A company is migrating applications to AWS and has established a Direct Connect link in a central network account. The company will have hundreds of AWS accounts and VPCs. Corporate on-premises systems must access AWS resources transparently and communicate with all VPCs. The company also wants to route cloud outbound traffic to the internet via the on-premises data center. Which combination of steps satisfies these requirements? (Choose three.)
Choose an answer
Tap an option to check your answer.
Correct answer: Create a Direct Connect gateway and a Transit Gateway in the central network account. Attach the Transit Gateway to the Direct Connect gateway using a transit virtual interface (transit VIF)., Share the Transit Gateway with other accounts. Attach each VPC to the Transit Gateway., Provision only private subnets. Configure routes on the Transit Gateway and the customer gateway so outbound internet traffic from AWS flows through NAT services running in the on-premises data center..
Why this is the answer
The correct options address the requirements for centralized connectivity, inter-VPC communication, and controlled outbound internet access. Creating a Direct Connect gateway and a Transit Gateway in a central account, then attaching them via a transit VIF, centralizes the Direct Connect connection and allows all VPCs to access on-premises resources through the Transit Gateway. Sharing the Transit Gateway and attaching each VPC enables transparent communication between hundreds of VPCs and provides a single point for on-premises connectivity. Provisioning private subnets and routing all outbound internet traffic through on-premises NAT services via the Transit Gateway and customer gateway ensures that all internet egress is controlled and inspected by corporate security policies. Incorrect options: Creating a Direct Connect gateway and associating it with individual virtual private gateways in each account is not scalable for hundreds of VPCs and doesn't facilitate inter-VPC communication. Provisioning an internet gateway would allow direct internet access from AWS, bypassing the requirement to route traffic through the on-premises data center. VPC peering connections are not scalable for hundreds of VPCs and do not provide a centralized path to on-premises resources or controlled internet egress.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed