A company has two domain controllers in a shared-services VPC placed in private subnets. They are deploying a new application to a new VPC in the same account on a Windows Server EC2 instance that must join the domain hosted in the shared-services VPC. A Transit Gateway is attached to both VPCs and route tables on the Transit Gateway and in both VPCs have been updated. Security groups on the domain controllers and on the new instance permit only the ports required for domain traffic. The instance cannot join the domain. Which two steps will help diagnose the problem with the least operational effort?
Choose an answer
Tap an option to check your answer.
Correct answer: Use AWS Network Manager to run a route analysis for the transit gateway network. Use the existing EC2 instance as the source and the first domain controller as the destination. Repeat the route analysis for the second domain controller., Review the VPC flow logs for the shared-services VPC and for the new VPC..
Why this is the answer
AWS Network Manager's route analyzer is an efficient tool for diagnosing routing issues across a Transit Gateway. It simulates traffic flow from the EC2 instance to the domain controllers, identifying any misconfigurations in Transit Gateway attachments, route tables, or security groups that prevent connectivity. This directly addresses potential network path problems. VPC Flow Logs provide detailed information about IP traffic going to and from network interfaces in your VPC. Reviewing these logs for both the shared-services VPC and the new VPC will reveal if traffic is reaching the domain controllers and if any security group or network ACL rules are implicitly denying the connection, offering insights into why the domain join is failing. Port mirroring is complex to set up and analyze, requiring an additional EC2 instance and specialized tools, making it less operationally efficient for initial diagnosis. Pinging from a domain controller only checks basic ICMP connectivity, not the specific ports or protocols required for domain join, and doesn't provide detailed routing or security information. Verifying route propagation disabled on the shared-services VPC is incorrect; route propagation is typically enabled for Transit Gateway attachments to simplify routing.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed