How to Connect VPCs with Overlapping IP Ranges Using AWS PrivateLink?

A company has five VPCs in the us-east-1 Region. The company hosts an internal web application in us-east-1. One of the company's VPCs. named VPC-A, needs to connect to an external partner's AWS environment. The partner’s environment is in the same AWS Region where the partner hosts a new version of the company's web application. The partner hosts its version of the application in a VPC named VPC-B. The company has Amazon EC2 instances in VPC-A that need to connect to the web application in VPC-B A network engineer notices that the partner's VPC-B and the company's VPC-A use the same IP space. The network engineer needs a solution to allow the EC2 instances to connect to the web application. The solution must not negatively affect the exiting environment of the company or the partner. Which combination of steps should the network engineer take meet these requirements? (Choose two.)

  1. Establish a VPC peering connection between VPC-A to VPC-B.
  2. Ensure the partner creates a VPC endpoint service that uses a Network Load Balancer in VPC-B. Source Reference Answer
  3. Deploy a VPC endpoint in VPC-A that uses a VPC endpoint service that is shared by the partner. Source Reference Answer
  4. Deploy a new routable VPC CIDR block as a secondary CIDR block to both VPC-A and VPC-B. Deploy a public NAT gateway in VPC-A.
  5. Establish an AWS Site-to-Site VPN connection between VPC-A and VPC-B.

Community Votes

BC
100%

100% of anonymous learners picked answer BC. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

This question tests the limitations of VPC peering/VPN with overlapping IP ranges and the use of PrivateLink to connect services without routing. The common trap is selecting peering or VPN, which fail due to CIDR conflicts.

For the ANS-C01 exam, connecting VPCs with overlapping CIDRs requires AWS PrivateLink: the partner creates a VPC endpoint service backed by a Network Load Balancer, and the company creates a VPC endpoint. Community consensus (100% BC) confirms this avoids IP conflicts and preserves existing environments.

Choosing A (VPC peering) or E (Site-to-Site VPN) is the most common mistake. These require non-overlapping CIDRs and would cause routing conflicts; they cannot connect VPCs with the same IP space.

Community Discussion (3 comments)

ashk123456 👍 1 Selected: BC
AWS PrivateLink (which uses VPC endpoint services) is specifically designed to connect services across VPCs without requiring overlapping CIDR ranges to be routable between them. This solves the IP overlap problem without requiring IP address changes. The partner would create a VPC endpoint service backed by a Network Load Balancer that fronts their web application in VPC-B. The company would then create a VPC endpoint in VPC-A that connects to the partner's endpoint service, allowing EC2 instances to access the application using a private DNS name that resolves to a private IP within VPC-A's address space.
woorkim 👍 2 Selected: BC
Handles overlapping IP ranges Doesn't require network changes Provides secure connectivity Uses AWS PrivateLink, which is designed for this scenario Maintains isolation between environments
c1193d4 👍 2 Selected: BC
B and C: see https://aws.amazon.com/blogs/networking-and-content-delivery/connecting-networks-with-overlapping-ip-ranges/

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

B and C work together: the partner creates a VPC endpoint service backed by a Network Load Balancer in VPC-B (B). The company then creates a VPC endpoint in VPC-A using that service (C). PrivateLink enables connectivity without advertising overlapping CIDRs, so no routing conflict occurs. This is the only solution that works across overlapping IP spaces without changing IPs.

Why the Other Options Are Wrong

A (VPC peering) and E (Site-to-Site VPN) establish direct network paths that require unique IP spaces; overlapping CIDRs would cause ambiguous routing and break connectivity. D is unnecessary and does not resolve the overlap. Only PrivateLink, using the endpoint service model, allows the two VPCs to remain isolated while the EC2 instances reach the specific load balancer endpoint.

Community Comment Notes

All valid comments agree on BC. One comment highlights that PrivateLink is 'designed for this scenario' and maintains isolation. Another references an AWS blog post on connecting networks with overlapping IP ranges, reinforcing that PrivateLink handles this use case.

Official Reference

Exam Strategy

Remember that overlapping CIDRs rule out peering and VPN; instead look for PrivateLink/endpoint services. On exam day, if you see overlapping IP spaces, immediately consider VPC endpoint services backed by NLBs, and look for the two-step answer: service provider creates endpoint service, and consumer creates VPC endpoint.

Related Analysis

Practice All ANS-C01 Questions

Access 137 questions with complete answers and detailed explanations.

View Full ANS-C01 Practice Test →

← Back to ANS-C01 Study Guide