A solutions architect is designing an AWS account and networking structure for multiple teams that all operate in the same AWS Region. The company needs a VPC that connects to the on-premises network and expects less than 50 Mbps of total traffic to/from on-premises. Which combination of steps is the MOST cost-effective way to meet these requirements? (Choose two.)
Choose an answer
Tap an option to check your answer.
Correct answer: Create an AWS CloudFormation template that provisions a VPC and required subnets, deploy that template in a shared services account, and share the subnets using AWS Resource Access Manager (RAM)., Use AWS Site-to-Site VPN for connectivity to the on-premises network..
Why this is the answer
The most cost-effective solution involves using AWS Site-to-Site VPN for on-premises connectivity because the traffic requirement is low (less than 50 Mbps). AWS Direct Connect, while offering higher bandwidth and consistent performance, is significantly more expensive and overkill for this use case. To manage VPCs across multiple teams efficiently and cost-effectively, creating a CloudFormation template for the VPC and subnets, deploying it in a shared services account, and then sharing those subnets via AWS Resource Access Manager (RAM) is ideal. This centralizes networking resources, reduces duplication, and simplifies management. Using AWS Transit Gateway adds unnecessary cost and complexity for a single-region setup with low traffic requirements, especially when a Site-to-Site VPN can be directly attached to the shared VPC.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed