nerdexam
Amazon

ANS-C01 · Question #32

A network engineer needs to update a company's hybrid network to support IPv6 for the upcoming release of a new application. The application is hosted in a VPC in the AWS Cloud. The company's…

The correct answer is A. Update the Direct Connect transit VIF and configure BGP peering with the AWS assigned IPv6. For dual-stack connectivity on the Site-to-Site VPN connection via a Transit Gateway, you need to create two VPN connections, one for the IPv4 stack and one for the IPv6 stack. D. For AWS Direct Connect connection, reuse your existing VIFs and enable them for dual-stack…

Submitted by hassan_iq· Mar 6, 2026

Question

A network engineer needs to update a company's hybrid network to support IPv6 for the upcoming release of a new application. The application is hosted in a VPC in the AWS Cloud. The company's current AWS infrastructure includes VPCs that are connected by a transit gateway. The transit gateway is connected to the on-premises network by AWS Direct Connect and AWS Site-to-Site VPN. The company's on-premises devices have been updated to support the new IPv6 requirements. The company has enabled IPv6 for the existing VPC by assigning a new IPv6 CIDR block to the VPC and by assigning IPv6 to the subnets for dual-stack support. The company has launched new Amazon EC2 instances for the new application in the updated subnets. When updating the hybrid network to support IPv6 the network engineer must avoid making any changes to the current infrastructure. The network engineer also must block direct access to the instances' new IPv6 addresses from the internet. However, the network engineer must allow outbound internet access from the instances. What is the MOST operationally efficient solution that meets these requirements?

Options

  • AUpdate the Direct Connect transit VIF and configure BGP peering with the AWS assigned IPv6
  • BUpdate the Direct Connect transit VIF and configure BGP peering with the AWS assigned IPv6
  • CCreate a Direct Connect transit VIF and configure BGP peering with the AWS assigned IPv6
  • DCreate a Direct Connect transit VIF and configure BGP peering with the AWS assigned IPv6

How the community answered

(26 responses)
  • A
    69% (18)
  • B
    8% (2)
  • C
    19% (5)
  • D
    4% (1)

Explanation

For dual-stack connectivity on the Site-to-Site VPN connection via a Transit Gateway, you need to create two VPN connections, one for the IPv4 stack and one for the IPv6 stack. D. For AWS Direct Connect connection, reuse your existing VIFs and enable them for dual-stack support. https://aws.amazon.com/blogs/networking-and-content-delivery/dual-stack-ipv6-architectures-for- aws-an d-hybrid-networks/

Topics

#AWS Direct Connect#IPv6#BGP peering#Hybrid networking

Community Discussion

No community discussion yet for this question.

Full ANS-C01 Practice