Advertise on-premises and VPC prefixes across a transit VIF for Direct Connect reachability
A company wants to establish a dedicated connection between its on-premises infrastructure and AWS. The company is setting up a 1 Gbps AWS Direct Connect connection to its account VPC. The architecture includes a transit gateway and a Direct Connect gateway to connect multiple VPCs and the on-premises infrastructure. The company must connect to VPC resources over a transit VIF by using the Direct Connect connection. Which combination of steps will meet these requirements? (Choose two.)
Community Votes
100% of anonymous learners picked answer BC. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
A transit VIF is a routed connection, so reachability depends entirely on route propagation in both directions: the on-premises prefixes must be advertised onto the transit VIF and the VPC prefixes from the Direct Connect gateway must be advertised back to on-premises.
A company is setting up a 1 Gbps Direct Connect connection with a transit gateway and a Direct Connect gateway to connect multiple VPCs to on-premises infrastructure. Traffic must reach VPC resources over a transit VIF on this connection.
Focusing on the port speed or on MACsec. The 1 Gbps port is the stated design and nothing in the requirement asks for more bandwidth, and MACsec encryption on Direct Connect is only supported at 10 Gbps and 100 Gbps so it is not available on this connection at all, making both encryption options inapplicable.
Community Discussion (5 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
A transit VIF carries routed traffic between the on-premises network and AWS, and routing on a routed link works in both directions. Advertising the on-premises network prefixes over the transit VIF is what lets AWS know how to send traffic back to the data center, so B is required. Advertising the VPC prefixes from the Direct Connect gateway to the on-premises network over the same transit VIF is what lets the data center know how to reach the VPCs attached to the transit gateway, so C is required. With both directions propagated, the transit gateway resolves routes between the on-premises router and the attached VPCs, which is the stated architecture.Why the Other Options Are Wrong
A: Upgrading the connection to 10 Gbps changes the port speed and cost but does not contribute to the routing that transit VIF reachability depends on, and nothing in the requirements calls for additional bandwidth. D and E: MACsec encryption on Direct Connect is supported only on 10 Gbps and 100 Gbps dedicated connections, so a 1 Gbps connection cannot use it at all, and neither updating the encryption mode nor associating a MACsec key pair would create the routing needed to reach VPC resources.Community Comment Notes
The community voted 100 to 0 for B and C, and the reasoning was repeated across the top comments, both prefix advertisements are required for the on-premises network and the VPCs to see each other. A commenter linked the AWS Direct Connect documentation page for transit gateways and another ruled out the MACsec options with a link to the announcement stating that MACsec requires a dedicated 10 Gbps or 100 Gbps connection.Official Reference
Related Analysis
Practice All SAP-C02 Questions
Access 85 questions with complete answers and detailed explanations.
View Full SAP-C02 Practice Test →