A company has 50 member AWS accounts and wants to use AWS Transit Gateway to connect VPCs across those accounts. When a new member account is created, the company wants to automate creating a new VPC and attaching it to the Transit Gateway. Which combination of actions will achieve this? (Choose two.)
Choose an answer
Tap an option to check your answer.
Correct answer: From the management account, share the Transit Gateway with member accounts by using AWS Resource Access Manager (AWS RAM)., From the management account, deploy an AWS CloudFormation StackSet that automatically creates a new VPC and a Transit Gateway VPC attachment in the member account. Associate that attachment with the Transit Gateway in the management account by referencing the Transit Gateway ID..
Why this is the answer
Sharing the Transit Gateway (TGW) from the management account to member accounts using AWS Resource Access Manager (RAM) is essential. RAM allows you to share AWS resources, including TGWs, across accounts within an AWS Organization. This enables member accounts to create attachments to the shared TGW. Deploying an AWS CloudFormation StackSet from the management account automates the creation of a new VPC and the TGW VPC attachment in the new member account. The StackSet can reference the shared TGW's ID to establish the connection. Incorrect options: AWS Organizations service control policies (SCPs) manage permissions but don't share resources like TGWs. Creating a peering TGW attachment is not the standard way to connect VPCs within the same TGW, and a service-linked role isn't used for sharing attachments in this manner. AWS Service Catalog is for sharing curated IT services, not for sharing infrastructure resources like TGWs directly for connectivity.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed