How to Connect Overlapping VPCs to an AWS Marketplace Partner Service?
A company has a VPC in the AWS Cloud. The company recently acquired a competitor that also has a VPC the AWS Cloud. A network engineer discovers an IP address overlap between the two VPCs. Both VPCs require access to an AWS Marketplace partner service. Which solution will ensure interoperability among the VPC hosted services and the AWS Markelplace partner service?
Community Votes
100% of anonymous learners picked answer C. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
This question tests your understanding of inter-VPC connectivity limitations when IP ranges overlap, and the trap is assuming VPC peering or transit gateway can resolve the conflict.
When two AWS VPCs have overlapping IP addresses and both need access to an AWS Marketplace partner service, AWS PrivateLink with interface endpoints is the recommended solution. The community consensus is that this approach avoids IP conflicts while providing secure, private connectivity.
Choosing VPC peering (option A) — VPC peering does not support overlapping CIDR blocks, so routes become ambiguous and traffic cannot be correctly delivered.
Community Discussion (6 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
Option C uses AWS PrivateLink to create interface endpoints in each VPC. Since the partner service is exposed via endpoint services, each VPC can connect independently using its own VPC endpoint, avoiding any direct routing between the VPCs. This means overlapping IP addresses are irrelevant, as traffic never goes from one VPC to the other; it goes from each VPC to the partner service via the endpoint. The DNS names created for each interface endpoint provide a simple and secure way to route traffic. This approach is fully supported by AWS Marketplace partner services that are integrated with PrivateLink.
Why the Other Options Are Wrong
Option A (VPC peering) is invalid because AWS VPC peering does not support overlapping CIDR blocks; peering connections require non-overlapping ranges to allow route table entries. Option B (NAT gateways with transit gateway) does not solve the overlap either, and it also introduces unnecessary complexity; a transit gateway still needs to route between VPCs, which breaks with overlapping IPs. Option D (NAT instances) similarly fails to address the overlap, and using interface endpoints there is mixed with NAT instances which are not intended for this scenario; the endpoint itself is enough, but the overall design is flawed because NAT instances do not resolve IP conflicts.
Community Comment Notes
Comments repeatedly highlight that VPC peering and transit gateway are not valid when IP addresses overlap. One comment (likes=2) explicitly states that "VPC peering does not support overlapping IP address ranges" and "transit gateway does not resolve IP overlap issues." Another comment (likes=2) mentions that "NAT instance option is not preferred when you considered IP overlaps." The only solution that avoids the overlap problem is PrivateLink because it creates a logical connection to a service without relying on VPC-to-VPC routing.
Official Reference
Exam Strategy
When facing overlapping VPC IP ranges, immediately eliminate any option that requires VPC-to-VPC routing (peering, transit gateway, or VPN between VPCs). Look for a service-based connectivity model like PrivateLink, which allows each VPC to connect to a service endpoint independently. Remember that PrivateLink is the standard answer for secure access to AWS Marketplace partner services.
Related Analysis
Practice All ANS-C01 Questions
Access 137 questions with complete answers and detailed explanations.
View Full ANS-C01 Practice Test →