AWS SAP-C02 · Question 01 · Domain 1.1: Network Connectivity
A global enterprise is redesigning its AWS network architecture across 50 AWS accounts and 3 AWS Regions. They currently use VPC peering, which has become unmanageable. The new architecture must support transitive routing, centralized outbound internet access, and dedicated hybrid connectivity to two on-premises data centers via AWS Direct Connect. Which solution meets these requirements with the LEAST operational overhead?
Answer options:
Deploy AWS Transit Gateway in each Region. Peer the Transit Gateways. Attach VPCs and a Direct Connect gateway to the Transit Gateways. Route outbound traffic to a centralized egress VPC in each Region.
Deploy a single global AWS Transit Gateway. Attach all VPCs across all Regions to this Transit Gateway. Attach a Direct Connect gateway. Route outbound traffic through a single egress VPC.
Use AWS Cloud WAN to create a global core network. Attach VPCs directly to the Direct Connect gateway. Use NAT Gateways in every VPC for internet access.
Maintain VPC peering but automate it using AWS Resource Access Manager (RAM). Terminate Direct Connect on a Transit VPC using software VPN appliances.
75 questions · hints · full answers · grading