A company has hundreds of application VPCs plus a shared-services VPC in a single Region and a VPN connection to on premises. Requirements: application VPCs must be isolated from each other; application VPCs need bidirectional traffic to on premises and to the shared-services VPC. The transit gateway was created with default route table association and propagation disabled. The engineer created VPC and VPN attachments and must now meet all requirements using the fewest transit gateway route tables. Which combination of actions achieves this? (Choose two.)
Choose an answer
Tap an option to check your answer.
Correct answer: Create one transit gateway route table that will serve all application VPCs. Associate every application VPC attachment with that transit gateway route table. Propagate the shared-services VPC attachment and the VPN attachment to that application route table., Create a single transit gateway route table that contains both the on-premises and the shared-services VPC routes. Associate the VPN attachment and the shared-services VPC attachment with this transit gateway route table. Propagate all application VPC attachments to this transit gateway route table..
Why this is the answer
The correct options leverage a single transit gateway route table to simplify routing for application VPCs. The first correct option creates one route table for all application VPCs. By associating all application VPC attachments with this route table and propagating the shared-services VPC and VPN attachments to it, all application VPCs gain bidirectional access to shared services and on-premises. This meets the requirements while keeping application VPCs isolated from each other because they only see routes to shared services and on-premises, not to other application VPCs. The second correct option is similar, consolidating routes for on-premises and shared services into a single route table. Associating the VPN and shared-services VPC attachments with this table and propagating all application VPC attachments to it achieves the same outcome: all application VPCs can reach shared services and on-premises, and remain isolated from each other. The incorrect options either create too many route tables (e.g., one per application VPC, which is inefficient for hundreds of VPCs) or don't fully meet the bidirectional communication requirement for all necessary connections.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed