AWS Advanced Networking – Specialty
Certification Exam Practice Questions
And Correct Answers (Verified Answers)
Plus Rationale 2026 Q&A| Instant
Download Pdf
1. A company operates a multi-account AWS environment in which
application VPCs are deployed across several AWS Regions. The
networking team wants to provide centralized connectivity between
VPCs while minimizing the number of individual peering relationships
that must be maintained. The architecture must also support
connectivity between VPCs and on-premises networks through a
centralized network hub. Which AWS service and architecture best
satisfy these requirements?
A. Use VPC peering between every VPC and establish a separate Site-to-Site
VPN connection from each VPC to the on-premises network.
B. Use AWS Transit Gateway as a regional network hub and attach the VPCs
and appropriate hybrid connectivity resources to it.
C. Use AWS PrivateLink to create endpoint services between every VPC and
,use Internet gateways for on-premises connectivity.
D. Use NAT gateways in each VPC and route all inter-VPC traffic through
public IP addresses.
Answer: B. Use AWS Transit Gateway as a regional network hub and attach
the VPCs and appropriate hybrid connectivity resources to it.
Rationale: AWS Transit Gateway provides centralized Layer 3 connectivity
for multiple VPCs and can also integrate with hybrid networking resources
such as Direct Connect gateways and Site-to-Site VPN. This hub-and-spoke
model avoids the operational complexity of creating and managing many
individual VPC peering relationships.
2. An enterprise has VPCs in several AWS Regions and wants workloads
in those VPCs to communicate privately across the AWS global
network rather than traverse the public internet. The networking team
wants a scalable architecture that can accommodate additional
Regions without creating a large mesh of individual connections.
Which solution is most appropriate?
A. Create VPC peering connections between every VPC in every Region.
B. Deploy NAT gateways in each Region and route inter-Regional traffic
through them.
C. Use AWS Transit Gateway inter-Region peering between regional transit
,gateways.
D. Use Internet gateways and public DNS records to connect the VPCs.
Answer: C. Use AWS Transit Gateway inter-Region peering between
regional transit gateways.
Rationale: AWS Transit Gateway supports inter-Region peering, allowing
transit gateways in different Regions to exchange traffic privately over the
AWS global network. This provides a scalable architecture while avoiding a
complex full-mesh topology of VPC peering connections.
3. A company uses AWS Direct Connect to connect its data center to
AWS. The company has multiple VPCs in the same Region and wants
to advertise routes from the on-premises network to those VPCs
through a centralized networking architecture. Which AWS
component should the company use to associate the Direct Connect
connection with multiple VPCs through a centralized routing design?
A. AWS Direct Connect gateway
B. NAT gateway
C. Internet gateway
D. VPC endpoint gateway
Answer: A. AWS Direct Connect gateway
, Rationale: An AWS Direct Connect gateway enables a Direct Connect
connection to reach multiple VPCs, including VPCs associated through
supported transit gateway architectures. It is designed for scalable hybrid
connectivity rather than requiring a separate physical Direct Connect
connection for every VPC.
4. A network engineer is designing a highly available connection between
an enterprise data center and AWS. The company requires private
connectivity with predictable performance and wants redundancy
against a failure of a single Direct Connect location or device. Which
architecture provides the strongest resilience?
A. One Direct Connect connection with a single virtual interface and a
backup NAT gateway.
B. Two Direct Connect connections from independent devices or locations,
combined with appropriate routing redundancy.
C. One Site-to-Site VPN connection through a single customer gateway.
D. One Direct Connect connection with a public virtual interface only.
Answer: B. Two Direct Connect connections from independent devices or
locations, combined with appropriate routing redundancy.
Rationale: Independent Direct Connect connections reduce the risk that a
single circuit, device, or location failure will interrupt hybrid connectivity.
Certification Exam Practice Questions
And Correct Answers (Verified Answers)
Plus Rationale 2026 Q&A| Instant
Download Pdf
1. A company operates a multi-account AWS environment in which
application VPCs are deployed across several AWS Regions. The
networking team wants to provide centralized connectivity between
VPCs while minimizing the number of individual peering relationships
that must be maintained. The architecture must also support
connectivity between VPCs and on-premises networks through a
centralized network hub. Which AWS service and architecture best
satisfy these requirements?
A. Use VPC peering between every VPC and establish a separate Site-to-Site
VPN connection from each VPC to the on-premises network.
B. Use AWS Transit Gateway as a regional network hub and attach the VPCs
and appropriate hybrid connectivity resources to it.
C. Use AWS PrivateLink to create endpoint services between every VPC and
,use Internet gateways for on-premises connectivity.
D. Use NAT gateways in each VPC and route all inter-VPC traffic through
public IP addresses.
Answer: B. Use AWS Transit Gateway as a regional network hub and attach
the VPCs and appropriate hybrid connectivity resources to it.
Rationale: AWS Transit Gateway provides centralized Layer 3 connectivity
for multiple VPCs and can also integrate with hybrid networking resources
such as Direct Connect gateways and Site-to-Site VPN. This hub-and-spoke
model avoids the operational complexity of creating and managing many
individual VPC peering relationships.
2. An enterprise has VPCs in several AWS Regions and wants workloads
in those VPCs to communicate privately across the AWS global
network rather than traverse the public internet. The networking team
wants a scalable architecture that can accommodate additional
Regions without creating a large mesh of individual connections.
Which solution is most appropriate?
A. Create VPC peering connections between every VPC in every Region.
B. Deploy NAT gateways in each Region and route inter-Regional traffic
through them.
C. Use AWS Transit Gateway inter-Region peering between regional transit
,gateways.
D. Use Internet gateways and public DNS records to connect the VPCs.
Answer: C. Use AWS Transit Gateway inter-Region peering between
regional transit gateways.
Rationale: AWS Transit Gateway supports inter-Region peering, allowing
transit gateways in different Regions to exchange traffic privately over the
AWS global network. This provides a scalable architecture while avoiding a
complex full-mesh topology of VPC peering connections.
3. A company uses AWS Direct Connect to connect its data center to
AWS. The company has multiple VPCs in the same Region and wants
to advertise routes from the on-premises network to those VPCs
through a centralized networking architecture. Which AWS
component should the company use to associate the Direct Connect
connection with multiple VPCs through a centralized routing design?
A. AWS Direct Connect gateway
B. NAT gateway
C. Internet gateway
D. VPC endpoint gateway
Answer: A. AWS Direct Connect gateway
, Rationale: An AWS Direct Connect gateway enables a Direct Connect
connection to reach multiple VPCs, including VPCs associated through
supported transit gateway architectures. It is designed for scalable hybrid
connectivity rather than requiring a separate physical Direct Connect
connection for every VPC.
4. A network engineer is designing a highly available connection between
an enterprise data center and AWS. The company requires private
connectivity with predictable performance and wants redundancy
against a failure of a single Direct Connect location or device. Which
architecture provides the strongest resilience?
A. One Direct Connect connection with a single virtual interface and a
backup NAT gateway.
B. Two Direct Connect connections from independent devices or locations,
combined with appropriate routing redundancy.
C. One Site-to-Site VPN connection through a single customer gateway.
D. One Direct Connect connection with a public virtual interface only.
Answer: B. Two Direct Connect connections from independent devices or
locations, combined with appropriate routing redundancy.
Rationale: Independent Direct Connect connections reduce the risk that a
single circuit, device, or location failure will interrupt hybrid connectivity.