A media streaming company is implementing Direct Connect access to private VPC resources and public AWS services on the same physical connection. Which virtual interface choices are correct? Additional constraint: change windows are limited to 30 minutes, and the environment includes 17 VPCs across 13 AWS accounts. What should the network engineer do?