SAP-C02 exam dumps

SAP-C02 practice question 31 of 678

AWS Certified Solutions Architect - Professional. Professional level, Amazon Web Services. Free question with the correct answer and a full explanation.

SAP-C02 Question 31

Single answer

A company has deployed a multi-tier web application across multiple AWS accounts and VPCs. The application consists of a front-end hosted in a public subnet in Account A, a back-end API server in a private subnet in Account B, and a database layer in a private subnet in Account C. The requirement is to ensure secure communication between the VPCs while minimizing the operational overhead and ensuring high scalability. Which solution meets these requirements?

  1. A

    Use VPC Peering to establish connections between the VPCs in Account A, Account B, and Account C.

  2. B

    Use AWS Transit Gateway to establish connectivity between the VPCs in the three accounts.

  3. C

    Establish site-to-site VPN connections between the VPCs in Account A, Account B, and Account C.

  4. D

    Use public IP addresses for the instances and configure security groups to allow communication between the VPCs.

Show answer and explanation

Correct answer: B

Explanation

AWS Transit Gateway is the most suitable solution for connecting multiple VPCs across multiple accounts in a scalable and secure manner. It acts as a central hub to simplify routing and management, meeting the requirements of the scenario while minimizing operational overhead. Other options either fail to scale, introduce unnecessary complexity, or do not meet the security requirements.

  • A. Incorrect.

    VPC Peering can establish connectivity between two VPCs, but it does not scale well for a multi-account, multi-VPC architecture. Managing a mesh of peering connections between multiple VPCs can become complex and unmanageable.

  • B. Correct.

    AWS Transit Gateway is the correct choice as it provides a scalable, centralized hub for connecting multiple VPCs across multiple AWS accounts. It simplifies management and ensures secure communication.

  • C. Incorrect.

    Site-to-site VPN is not suitable for VPC-to-VPC communication within AWS. It adds unnecessary complexity and latency, and is primarily used for connecting on-premises networks to AWS.

  • D. Incorrect.

    Using public IP addresses for communication between VPCs is not secure and does not meet the requirement for secure communication. This approach also increases exposure to the internet.

Timed practice exam

Take a SAP-C02 practice test under exam conditions

75 questions in 180 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam