public internet, VPN, or a NAT device. Traffic stays on the cloud provider's backbone, which is why it is considered private connectivity. This is the defining characteristic of VPC peering and the reason it is used for cross-VPC application tiers, shared services, and multi-account architectures.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    VPC peering requires VPN gateways to establish connectivity

    Why it's wrong here

    VPC peering creates a direct routing relationship between the two VPCs over the provider's private backbone, so no VPN gateways or tunnels are involved. It is tempting because VPN gateways do connect VPCs, and would be correct when linking networks across regions, accounts or to on-premises over encrypted tunnels.

  • ✓

    VPC peering enables private IP connectivity across VPCs without internet

    Why this is correct

    VPC peering establishes a direct routing relationship between two VPCs using their private IPv4 or IPv6 addresses, so instances communicate over the cloud provider's internal backbone. Traffic never traverses the public internet, satisfying the private connectivity requirement without gateways or VPNs.

  • ✗

    VPC peering automatically encrypts all traffic between VPCs

    Why it's wrong here

    VPC peering provides private IP routing between the VPCs; encryption is not added by the peering itself, and traffic within a provider's backbone is not automatically encrypted by this feature. It is tempting because private connectivity feels inherently protected, and would be correct where a VPN or application-layer TLS supplies encryption.

  • ✗

    VPC peering supports transitive routing through intermediate VPCs

    Why it's wrong here

    VPC peering is strictly non-transitive: a peered VPC cannot forward traffic to a third VPC through an intermediate one, so each pair needs its own peering connection. Transitive routing is what a transit gateway provides when many VPCs must reach each other through a central hub.

Visual reference

Inside (Private) PC-A 10.0.0.1 PC-B 10.0.0.2 NAT Router Outside (Public) 203.0.113.1 Inside Global Server PAT: many private IPs share one public IP via unique port numbers

About these practice questions

One of 934 original CCSP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.