A company has a 1 Gbps Direct Connect link between its on-premises site and AWS. An on-prem application needs encrypted, private-IP communication with an application in a VPC. The traffic must not traverse the public internet. Which solution provides the required connectivity with the LEAST operational overhead?
Choose an answer
Tap an option to check your answer.
Correct answer: Create a transit gateway, configure a transit VIF on the Direct Connect connection, associate the transit VIF with a Direct Connect gateway, attach the Direct Connect gateway to the new transit gateway, and set up a Site-to-Site VPN private IP connection to the transit gateway..
Why this is the answer
The correct solution uses a Transit Gateway, a transit VIF on Direct Connect, and a Site-to-Site VPN. A transit VIF allows multiple VPCs (via Transit Gateway) to communicate with on-premises resources over Direct Connect. The Site-to-Site VPN provides the necessary encryption over the private Direct Connect link, fulfilling the requirement for encrypted, private-IP communication without traversing the public internet. This combination offers the least operational overhead for encrypted private connectivity. Option 1 is incorrect because a private VIF does not support native encryption, and a Site-to-Site VPN over a private VIF to a VGW is not a standard or efficient pattern for this requirement. Option 3 is incorrect because a public VIF is for public AWS services, not private IP communication with a VPC. Option 4 introduces a third-party firewall, which adds significant operational overhead and complexity compared to a native AWS VPN solution.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed