AWS Certified SysOps Administrator – AssociateNetworking and Content DeliveryMedium
A company is using AWS Transit Gateway to connect multiple VPCs and on-premises networks. A SysOps administrator needs to ensure that traffic between two specific VPCs (VPC A and VPC B) connected to the Transit Gateway never traverses the public internet, even if they are in different AWS regions. Which Transit Gateway feature is required?
- AVPC peering connection.
- BAWS Site-to-Site VPN.
- CAWS Direct Connect.
- DTransit Gateway peering.
Show answer & explanationAnswer & explanation
Correct answer: D. Transit Gateway peering.
Transit Gateway peering allows you to connect two Transit Gateways across different AWS Regions. This establishes a direct, private connection between the Transit Gateways, enabling traffic to flow between attached VPCs in different regions without traversing the public internet, ensuring secure and low-latency communication.
Why the other options are wrong
- A. VPC peering connects two VPCs directly within the same region or across regions, but doesn't scale for many VPCs via Transit Gateway.
- B. Site-to-Site VPN connects on-premises networks to a VPC or Transit Gateway, not VPCs to other VPCs across regions privately.
- C. Direct Connect connects on-premises networks to AWS, not VPCs to other VPCs across regions.
Transit Gateway Peering
Transit Gateway peering allows you to connect two Transit Gateways across different AWS Regions, enabling private communication between their attached VPCs and on-premises networks.
- Connects Transit Gateways across regions.
- Enables private, low-latency cross-region traffic.
- Extends the Transit Gateway network globally.
Memory trick: To 'peer' across 'regions' with Transit Gateway, you need 'Transit Gateway peering'.