An account has four VPCs in us-east-1: one development VPC and three production VPCs. On-premises connectivity is via Direct Connect and a Direct Connect gateway. Production VPCs may exchange traffic, but the development VPC must be isolated from production. A transit gateway was created with a single route table (default association and propagation disabled), and all VPCs plus the Direct Connect gateway were attached. Each VPC route table points 0.0.0.0/0 to the transit gateway. What steps should the engineer take next to enforce isolation while allowing on-premises connectivity? (Choose three.)
Choose an answer
Tap an option to check your answer.
Correct answer: Associate the production VPC attachments with the existing transit gateway route table. Propagate the routes from these attachments., Associate the Direct Connect gateway attachment with the existing transit gateway route table. Propagate the Direct Connect gateway attachment to this route table., Create a new transit gateway route table. Associate the new route table with the development VPC attachment. Propagate the Direct Connect gateway and development VPC attachment to the new route table..
Why this is the answer
To enforce isolation while allowing on-premises connectivity, a multi-route table strategy is needed. The first correct step is to associate the production VPC attachments with the existing transit gateway route table and propagate their routes. This allows production VPCs to communicate with each other. The second correct step is to associate the Direct Connect gateway attachment with this same route table and propagate its routes, enabling on-premises connectivity to the production VPCs. The third correct step involves creating a new transit gateway route table. This new route table should be associated with the development VPC attachment, and then the Direct Connect gateway and development VPC attachment routes should be propagated to it. This isolates the development VPC, allowing it to reach on-premises resources but preventing communication with production VPCs. Incorrect options: Associating all attachments with the existing route table would allow development and production VPCs to communicate, violating the isolation requirement. Changing security group rules on transit gateway network interfaces is not a valid or effective method for controlling inter-VPC routing at the transit gateway level. Creating a new transit gateway is unnecessary and overcomplicates the solution; a single transit gateway with multiple route tables is sufficient.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed