exam questions

Exam AWS Certified Solutions Architect - Professional All Questions

View all questions & answers for the AWS Certified Solutions Architect - Professional exam

Exam AWS Certified Solutions Architect - Professional topic 1 question 869 discussion

A solutions architect is designing a solution to connect a company's on-premises network with all the company's current and future VPCs on AWS. The company is running VPCs in five different AWS Regions and has at least 15 VPCs in each Region.
The company's AWS usage is constantly increasing and will continue to grow. Additionally, all the VPCs throughout all five Regions must be able to communicate with each other.
The solution must maximize scalability and ease of management.
Which solution meets these requirements?

  • A. Set up a transit gateway in each Region. Establish a redundant AWS Site-to-Site VPN connection between the on-premises firewalls and the transit gateway in the Region that is closest to the on-premises network. Peer all the transit gateways with each other. Connect all the VPCs to the transit gateway in their Region.
  • B. Create an AWS CloudFormation template for a redundant AWS Site-to-Site VPN tunnel to the on-premises network. Deploy the CloudFormation template for each VPC. Set up VPC peering between all the VPCs for VPC-to-VPC communication.
  • C. Set up a transit gateway in each Region. Establish a redundant AWS Site-to-Site VPN connection between the on-premises firewalls and each transit gateway. Route traffic between the different Regions through the company's on-premises firewalls. Connect all the VPCs to the transit gateway in their Region.
  • D. Create an AWS CloudFormation template for a redundant AWS Site-to-Site VPN tunnel to the on-premises network. Deploy the CloudFormation template for each VPC. Route traffic between the different Regions through the company's on-premises firewalls.
Show Suggested Answer Hide Answer
Suggested Answer: A 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Bigbearcn
Highly Voted 2 years, 7 months ago
Selected Answer: A
I think it's A. The solution must maximize scalability and ease of management. There are too much VPC, so B is wrong.
upvoted 9 times
snakecharmer2
2 years, 7 months ago
It is A - intra-region transit gateways peering - https://aws.amazon.com/blogs/networking-and-content-delivery/aws-transit-gateway-now-supports-intra-region-peering/
upvoted 2 times
delfnec
2 years, 7 months ago
but they have 5 regions so you cant pearing them...
upvoted 1 times
...
delfnec
2 years, 7 months ago
oh sorry ,then can...here is the url... https://aws.amazon.com/about-aws/whats-new/2019/12/aws-transit-gateway-supports-inter-region-peering/?nc1=h_ls
upvoted 1 times
...
...
...
Blair77
Most Recent 2 years, 1 month ago
Selected Answer: A
AAA for me!
upvoted 1 times
...
bobsmith2000
2 years, 6 months ago
Selected Answer: A
A or C. A looks better, because we don't need to create lots of VPNs and route traffic through onprem
upvoted 3 times
wassb
2 years, 1 month ago
It's A. In C, the TGW are not peered and the VPCs throughout the region wont be able to communicate.
upvoted 1 times
...
...
mirnuj_atom
2 years, 7 months ago
I think C fits better, the company already has 75 VPCs and plans to grow. So setting up 1 to 74 peering connections per VPC and updating the pool for each new VPC sounds like a mess to me.
upvoted 2 times
Rocketeer
2 years, 3 months ago
one transit gateway per region. Hence the transit gateways in different regions need to be peered. Hence A.
upvoted 1 times
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago