A retailer has a Direct Connect link between its datacenter and AWS in eu-west-2 where multiple VPCs are attached to a transit gateway. The retailer recently created resources in eu-central-1 in a single VPC. The engineer must connect the eu-central-1 resources to both the on-premises datacenter and to resources in eu-west-2 while minimizing changes to the existing Direct Connect. What should the engineer do?
Choose an answer
Tap an option to check your answer.
Correct answer: Create a new transit gateway in eu-central-1. Create a transit gateway peering attachment request to the transit gateway in eu-west-2. Add a static route in the eu-central-1 transit gateway route table that points to the peering attachment. Accept the peering request. Add a static route in the eu-west-2 transit gateway route table that points to the peering attachment to the new transit gateway..
Why this is the answer
The correct solution involves creating a new Transit Gateway in eu-central-1 and peering it with the existing Transit Gateway in eu-west-2. This allows resources in eu-central-1 to communicate with resources in eu-west-2 and, via the eu-west-2 Transit Gateway, with the on-premises datacenter over the existing Direct Connect. Route table entries on both Transit Gateways ensure proper traffic flow. This approach leverages Transit Gateway's capabilities for inter-region connectivity and minimizes changes to the existing Direct Connect setup. Option 1 is incorrect because a virtual private gateway (VPG) is for a single VPC and doesn't scale well for multiple VPCs or inter-region connectivity via a Transit VIF. A Transit VIF connects to a Transit Gateway, not directly to a VPG. Option 3 is incorrect because while an AWS Site-to-Site VPN could connect the two Transit Gateways, peering is generally preferred for inter-region Transit Gateway communication due to better performance and lower administrative overhead for this specific use case. Option 4 is incorrect because a public virtual interface (public VIF) is used to access public AWS services, not private resources within a VPC or over a private connection like Direct Connect.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed