Medium1 markMultiple Choice
Domain 1.1: Network ConnectivityTransit GatewayNetworkingMulti-Region

AWS SAP-C02 · Question 05 · Domain 1.1: Network Connectivity

A global financial institution is migrating its core banking application to AWS. The application requires strict network isolation, centralized egress inspection, and the ability to route traffic between 100+ VPCs across two AWS Regions. What is the MOST scalable architecture?

Answer options:

A.

Create a full mesh of VPC peering connections between all 100+ VPCs across both regions.

B.

Deploy an AWS Transit Gateway in each region. Peer the Transit Gateways. Route egress traffic to a centralized inspection VPC attached to the Transit Gateway.

C.

Use AWS VPN CloudHub to connect all VPCs together using Virtual Private Gateways.

D.

Deploy a single Transit Gateway in one region and attach all 100+ VPCs from both regions to it.

How to approach this question

Evaluate scalability for 100+ VPCs across regions.

Full Answer

B.Deploy an AWS Transit Gateway in each region. Peer the Transit Gateways. Route egress traffic to a centralized inspection VPC attached to the Transit Gateway.✓ Correct
Deploy an AWS Transit Gateway in each region. Peer the Transit Gateways. Route egress traffic to a centralized inspection VPC attached to the Transit Gateway.
AWS Transit Gateway acts as a regional virtual router. To connect VPCs across regions, you deploy a TGW in each region and establish an inter-region peering connection between them.

Common mistakes

Selecting VPC peering for large-scale networks.

Practice the full AWS Solutions Architect Professional SAP-C02 Practice Exam 2

75 questions · hints · full answers · grading

More questions from this exam