An application team cannot launch new resources because a VPC has exhausted usable IP addresses. The VPC CIDR is 172.16.0.0/16. Which additional CIDR block can be associated with this VPC?
Choose an answer
Tap an option to check your answer.
Correct answer: 172.17.0.0/16.
Why this is the answer
When associating a secondary CIDR block with a VPC, it must not overlap with the primary CIDR block or any existing secondary CIDR blocks. The new CIDR block must also be from a private IP address range (RFC 1918). The current VPC CIDR is 172.16.0.0/16. 172.17.0.0/16 is a valid private IP range and does not overlap with 172.16.0.0/16. This makes it a suitable choice. 172.17.0.0/29 is a valid private IP range and does not overlap, but it is too small to significantly address the exhaustion issue. While technically associable, it's not the best solution for the problem described. 10.0.0.0/16 is a valid private IP range and does not overlap, but it is not in the same /16 block as the original VPC. While AWS allows associating CIDRs from different private ranges, the question implies expanding the existing range. 192.168.0.0/16 is a valid private IP range and does not overlap, but similar to 10.0.0.0/16, it's a completely different private IP range.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed