ANS-C01 exam dumps

ANS-C01 practice question 238 of 513

AWS Certified Advanced Networking - Specialty. Expert level, Amazon Web Services. Free question with the correct answer and a full explanation.

ANS-C01 Question 238

Select 2

Your organization has three AWS accounts (Account A, Account B, Account C), each hosting a VPC in the same AWS Region but with different CIDR ranges. The VPCs need to communicate with each other for inter-application traffic. Additionally, Account A hosts a centralized security inspection service that other VPCs must route traffic through before reaching their destination. How can you implement this architecture while minimizing operational overhead and ensuring scalability?

  1. A

    Establish VPC peering connections between all three VPCs and configure routes to send traffic through Account A's VPC for inspection.

  2. B

    Use AWS Transit Gateway to connect the three VPCs and configure a route table to send traffic through Account A's centralized inspection service.

  3. C

    Enable AWS PrivateLink in the centralized VPC in Account A and create interface endpoints in the other VPCs for service access.

  4. D

    Use AWS Transit Gateway with a centralized inspection VPC attachment in Account A and configure routing to force all inter-VPC traffic through the inspection service.

  5. E

    Set up a site-to-site VPN between the VPCs in Account B and Account C to Account A for routing inspection traffic.

Show answer and explanation

Correct answers: B, D

Explanation

To implement routing and connectivity across multiple AWS accounts while supporting centralized inspection and scalability, AWS Transit Gateway is the best solution. It simplifies the architecture by enabling centralized connectivity and routing configuration. By attaching a centralized inspection VPC in Account A to the Transit Gateway and configuring route tables appropriately, all inter-VPC traffic can be inspected without creating a complex peering mesh or relying on less scalable solutions like VPNs.

  • A. Incorrect.

    VPC peering does not scale well in multi-account environments as it requires a mesh of connections. Additionally, it doesn’t natively support centralized traffic inspection.

  • B. Correct.

    AWS Transit Gateway provides scalable, centralized connectivity between multiple VPCs and accounts. Configuring a route table to forward traffic through Account A’s VPC for inspection aligns with the requirements.

  • C. Incorrect.

    AWS PrivateLink is used for private access to services but is not suitable for routing all inter-VPC traffic through an inspection service.

  • D. Correct.

    Using AWS Transit Gateway with a centralized inspection VPC attachment ensures traffic routing through the inspection service. This approach is scalable and simplifies connectivity.

  • E. Incorrect.

    Site-to-site VPNs are not necessary for VPC-to-VPC connectivity within a Region and would introduce unnecessary complexity and latency.

Timed practice exam

Take a ANS-C01 practice test under exam conditions

65 questions in 170 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam