A company has two VPCs: VPC A (192.168.0.0/16) and VPC B (10.0.0.0/16) in separate Regions. Remote users outside the office need encrypted internet access to applications in both VPCs. The solution should minimize management overhead. Which combination of steps should the engineer implement? (Choose three.)
Choose an answer
Tap an option to check your answer.
Correct answer: Establish a VPC peering connection between VPC A and VPC B., Create an AWS Client VPN endpoint in VPC A Add an authorization rule to grant access to VPC A and VPC B., Add a route to the AWS Client VPN endpoint's route table to direct traffic to VPC B..
Why this is the answer
To allow remote users encrypted access to applications in both VPCs, an AWS Client VPN endpoint is needed. Creating one in VPC A (or B) is sufficient, as it can be configured to reach the other VPC. An authorization rule grants users access to the specified VPCs. A VPC peering connection between VPC A and VPC B is essential to enable private communication between them across different regions. Finally, a route must be added to the Client VPN endpoint's route table to direct traffic destined for VPC B through the peering connection, allowing users connected to the Client VPN in VPC A to reach resources in VPC B. Establishing a Site-to-Site VPN between VPCs is incorrect because VPC peering is simpler for inter-VPC communication. Creating Client VPN endpoints in both VPCs is unnecessary and increases management overhead. Adding a route to VPC A from the Client VPN endpoint in VPC A is redundant, as the endpoint is already within VPC A.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed