A company has one VPC in us-east-1 and plans a new VPC in us-east-2. The existing VPC has a Site-to-Site VPN to on-premises using a virtual private gateway. The engineer must link the existing VPC and the new VPC and add IPv6 support for the new VPC so new on-premises resources can connect to VPC resources over IPv6. Which solution meets these needs?
Choose an answer
Tap an option to check your answer.
Correct answer: Create a Transit Gateway in both us-east-1 and us-east-2. Attach the existing VPC and the new VPC to their respective Transit Gateways. Create a new Site-to-Site VPN connection to each Transit Gateway with IPv4 and IPv6 support. Configure Transit Gateway peering and route between the VPCs and on-premises..
Why this is the answer
The correct solution uses Transit Gateway peering across regions to connect the VPCs and on-premises networks. Transit Gateway supports IPv6 for VPN connections and VPC attachments, fulfilling the requirement for IPv6 connectivity to on-premises. By creating a Transit Gateway in each region (us-east-1 and us-east-2), attaching the respective VPCs, and then peering the Transit Gateways, you establish a scalable and robust inter-region network. New Site-to-Site VPN connections to each Transit Gateway with IPv4 and IPv6 support enable on-premises access to both VPCs. Incorrect options: Using a Virtual Private Gateway (VPG) for the new VPC and VPC peering for inter-VPC routing does not provide a centralized solution for IPv6 VPN to both VPCs. VPGs are regional and cannot span regions. Attaching both VPCs to a single Transit Gateway in us-east-1 is not possible as VPCs are in different regions (us-east-1 and us-east-2). Transit Gateway attachments must be in the same region as the Transit Gateway.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed