exam questions

Exam AWS Certified Solutions Architect - Professional SAP-C02 All Questions

View all questions & answers for the AWS Certified Solutions Architect - Professional SAP-C02 exam

Exam AWS Certified Solutions Architect - Professional SAP-C02 topic 1 question 215 discussion

A solutions architect is designing an AWS account structure for a company that consists of multiple teams. All the teams will work in the same AWS Region. The company needs a VPC that is connected to the on-premises network. The company expects less than 50 Mbps of total traffic to and from the on-premises network.

Which combination of steps will meet these requirements MOST cost-effectively? (Choose two.)

  • A. Create an AWS CloudFormation template that provisions a VPC and the required subnets. Deploy the template to each AWS account.
  • B. Create an AWS CloudFormation template that provisions a VPC and the required subnets. Deploy the template to a shared services account. Share the subnets by using AWS Resource Access Manager.
  • C. Use AWS Transit Gateway along with an AWS Site-to-Site VPN for connectivity to the on-premises network. Share the transit gateway by using AWS Resource Access Manager.
  • D. Use AWS Site-to-Site VPN for connectivity to the on-premises network.
  • E. Use AWS Direct Connect for connectivity to the on-premises network.
Show Suggested Answer Hide Answer
Suggested Answer: BD 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
NikkyDicky
Highly Voted 1 year, 9 months ago
Selected Answer: BD
BD they need a (one) VPC, no need for TGW. Use case for subnet sharing via RAM
upvoted 13 times
LuongTo
4 months, 4 weeks ago
why A out?
upvoted 1 times
KennethYY
4 months ago
because deploy to "each account"
upvoted 1 times
...
...
...
8693a49
Most Recent 9 months ago
Selected Answer: AC
They are designing an account structure. This means multiple accounts, implicitly multiple VPCs. So A will take care of account provisioning. (B is incorrect, subnets cannot be shared). To connect to on-prem, site-to-site VPN is sufficient and most cost-effective, and we also need to give access to it from all accounts, so we need a Transit Gateway. Therefore C is the other correct answer. (D is incorrect because it only works for one VPC, one account, and E is incorrect because is more expensive than VPN and not necessary)
upvoted 2 times
helloworldabc
8 months, 1 week ago
just BD
upvoted 1 times
...
8693a49
9 months ago
Correction. VPC subnets can be shared, so BC would work, but the resulting architecture is a networking nightmare. I would not do that.
upvoted 2 times
helloworldabc
8 months, 1 week ago
Transit gateways are not cost-effective
upvoted 1 times
...
...
...
gfhbox0083
9 months, 3 weeks ago
B, D for sure. No need for a TGW
upvoted 1 times
LuongTo
4 months, 4 weeks ago
why A out?
upvoted 1 times
...
...
bacharbhouri
11 months, 1 week ago
Selected Answer: BE Why is nobody considering Direct Connect, it is cheaper than Site to Site VPN.
upvoted 1 times
bacharbhouri
11 months, 1 week ago
the ask here is for most cost effectively choice.
upvoted 1 times
...
...
YOUSSEFSWAID
12 months ago
If you have one VPC why you need to share the subnets ?
upvoted 2 times
...
TonytheTiger
1 year, 1 month ago
Selected Answer: BD
Option BC & NOT C - The MOST cost effective option: AWS Site-to-Site VPN connection pricing still applies in addition to AWS Transit Gateway VPN attachment pricing. So you will be additional cost with both option https://aws.amazon.com/transit-gateway/pricing/
upvoted 2 times
...
ftaws
1 year, 3 months ago
The problem did not say how many VPC. @@@
upvoted 2 times
pk0619
4 months, 1 week ago
there is just one VPC if you select B which makes D the right choice for second answer
upvoted 1 times
...
...
ayadmawla
1 year, 4 months ago
Selected Answer: BC
B+C in my humble opinion. Reason for C is that this is a design for a company with "multiple teams" so it is only logical that these teams will want to have at some stage independent accounts from one another and different accounts within the same teams. Thinking about a single VPC would be a bit short sighted.
upvoted 3 times
...
career360guru
1 year, 5 months ago
Selected Answer: BD
B and D is right choice.
upvoted 2 times
...
lghoshino78
1 year, 5 months ago
Selected Answer: AD
Most Cost Effective...
upvoted 1 times
...
nublit
1 year, 5 months ago
Selected Answer: AD
You need to create a singe VPC and a single Account.
upvoted 1 times
...
SK_Tyagi
1 year, 8 months ago
Selected Answer: BD
Direct Connect may be an overkill with 1GBPs
upvoted 3 times
...
kebmiockey
1 year, 8 months ago
Other problem with VPN is 1.25 Gb limitation.
upvoted 1 times
...
ggrodskiy
1 year, 9 months ago
Correct AD. I think A is correct because you can connect the VPN to each VPC by using a VPN connection resource in each AWS account. You do not need a shared network account for that. You can refer to this documentation for more details: https://docs.aws.amazon.com/vpn/latest/s2svpn/VPC_VPN.html B is not correct because it will create a single VPC for all the AWS accounts, which will reduce the isolation and security for the different teams. It will also require sharing the subnets by using AWS Resource Access Manager, which will add complexity and overhead.
upvoted 3 times
...
Christina666
1 year, 9 months ago
Selected Answer: BD
Tgw is for VPCs communication.
upvoted 1 times
...
SmileyCloud
1 year, 10 months ago
Selected Answer: BC
BC. There are multiple teams and accounts.
upvoted 3 times
...
SkyZeroZx
1 year, 10 months ago
Selected Answer: BD
BD? dont think we need tgw here.
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago