SCS-C02 exam dumps

SCS-C02 practice question 218 of 504

AWS Certified Security - Specialty. Expert level, Amazon Web Services. Free question with the correct answer and a full explanation.

SCS-C02 Question 218

Single answer

Your organization has two VPCs in the same AWS region, VPC-A and VPC-B. VPC-A hosts a critical database with sensitive data, and VPC-B hosts application servers that need to query the database. Due to compliance requirements, you must ensure that all traffic between the VPCs remains within the AWS network and does not traverse the public internet. Additionally, the solution should minimize configuration complexity and support future scalability. Which solution should you implement?

  1. A

    Set up a VPC peering connection between VPC-A and VPC-B, and configure route tables to allow traffic.

  2. B

    Use an AWS Transit Gateway to connect VPC-A and VPC-B and configure route tables accordingly.

  3. C

    Create an interface VPC endpoint in VPC-B for the database in VPC-A.

  4. D

    Deploy a NAT gateway in both VPCs to route traffic securely between them.

Show answer and explanation

Correct answer: B

Explanation

AWS Transit Gateway is the most appropriate solution for inter-VPC connectivity in this scenario. It ensures that traffic remains within the AWS private network, supports future scalability, and simplifies management with a centralized hub-and-spoke model. While other options might enable connectivity, they either do not meet the compliance requirement or fail to provide a scalable and centralized architecture.

  • A. Incorrect.

    While VPC peering can connect two VPCs, it may not be ideal for future scalability as it requires a separate peering connection for each additional VPC. It also lacks centralized management.

  • B. Correct.

    AWS Transit Gateway is the best option as it provides scalable, centralized, and private connectivity between multiple VPCs, ensuring traffic remains within the AWS network.

  • C. Incorrect.

    An interface VPC endpoint is used to connect to AWS services privately. It is not suitable for connecting two VPCs directly.

  • D. Incorrect.

    NAT gateways are used to provide internet access for private instances, but they are not designed for inter-VPC connectivity. Additionally, they would not meet the requirement of keeping traffic within the AWS network.

Timed practice exam

Take a SCS-C02 practice test under exam conditions

65 questions in 170 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam