A retail firm is migrating its on-premises application to AWS. It has two on-prem data centers (east and west coasts), each with four databases (largest is 500 GB). The data centers sync over two 10 GbE circuits. Each data center has two separate 1 GbE internet upstream links. The plan is eight VPCs: four in us-east-1 and four in us-west-2. You must provide VPC-to-VPC connectivity and secure connectivity between on-prem data centers and AWS for the migration. Expect traffic spikes between VPCs during database synchronization. The migration should run over one weekend and start as soon as technically possible. Minimize long-term operational and staffing costs. Which combination of steps satisfies these requirements? (Choose two.)
Choose an answer
Tap an option to check your answer.
Correct answer: Provision two AWS Direct Connect connections from two Direct Connect locations that serve us-east-1 and us-west-2 to provide connectivity between the data centers and AWS., Provision one transit gateway VPN attachment for each data center to build connectivity between the on-premises data centers and AWS VPCs..
Why this is the answer
The correct answers are provisioning two Direct Connect connections and one transit gateway VPN attachment per data center. Direct Connect provides dedicated, high-bandwidth, low-latency connections essential for migrating large databases (500 GB) and handling traffic spikes during synchronization, especially within a tight weekend migration window. Using two Direct Connect connections across two regions ensures redundancy and regional proximity for the respective AWS VPCs. The transit gateway VPN attachments allow the on-premises data centers to securely connect to the AWS Transit Gateway, which then provides connectivity to all eight VPCs. This centralizes connectivity management, reducing operational overhead and staffing costs compared to managing individual VPNs to each VPC. Configuring VPC peering between all VPCs would create a complex mesh network (28 peering connections for 8 VPCs), which is difficult to manage and scale, especially with the addition of on-premises connectivity. Provisioning one AWS Site-to-Site VPN connection for each data center and for each VPC would also lead to a complex and unmanageable setup (8 VPCs 2 data centers = 16 VPN connections), increasing operational costs. Deploying one transit gateway and attaching all VPCs is a good step for intra-AWS connectivity but doesn't address the on-premises connection requirement.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed