A company operates workloads across multiple VPCs and must securely reach a workload in VPC-A from an on-premises data center. A network engineer created an AWS Site-to-Site VPN to a transit gateway and enabled dynamic routing; connectivity worked. VPC-A's owner later added an additional CIDR to VPC-A and launched workloads using that CIDR, but the on-premises network cannot reach those new workloads. The network engineer must restore connectivity and ensure future VPC CIDR additions do not break connectivity with the least operational effort. Which approach meets these requirements most efficiently?
Choose an answer
Tap an option to check your answer.
Correct answer: Enable route propagation from VPC-A to the VPN attachment's route table..
Why this is the answer
Enabling route propagation from VPC-A to the VPN attachment's route table is the most efficient solution. When a new CIDR is added to VPC-A, route propagation automatically updates the transit gateway's VPN attachment route table with the new routes, ensuring on-premises connectivity without manual intervention. This meets the "least operational effort" requirement. Manually adding the new CIDR is incorrect because it requires manual intervention for every CIDR change, failing the "least operational effort" and "future additions" requirements. EventBridge and CloudWatch with Lambda functions are overly complex for this scenario. While they could automate the process, route propagation is a native, simpler, and more direct AWS feature designed for this exact purpose, making the Lambda solutions less efficient operationally. Restarting VPN tunnels is unnecessary and disruptive.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed