A company wants to let employees work from home by connecting via VPN to access internal applications hosted in VPCs across multiple AWS accounts. Currently on-premises office users access these apps over a Site-to-Site VPN and VPC peering from the main account to other accounts' VPCs. For a scalable and cost-effective AWS Client VPN solution for remote employees, what should the solutions architect do?
Choose an answer
Tap an option to check your answer.
Correct answer: Create a single AWS Client VPN endpoint in the main AWS account and configure routing to allow access to internal applications..
Why this is the answer
Creating a single AWS Client VPN endpoint in the main AWS account is the most scalable and cost-effective solution. This centralizes management and reduces operational overhead compared to deploying multiple endpoints. By configuring appropriate routing within the Client VPN and the connected VPCs (potentially using VPC peering or Transit Gateway, though not explicitly chosen as the primary solution here), remote users can securely access applications across all specified VPCs. Creating a separate Client VPN endpoint in each account would be more complex and expensive to manage. While a Transit Gateway solution is viable, the question implies existing VPC peering, making a single Client VPN endpoint with routing a more direct and potentially simpler initial step if peering is already established. Connecting the Client VPN to the existing Site-to-Site VPN is not a standard or efficient way to provide remote user access to internal applications; Site-to-Site VPNs are typically for connecting networks, not individual clients.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed