A company has hundreds of VPCs across many AWS accounts and wants to connect those accounts to its on-premises network. Site-to-Site VPNs already exist in a single AWS account. The company wants to control which VPCs can talk to which other VPCs with minimal operational effort. Which combination of steps will achieve this? (Choose three.)
Choose an answer
Tap an option to check your answer.
Correct answer: Create an AWS Transit Gateway in an AWS account and share it across accounts using AWS Resource Access Manager (AWS RAM)., Create Transit Gateway attachments to all relevant VPCs and to the VPN connections., Create Transit Gateway route tables and associate VPCs and VPNs with the appropriate route tables..
Why this is the answer
The correct options leverage AWS Transit Gateway for scalable, centralized network connectivity. Creating a Transit Gateway in a central account and sharing it via AWS RAM allows all VPCs across accounts to connect to a single gateway, simplifying management. Creating Transit Gateway attachments for all VPCs and existing VPN connections centralizes routing. Using Transit Gateway route tables to associate specific VPCs and VPNs provides granular control over traffic flow between different networks and segments, meeting the requirement for controlling which VPCs can communicate with others with minimal operational effort. Incorrect options: VPC peering is not scalable for hundreds of VPCs and does not centralize connectivity to on-premises networks. Configuring attachments between VPCs and VPNs directly would require individual connections for each VPC, which is not scalable or easily manageable. Configuring route tables on individual VPCs and VPNs would be operationally intensive for hundreds of VPCs and would not provide centralized traffic control.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed