A company (TGW-C) has multiple VPCs in us-east-1 using CIDRs within 10.10.0.0/16 and a transit gateway TGW-C with ASN 64520. A partner has VPCs in us-east-1 using CIDRs within 172.16.0.0/16 and a transit gateway TGW-P with ASN 64530. The engineer must connect the company’s VPCs to the partner’s VPCs in us-east-1 with minimal changes to both networks. Which solution meets this requirement?
Choose an answer
Tap an option to check your answer.
Correct answer: Configure a cross-account transit gateway peering attachment between TGW-C and TGW-P. Configure the transit gateway route tables so traffic flows over the peering attachment..
Why this is the answer
The most efficient solution is to configure a cross-account transit gateway peering attachment between TGW-C and TGW-P. This allows direct routing between the two transit gateways, enabling communication between the company's and partner's VPCs with minimal changes. Each transit gateway's route tables must be updated to direct traffic for the other network's CIDRs over the peering attachment. Creating a new VPC with a router from the AWS Marketplace is overly complex and introduces additional management overhead and cost. An IPsec VPN connection between transit gateways is possible but less efficient and scalable than a direct peering attachment. Sharing TGW-C with the partner account would require the partner to associate their VPCs with the company's transit gateway, which violates the requirement for minimal changes to both networks and could lead to complex routing and security implications.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed