AWS Certified SysOps Administrator – AssociateNetworking and Content DeliveryMedium

A company is deploying a multi-tier application in a VPC. The web tier is in public subnets, and the application and database tiers are in private subnets. All tiers need to communicate with each other, and the application tier needs to connect to the internet for third-party APIs. The company plans to expand to multiple VPCs in the future and wants a centralized network hub for inter-VPC and on-premises connectivity. Which AWS service provides a scalable and centralized solution for connecting these VPCs and enabling internet access for the application tier?

  1. AVPN CloudHub
  2. BVPC Peering
  3. CAWS Direct Connect
  4. DAWS Transit Gateway
Show answer & explanation

Correct answer: D. AWS Transit Gateway

AWS Transit Gateway acts as a central hub for connecting multiple VPCs and on-premises networks. It simplifies network management, supports routing between attached VPCs, and can be used with a NAT Gateway (in a connected VPC) to provide internet access to private subnets.

Why the other options are wrong

  • A. VPN CloudHub is for connecting multiple on-premises networks to AWS via VPN, not a general scalable inter-VPC hub with centralized internet access.
  • B. VPC Peering connects two VPCs directly and does not scale well for many VPCs or provide centralized internet access.
  • C. Direct Connect provides connectivity to on-premises networks but doesn't act as a central hub for inter-VPC communication.

AWS Transit Gateway

A network transit hub that you can use to interconnect your virtual private clouds (VPCs) and on-premises networks.

  • Simplifies network topology for complex environments
  • Supports routing between attached VPCs and VPNs
  • Can serve as a central point for shared services (e.g., NAT, firewall VPCs)
  • Scales up to thousands of VPCs

Memory trick: Transit Gateway is the 'central station' for your VPCs and on-prem.

More Networking and Content Delivery questions