Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.

Unlimited Access

Get Unlimited Contributor Access to the all ExamTopics Exams!
Take advantage of PDF Files for 1000+ Exams along with community discussions and pass IT Certification Exams Easily.

Exam AWS Certified Advanced Networking - Specialty ANS-C01 topic 1 question 100 discussion

A network engineer is designing a hybrid networking environment that will connect a company's corporate network to the company's AWS environment. The AWS environment consists of 30 VPCs in 3 AWS Regions.

The network engineer needs to implement a solution to centrally filter traffic by using a firewall that the company's security team has approved. The solution must give all the VPCs the ability to connect to each other. Connectivity between AWS and the corporate network must meet a minimum bandwidth requirement of 2 Gbps.

Which solution will meet these requirements?

  • A. Deploy an IPsec VPN connection between the corporate network and a new transit gateway. Connect all VPCs to the transit gateway. Associate the approved firewall with the transit gateway.
  • B. Deploy a single 10 Gbps AWS Direct Connect connection between the corporate network and virtual private gateway of each VPC. Connect the virtual private gateways to a Direct Connect gateway. Build an IPsec tunnel to a new transit VPC. Deploy the approved firewall to the transit VPC.
  • C. Deploy two 1 Gbps AWS Direct Connect connections in different Direct Connect locations to connect to the corporate network. Build a transit VIF on each connection to a Direct Connect gateway. Associate the Direct Connect gateway with a new transit gateway for each Region. Configure the VIFs to use equal-cost multipath (ECMP) routing. Connect all the VPCs in the three Regions to the transit gateway. Configure the transit gateway route table to route traffic to an inspection VPDeploy the approved firewall to the inspection VPC.
  • D. Deploy four 1 Gbps AWS Direct Connect connections in different Direct Connect locations to connect to the corporate network. Build a transit VIF on each connection to a Direct Connect gateway. Associate the Direct Connect gateway with a new transit gateway for each Region. Connect the transit gateways by using a transit gateway peering attachment. Configure the VIFs to use equal-cost multipath (ECMP) routing. Configure transit gateway route tables to route traffic to an inspection VPC. Deploy the approved firewall to the inspection VPC.
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
Manh
Highly Voted 1 year, 1 month ago
Selected Answer: D
This solution meets the requirements because: • It uses AWS Direct Connect, which provides a dedicated and private connection between the corporate network and AWS, with a minimum bandwidth of 2 Gbps (4 x 1 Gbps). • It uses a Direct Connect gateway, which allows multiple VPCs in different Regions to share the same Direct Connect connection. • It uses a transit gateway, which acts as a network hub that connects multiple VPCs and other networks, such as the corporate network and the inspection VPC. • It uses a transit gateway peering attachment, which enables routing between transit gateways in different Regions. • It uses ECMP routing, which allows traffic to be distributed across multiple paths for higher throughput and redundancy. • It uses an inspection VPC, which hosts the approved firewall and filters traffic between the corporate network and the AWS environment.
upvoted 5 times
...
Blitz1
Most Recent 1 month, 3 weeks ago
Selected Answer: D
i have read the answers several times and the debate is indeed between C and D. But i believe C) is excluded in the end because: 1) even if it is stating that is creating "a new transit gateway for each Region" after few phrases is saying "Connect all the VPCs in the three Regions to the transit gateway". Ups...you cannot connect all the VPCs in all the regions on only ONE transit gateway. Maybe is phrased bad(maybe they wanted to say something like: attach all the vpcs to their corresponding transit gateways in each region) or it's a big clue. And i believe is the clue. 2) in D we have a transit peering which is required by "The solution must give all the VPCs the ability to connect to each other" BUT this can be a benefit in the answer or a hint for actually disqualify the response. It is not saying in the question if traffic between regions should be inspected or not.(and i see that most of the ppl assumed that only traffic between on-prem and aws should be inspected) - this one is very tricky. So, yes i will go in the end with D just because of (1) and consider (2) a strange bonus.
upvoted 1 times
...
Raphaello
4 months, 4 weeks ago
Selected Answer: D
D is the correct answer.
upvoted 1 times
...
WherecanIstart
6 months, 3 weeks ago
Selected Answer: D
D is the correct answer. You need to peer the transit gateways.
upvoted 2 times
...
Arad
10 months, 1 week ago
Selected Answer: D
I think the correct answer is D.
upvoted 2 times
...
evargasbrz
1 year ago
Selected Answer: C
C is the right, as D didn't say to Connect all the VPCs in the three Regions to the transit gateway. You have no VPCs connected to the TGW in each region, so C is the right.
upvoted 1 times
AWS_Exam_Enjoyer
11 months, 1 week ago
Read: The solution must give all the VPCs the ability to connect to each other. It means it needs the 3 regions to be connected to each other so D the correct answer.
upvoted 1 times
...
...
DeathFrmAbv
1 year, 1 month ago
D provides transit gateway peering, the others don't, so D
upvoted 1 times
...
troopie22
1 year, 2 months ago
Selected Answer: D
I think the key is the need for connecting all the VPCs in different regions together and you can only accomplish that with the TGW peering in D.
upvoted 3 times
...
tcp22
1 year, 2 months ago
D for sure, C does not provide minimum2 Gbps in case of one DX goes down.
upvoted 1 times
...
Balasmaniam
1 year, 3 months ago
Selected Answer: D
option C - each region has a DXGW but maximum 3 VPC can connect on single DXGW without TGW. Option : D , has TGW with DXGW can connect multiple VPC with TGW peering.
upvoted 2 times
Balasmaniam
1 year, 3 months ago
one DXGW can connect maximum 10 VPC
upvoted 2 times
albertkr
1 year, 2 months ago
correct
upvoted 1 times
...
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...