exam questions

Exam AWS Certified Advanced Networking - Specialty ANS-C01 All Questions

View all questions & answers for the AWS Certified Advanced Networking - Specialty ANS-C01 exam

Exam AWS Certified Advanced Networking - Specialty ANS-C01 topic 1 question 97 discussion

A software-as-a-service (SaaS) company is migrating its private SaaS application to AWS. The company has hundreds of customers that connect to multiple data centers by using VPN tunnels. As the number of customers has grown, the company has experienced more difficulty in its effort to manage routing and segmentation of customers with complex NAT rules.

After the migration to AWS is complete, the company's AWS customers must be able to access the SaaS application directly from their VPCs. Meanwhile, the company's on-premises customers still must be able to connect through IPsec encrypted tunnels.

Which solution will meet these requirements?

  • A. Connect the AWS customer VPCs to a shared transit gateway. Use AWS Site-to-Site VPN connections to the transit gateway for the on-premises customers
  • B. Use AWS PrivateLink to connect the AWS customers. Use a third-party routing appliance in the SaaS application VPC to terminate onpremises Site-to-Site VPN connections.
  • C. Peer each AWS customer's VPCs to the VPC that hosts the SaaS application. Create AWS Site-to-Site VPN connections on the SaaS VPC virtual private gateway.
  • D. Use Site-to-Site VPN tunnels to connect each AWS customer's VPCs to the VPC that hosts the SaaS application. Use AWS Site-to-Site VPN to connect the on-premises customers.
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️


Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Highly Voted 1 year, 8 months ago
Selected Answer: B
You don't want to mess with customer's AWS VPC, whether via VPC peering or Transit gateway. The standard solution is always VPC endpoint with AWS Privatelink.
upvoted 12 times
1 year, 7 months ago
it is very unlikely that the solution expected from the question is from a different appliance from AWS. in this answer, it uses another routing appliance to provide the VPN solution for on-prem customers.
upvoted 1 times
Highly Voted 1 year, 7 months ago
Selected Answer: B
kry point " the company has experienced more difficulty in its effort to manage routing and segmentation of customers with complex NAT rules." do again routing on TGW required ? Ans B.
upvoted 5 times
1 year, 7 months ago
key point " the company has experienced more difficulty in its effort to manage routing and segmentation of customers with complex NAT rules." do need routing again on TGW required ? Ans B.
upvoted 2 times
Most Recent 1 month ago
Selected Answer: A
AWS PrivateLink is ideal for connecting AWS customers but does not support routing or IPsec connections for on-premises customers. Using a third-party routing appliance introduces additional complexity, cost, and potential performance bottlenecks.
upvoted 1 times
3 months ago
Selected Answer: A
should be A
upvoted 1 times
5 months, 3 weeks ago
A is the correct answer. Why do you even need private links and a third party appliance? Why complicate it again when this can be simply done using the Transit Gateway?
upvoted 3 times
1 year, 1 month ago
agreed, B is the right answer
upvoted 1 times
1 year, 6 months ago
Selected Answer: B
Going with B Though A is correct as well but there are some problems choosing that option 1] Company already experienced issues in managing growing customer base. with Option A, company has to share TGW with each new customer then they will attach their VPC and configure routing on their VPC. Plus company will have to edit TGW route table as well as application VPC route table for connectivity. So it not a good option if company is switching to new option to better manage growing cx need 2] Question mentions that "Saas application should be accessible DIRECTLY from cx VPC". With Option A, it not accessed directly cause we are routing the traffic via TGW to VPC and then to the actual application EC2 Thus, overall Option B is correct
upvoted 4 times
1 year, 7 months ago
B is the correct The is an adjustable limit of 50 with s2s vpn connections and customer gateways per Region. https://docs.aws.amazon.com/vpn/latest/s2svpn/vpn-limits.html Private link for connecting from customer's vpc and third party appliances for multiple s2s vpn connections with customers data centers seems to be the best solution
upvoted 3 times
1 year, 7 months ago
Selected Answer: A
vote for A
upvoted 3 times
1 year, 8 months ago
Should be A
upvoted 4 times
1 year, 8 months ago
and then allow each customer's VPC to access other customers' VPCs freely?
upvoted 1 times
1 year, 7 months ago
you can create multiple routing tables in TGW to prevent customer VPCs communicating each other.
upvoted 1 times
1 year, 6 months ago
This will not work as the VPC hosting the SaaS application can only be associated to a single TGW route table and therefore will lead to the condition has Iygf has stated. Answer A is not correct. All the best.
upvoted 1 times
1 year, 8 months ago
Yes A is the correct answer
upvoted 2 times
Community vote distribution
A (35%)
C (25%)
B (20%)
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

Loading ...
Someone Bought Contributor Access for:
London, 1 minute ago