Your VPC was originally in a single Availability Zone and connected to on-premises via a Site-to-Site VPN on the virtual private gateway. You added new subnets in a different Availability Zone and launched resources there, but those new resources cannot reach the on-premises network while the original resources still can. What should you do to restore connectivity for the new subnets?
Choose an answer
Tap an option to check your answer.
Correct answer: Add routes in the route tables for the new subnets that direct on-premises destination CIDR blocks to the virtual private gateway..
Why this is the answer
The correct answer is to add routes in the route tables for the new subnets. When you add new subnets, their associated route tables initially only contain local routes. To enable communication with your on-premises network via the existing Site-to-Site VPN, you must explicitly add a route that directs traffic destined for your on-premises CIDR block to the Virtual Private Gateway (VPG). The VPG is a regional resource, so the existing VPN connection can serve resources in any Availability Zone within that region once proper routing is configured. Opening a support case with AWS is unnecessary as this is a configuration issue you can resolve. Creating a separate Site-to-Site VPN is redundant and unnecessary, as the existing VPG and VPN connection can span Availability Zones. Swapping to AWS Direct Connect is a different connectivity solution and doesn't address the immediate routing problem with the existing VPN setup.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed