Data transfer between on-premises systems and EC2 instances in VPCs is being limited by the throughput of a single Site-to-Site VPN to an AWS Transit Gateway. The design needs to be highly available, secure, and scale VPN throughput from on premises to VPCs as traffic grows. Which design meets these requirements?
Choose an answer
Tap an option to check your answer.
Correct answer: Configure multiple dynamic BGP-based Site-to-Site VPN connections to the transit gateway. Configure equal-cost multi-path routing (ECMP)..
Why this is the answer
The correct answer is to configure multiple dynamic BGP-based Site-to-Site VPN connections to the Transit Gateway and enable ECMP. This approach provides high availability because if one VPN tunnel or connection fails, traffic can automatically failover to another. BGP allows for dynamic routing updates, which is crucial for ECMP to distribute traffic across multiple paths. ECMP enables the aggregation of throughput from multiple VPN tunnels, scaling the overall bandwidth as needed. Incorrect options: Static routing-based VPNs do not support ECMP for load balancing across multiple tunnels effectively, limiting throughput scaling and dynamic failover capabilities. While VPN acceleration can improve performance for a single connection, it doesn't provide the same level of high availability or aggregate throughput scaling as multiple ECMP-enabled VPNs. A software appliance-based VPN on an EC2 instance introduces a single point of failure and management overhead, and its throughput is limited by the EC2 instance type and network configuration, not offering the same scalability or native integration as Transit Gateway VPNs.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed