How to Connect On-Premises to Multiple AWS Regions via Direct Connect and Transit Gateways?
A company is running business applications on AWS. The company uses 50 AWS accounts, thousands of VPCs, and 3 AWS Regions across the United States and Europe. A network engineer needs to establish network connectivity between an on-premises data center and the Regions. The network engineer also must establish connectivity between the VPCs. On-premises: users and applications must be able to connect to applications that run in the VPCs. The company has an existing AWS Direct Connect connection that the network engineer can use. The network engineer creates a transit gateway in each Region and configures the transit gateways as inter-Region peers. Which solution will provide network connectivity from the on-premises data center to the Regions and will provide inter-VPC communications across the different Regions?
Community Votes
100% of anonymous learners picked answer C. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
This question tests your understanding of Direct Connect virtual interface types and Direct Connect gateway associations; the trap is assuming a private VIF with a virtual private gateway can scale to multiple VPCs and Regions, but only a transit VIF associated with a Direct Connect gateway and transit gateways provides the required multi-region connectivity.
Need to connect an on-premises data center to multiple AWS Regions and VPCs? The correct ANS-C01 solution is to create a transit VIF to a Direct Connect gateway and associate each regional transit gateway with that gateway, enabling seamless inter-Region and inter-VPC communication.
The most common wrong answers are A and B because they use private VIFs and virtual private gateways. These options work for a single VPC or multiple VPCs within one Region, but they cannot integrate with transit gateways for inter-Region peering across many VPCs and accounts.
Community Discussion (4 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
Option C is correct because a transit VIF is specifically designed to connect an AWS Direct Connect connection to a Direct Connect gateway. The Direct Connect gateway can then be associated with multiple transit gateways, one per Region, enabling on-premises connectivity to all VPCs attached to those transit gateways. Since the transit gateways are already configured as inter-Region peers, VPCs across Regions can communicate with each other and with on-premises networks. This is the only option that uses a transit VIF, which is required for Direct Connect gateway-to-transit-gateway associations, as the community comment notes: "only TGW has to be connected thru transit VIF!"
Why the Other Options Are Wrong
Option A is incorrect because a private VIF with a virtual private gateway can only be associated with a single VPC in a single Region. It does not provide connectivity to multiple VPCs across Regions or support transit gateway integration. Option B is incorrect because a private VIF to a Direct Connect gateway can associate with multiple virtual private gateways, but virtual private gateways are still limited to individual VPCs and do not support transit gateway inter-Region peering. Option D is incorrect because a Site-to-Site VPN over a public VIF adds unnecessary complexity and does not leverage the Direct Connect gateway and transit VIF architecture; it also does not provide the same private, low-latency connectivity expected for multi-Region inter-VPC traffic.
Community Comment Notes
Community comments overwhelmingly support C, with all voters selecting C. One commenter highlighted that a transit VIF allows a Direct Connect connection to reach a Direct Connect gateway, which can then be associated with multiple transit gateways across Regions, enabling seamless communication between on-premises and multiple VPCs. Another commenter succinctly stated "its c! only TGW has to be connected thru transit VIF!" reinforcing the key technical requirement. There was no dissent or alternative viewpoint in the comments, making C a clear and well-understood correct answer in the community.
Official Reference
Exam Strategy
On the ANS-C01 exam, whenever you see the need to connect an on-premises environment to multiple VPCs across AWS Regions using transit gateways, immediately look for an option that pairs a transit VIF with a Direct Connect gateway. Remember that transit VIF is the only virtual interface type that supports Direct Connect gateway-to-transit gateway associations, and avoid options that use private VIFs or virtual private gateways for multi-Region scenarios.
Related Analysis
Practice All ANS-C01 Questions
Access 137 questions with complete answers and detailed explanations.
View Full ANS-C01 Practice Test →