Example Corp. has an on-premises data center connected to VPC A in their AWS account via a Site-to-Site VPN. Example Corp. acquired AnyCompany, which has VPC B. There is no IP overlap. VPC A and VPC B are peered. On-premises servers can reach VPC A but cannot reach VPC B. Network ACLs and security groups are configured correctly. Which solution provides connectivity from on-premises to VPC B with the least operational effort?
Choose an answer
Tap an option to check your answer.
Correct answer: Create an AWS Transit Gateway, attach the Site-to-Site VPN, VPC A, and VPC B to the transit gateway, and update the transit gateway route tables to include routes for each network's IP ranges..
Why this is the answer
The correct solution is to use AWS Transit Gateway. Transit Gateway simplifies network architecture by acting as a central hub, allowing you to connect your on-premises network (via the existing Site-to-Site VPN) and multiple VPCs (VPC A and VPC B) to a single gateway. This eliminates the need for multiple point-to-point connections and complex routing. By attaching the VPN, VPC A, and VPC B to the Transit Gateway and configuring the route tables, on-premises servers can communicate with both VPC A and VPC B. Creating a new VPN to VPC B is inefficient and increases operational overhead. Updating route tables for the existing VPN and both VPCs directly without a central hub like Transit Gateway would be complex and difficult to manage at scale, especially with BGP propagation. Modifying the Virtual Private Gateway to span two VPCs is not a standard or supported configuration for direct connectivity between two distinct VPCs and an on-premises network.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed