After an IP exhaustion incident that impacted service capacity, a network engineer must implement monitoring of IP usage across multiple VPCs (each with subnets in multiple AZs) and receive alerts before incidents occur. Which approach gives the required monitoring with the least operational overhead?
Choose an answer
Tap an option to check your answer.
Correct answer: Set up Amazon VPC IP Address Manager (IPAM) with a new top-level pool. Create a pool for each VPC under the top-level pool, and within each VPC pool create a pool for each subnet. Enable auto-import for the VPC and subnet pools. Configure an Amazon CloudWatch alarm to publish an Amazon SNS notification when a pool's availability threshold is reached..
Why this is the answer
The correct option leverages Amazon VPC IP Address Manager (IPAM) because it is purpose-built for managing and monitoring IP addresses across multiple VPCs and subnets, directly addressing the core problem. Auto-import simplifies the setup by automatically discovering and tracking IP usage. Integrating with CloudWatch alarms and SNS provides native, low-overhead alerting when availability thresholds are met, preventing future exhaustion incidents. The other options involve custom solutions (Lambda, CloudWatch Logs, custom metrics) which introduce significant operational overhead for development, maintenance, and scaling, making them less efficient than IPAM's native capabilities. While EventBridge can trigger actions, CloudWatch Alarms are the standard and most direct way to monitor IPAM pool availability thresholds.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed