Advertise on-premises and VPC prefixes across a transit VIF for Direct Connect reachability

Answer Correct answers: B, C — Advertise on-premises prefixes over the transit VIF and advertise the Direct Connect gateway VPC prefixes to on-premises.

A company wants to establish a dedicated connection between its on-premises infrastructure and AWS. The company is setting up a 1 Gbps AWS Direct Connect connection to its account VPC. The architecture includes a transit gateway and a Direct Connect gateway to connect multiple VPCs and the on-premises infrastructure. The company must connect to VPC resources over a transit VIF by using the Direct Connect connection. Which combination of steps will meet these requirements? (Choose two.)

  1. Update the 1 Gbps Direct Connect connection to 10 Gbps.
  2. Advertise the on-premises network prefixes over the transit VIF. Correct Answer
  3. Advertise the VPC prefixes from the Direct Connect gateway to the on-premises network over the transit VIF. Correct Answer
  4. Update the Direct Connect connection's MACsec encryption mode attribute to must_encrypt.
  5. Associate a MACsec Connection Key Name/Connectivity Association Key (CKN/CAK) pair with the Direct Connect connection.

Community Votes

BC
100%

100% of anonymous learners picked answer BC. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

A transit VIF is a routed connection, so reachability depends entirely on route propagation in both directions: the on-premises prefixes must be advertised onto the transit VIF and the VPC prefixes from the Direct Connect gateway must be advertised back to on-premises.

A company is setting up a 1 Gbps Direct Connect connection with a transit gateway and a Direct Connect gateway to connect multiple VPCs to on-premises infrastructure. Traffic must reach VPC resources over a transit VIF on this connection.

Focusing on the port speed or on MACsec. The 1 Gbps port is the stated design and nothing in the requirement asks for more bandwidth, and MACsec encryption on Direct Connect is only supported at 10 Gbps and 100 Gbps so it is not available on this connection at all, making both encryption options inapplicable.

Community Discussion (5 comments)

AzureDP900 👍 2
Option B and Option C are correct because they enable connectivity between on-premises infrastructure and AWS VPCs by advertising network prefixes. Option B enables the on-premises network to reach AWS, while option C allows the AWS VPCs to communicate with on-premises resources over a transit VIF.
tushar321 👍 2
BC MACsec is ruled out as this needs 10 gbps https://aws.amazon.com/about-aws/whats-new/2021/03/aws-direct-connect-announces-macsec-encryption-for-dedicated-10gbps-and-100gbps-connections-at-select-locations/
pangchn 👍 4 Selected: BC
BC just need to add routing at both sides. https://docs.aws.amazon.com/directconnect/latest/UserGuide/direct-connect-transit-gateways.html https://docs.aws.amazon.com/vpc/latest/tgw/tgw-prefix-lists.html ADE seems not relevant
ahmadraufsyahputra 👍 3
BC because we need to ardvertise the VPC prefixes and on-premise prefixes so the on-premise and VPC can connected
Dgix 👍 3 Selected: BC
B and C are correct. A is not required, D needlessly involves encryption, and E doesn't create connectivity.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

A transit VIF carries routed traffic between the on-premises network and AWS, and routing on a routed link works in both directions. Advertising the on-premises network prefixes over the transit VIF is what lets AWS know how to send traffic back to the data center, so B is required. Advertising the VPC prefixes from the Direct Connect gateway to the on-premises network over the same transit VIF is what lets the data center know how to reach the VPCs attached to the transit gateway, so C is required. With both directions propagated, the transit gateway resolves routes between the on-premises router and the attached VPCs, which is the stated architecture.

Why the Other Options Are Wrong

A: Upgrading the connection to 10 Gbps changes the port speed and cost but does not contribute to the routing that transit VIF reachability depends on, and nothing in the requirements calls for additional bandwidth. D and E: MACsec encryption on Direct Connect is supported only on 10 Gbps and 100 Gbps dedicated connections, so a 1 Gbps connection cannot use it at all, and neither updating the encryption mode nor associating a MACsec key pair would create the routing needed to reach VPC resources.

Community Comment Notes

The community voted 100 to 0 for B and C, and the reasoning was repeated across the top comments, both prefix advertisements are required for the on-premises network and the VPCs to see each other. A commenter linked the AWS Direct Connect documentation page for transit gateways and another ruled out the MACsec options with a link to the announcement stating that MACsec requires a dedicated 10 Gbps or 100 Gbps connection.

Official Reference

Related Analysis

Practice All SAP-C02 Questions

Access 85 questions with complete answers and detailed explanations.

View Full SAP-C02 Practice Test →

← Back to SAP-C02 Study Guide