AWS Certified Advanced Networking – Specialty (ANS-C01)Network Security, Compliance, and GovernanceHard

A global manufacturing company needs to establish secure, encrypted connectivity between their on-premises data centers and multiple VPCs in different AWS regions. The solution must support dynamic routing and automatically failover in case of a connection disruption. They currently do not have AWS Direct Connect. Which AWS networking solution is most appropriate?

  1. AAWS Direct Connect with a dedicated connection to each region.
  2. BAWS Global Accelerator with endpoint groups in each region.
  3. CVPC Peering Connections between on-premises and each VPC.
  4. DAWS Site-to-Site VPN with AWS Transit Gateway in each region.
Show answer & explanation

Correct answer: D. AWS Site-to-Site VPN with AWS Transit Gateway in each region.

AWS Site-to-Site VPN creates encrypted tunnels over the public internet, satisfying the 'encrypted connectivity' requirement without Direct Connect. Using AWS Transit Gateway allows for hub-and-spoke connectivity to multiple VPCs within a region and can peer with Transit Gateways in other regions for inter-region connectivity. VPN connections support BGP for dynamic routing and automatic failover.

Why the other options are wrong

  • A. Direct Connect provides private connectivity but is not encrypted by default and requires a physical connection, which the company 'currently does not have'. It also doesn't inherently provide dynamic routing and automatic failover as robustly as VPN for this scenario.
  • B. AWS Global Accelerator improves performance by routing traffic over the AWS global network but does not establish encrypted site-to-site connectivity or dynamic routing for on-premises networks to VPCs.
  • C. VPC Peering connects only two VPCs at a time and does not support transitive routing, making it unscalable for 'multiple VPCs in different regions'. It also doesn't provide on-premises connectivity.

AWS Site-to-Site VPN with Transit Gateway

Provides secure, encrypted connectivity between on-premises networks and multiple AWS VPCs (potentially across regions) with dynamic routing and high availability.

  • Site-to-Site VPN: Encrypted tunnels over public internet.
  • Transit Gateway: Central hub for VPCs and on-premises connections.
  • Supports BGP for dynamic routing.
  • Automatic failover with redundant VPN tunnels.
  • Scalable for multi-VPC, multi-region connectivity.

Memory trick: VPN is the secure 'bridge', Transit Gateway is the 'central station' connecting all trains.

More Network Security, Compliance, and Governance questions