Hard1 markMultiple Choice
Domain 1.1: Network ConnectivityTransit GatewayNetworkingHigh Availability

AWS SAP-C02 · Question 74 · Domain 1.1: Network Connectivity

An enterprise is building a centralized network egress architecture. All internet-bound traffic from 50 VPCs must be routed through a central Egress VPC. The Egress VPC contains a NAT Gateway. The company wants to ensure that if the NAT Gateway in one Availability Zone fails, traffic automatically routes to a NAT Gateway in another Availability Zone. How should the Transit Gateway and VPC routing be configured?

Answer options:

A.

Configure the Transit Gateway route table to failover to the secondary AZ.

B.

Configure the VPC route table to point to a Network Load Balancer (NLB) in front of the NAT Gateways.

C.

This is not natively possible; Transit Gateway routes traffic to the NAT Gateway in the same AZ. High availability requires a NAT Gateway in each AZ.

D.

Use AWS Global Accelerator to route traffic to the healthy NAT Gateway.

How to approach this question

Understand Transit Gateway AZ affinity.

Full Answer

C.This is not natively possible; Transit Gateway routes traffic to the NAT Gateway in the same AZ. High availability requires a NAT Gateway in each AZ.✓ Correct
This is not natively possible; Transit Gateway routes traffic to the NAT Gateway in the same AZ. High availability requires a NAT Gateway in each AZ.
AWS Transit Gateway maintains Availability Zone affinity. Traffic originating from AZ-A in a spoke VPC will be routed to the ENI in AZ-A of the central Egress VPC. Therefore, you must deploy a NAT Gateway in every AZ to ensure high availability; you cannot natively failover cross-AZ within the TGW routing.

Common mistakes

Assuming TGW can do health-check based failover between AZs.

Practice the full AWS Solutions Architect Professional SAP-C02 Practice Exam 4

75 questions · hints · full answers · grading

More questions from this exam