ANS-C01 exam dumps

ANS-C01 practice question 245 of 513

AWS Certified Advanced Networking - Specialty. Expert level, Amazon Web Services. Free question with the correct answer and a full explanation.

ANS-C01 Question 245

Single answer

Your organization has multiple AWS accounts, each with its own set of VPCs. You need to establish secure and scalable connectivity between these VPCs across accounts, while minimizing operational overhead. Additionally, you require the ability to route traffic between on-premises environments and these VPCs. Which solution would best meet these requirements?

  1. A

    Use VPC peering to connect all VPCs and set up individual VPN connections to on-premises environments.

  2. B

    Deploy an AWS Transit Gateway to interconnect VPCs across accounts and use the same Transit Gateway to establish a Direct Connect or VPN attachment for on-premises connectivity.

  3. C

    Use a third-party SD-WAN solution to connect all VPCs and create a separate SD-WAN link for on-premises connectivity.

  4. D

    Set up a multi-account AWS PrivateLink implementation to connect VPCs and use AWS Site-to-Site VPN for on-premises connectivity.

Show answer and explanation

Correct answer: B

Explanation

AWS Transit Gateway is the most appropriate option for interconnecting multiple VPCs across accounts while providing on-premises connectivity. It simplifies network management by acting as a central hub, supports scalable routing configurations, and integrates well with AWS Direct Connect and VPN for hybrid cloud scenarios. This makes it an ideal choice for the scenario described.

  • A. Incorrect.

    VPC peering can create direct connections between VPCs, but it does not easily scale as the number of VPCs increases, especially across multiple accounts. Additionally, VPN connections to on-premises environments are managed individually, leading to higher operational overhead.

  • B. Correct.

    AWS Transit Gateway is a scalable solution for interconnecting multiple VPCs across accounts. It simplifies the network architecture by acting as a central hub, and it supports attachments for both AWS Direct Connect and VPN, enabling seamless on-premises connectivity.

  • C. Incorrect.

    While SD-WAN solutions can provide interconnectivity, they are often not as tightly integrated with AWS services as AWS Transit Gateway. This approach would add unnecessary complexity and cost.

  • D. Incorrect.

    AWS PrivateLink is typically used for service-to-service communication within or across VPCs, not for general-purpose VPC interconnectivity. It is not suitable for routing traffic between multiple VPCs and on-premises environments.

Timed practice exam

Take a ANS-C01 practice test under exam conditions

65 questions in 170 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam