Two companies are merging and each has a substantial AWS footprint with multiple VPCs. Both use Direct Connect with a Direct Connect gateway, and each has a Transit Gateway plus multiple Site-to-Site VPNs from its Transit Gateway to on-premises. The new design must maximize network visibility, throughput, logging, and monitoring. Which architecture meets these goals?
Choose an answer
Tap an option to check your answer.
Correct answer: Peer the two Transit Gateways using Transit Gateway peering. Enable VPC Flow Logs for all VPCs and publish them to CloudWatch. Use AWS Transit Gateway Network Manager to monitor the Transit Gateways, their connections, and the Transit Gateway peering link..
Why this is the answer
The correct option leverages Transit Gateway peering, which is the most scalable and performant method for connecting two Transit Gateways, offering higher throughput than Site-to-Site VPNs between them. VPC Flow Logs to CloudWatch provide comprehensive network visibility and logging for all VPC traffic. AWS Transit Gateway Network Manager is the ideal tool for centralized monitoring of Transit Gateways, their attachments (including Direct Connect, VPNs, and VPCs), and crucially, Transit Gateway peering connections, fulfilling the requirement for maximum visibility and monitoring. The incorrect options propose Site-to-Site VPNs between Transit Gateways, which is less efficient and performant than peering. While VPC Reachability Analyzer is useful for troubleshooting specific reachability issues, AWS Transit Gateway Network Manager offers a broader, centralized monitoring solution for the entire Transit Gateway network, including peering links.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed