A company uses a transit gateway to connect many VPCs. Changes to security groups, network ACLs, or route tables in a VPC have in the past caused loss of connectivity. When such changes occur, the company wants an automatic verification that connectivity between resources within a single VPC still works. Which solution accomplishes this?
Choose an answer
Tap an option to check your answer.
Correct answer: Create the set of paths to verify in VPC Reachability Analyzer. Create an Amazon EventBridge rule that watches for configuration changes logged in AWS CloudTrail. Configure the rule to invoke a Lambda function that tests the listed paths in Reachability Analyzer..
Why this is the answer
The correct solution uses VPC Reachability Analyzer to define and test connectivity paths within a VPC. CloudTrail logs API calls for configuration changes (e.g., security groups, NACLs, route tables), making it the appropriate service for EventBridge to monitor. When CloudTrail logs a relevant change, EventBridge triggers a Lambda function. This Lambda function then invokes Reachability Analyzer to re-evaluate the defined paths, automatically verifying connectivity. The incorrect options are: Using CloudWatch logs for configuration changes is less precise than CloudTrail, which specifically logs API calls. Transit Gateway Network Manager Route Analyzer is designed for analyzing routes through a Transit Gateway, not for verifying connectivity within a single VPC. The question specifically asks about connectivity between resources within a single VPC.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed