A company manages multiple AWS accounts with AWS Organizations. Some shared applications run in a VPC in the shared services account. A Transit Gateway is attached to that VPC. A development team needs access from a development account to the shared services applications. The development environment is frequently destroyed and recreated, and the team must be able to recreate its connection to the shared services account as needed. Which design meets these requirements?
Choose an answer
Tap an option to check your answer.
Correct answer: Enable automatic acceptance on the Transit Gateway in the shared services account. Use AWS Resource Access Manager (RAM) to share the Transit Gateway resource from the shared services account with the development account. Accept the shared resource in the development account and create a Transit Gateway attachment there..
Why this is the answer
Sharing the Transit Gateway (TGW) via AWS Resource Access Manager (RAM) allows the development account to create its own TGW attachment to the shared services TGW. This is efficient because the development team can manage their attachment lifecycle independently, which aligns with their need to frequently destroy and recreate their environment. Enabling automatic acceptance on the shared services TGW streamlines the connection process. Creating a separate TGW in the development account and peering it with the shared services TGW adds unnecessary complexity and cost compared to a direct attachment. VPC Endpoints are for private access to AWS services or services hosted on AWS, not for connecting VPCs via Transit Gateway. Using EventBridge and Lambda for attachment requests is overly complex and not the standard, scalable solution for TGW sharing.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed