AWS Certified Advanced Networking – Specialty (ANS-C01)Network ImplementationMedium

A network architect is designing a multi-VPC environment where different application teams manage their own VPCs. They need to ensure that traffic between these VPCs can be routed efficiently without creating a complex mesh of peering connections. Additionally, the architects want to enforce centralized network policies and visibility. Which AWS networking component should be used to achieve this?

  1. AInternet Gateway
  2. BVirtual Private Gateway
  3. CAWS Transit Gateway
  4. DVPC Peering
Show answer & explanation

Correct answer: C. AWS Transit Gateway

AWS Transit Gateway acts as a network hub, connecting multiple VPCs and on-premises networks. This simplifies the network topology by eliminating the need for a full mesh of peering connections, and allows for centralized routing, network policies, and traffic visibility.

Why the other options are wrong

  • A. An Internet Gateway connects a VPC to the public internet, not for inter-VPC communication.
  • B. A Virtual Private Gateway is used to connect an on-premises VPN or Direct Connect connection to a single VPC, not to connect multiple VPCs to each other.
  • D. VPC Peering connections are point-to-point and become unmanageable and complex in a multi-VPC environment (N*(N-1)/2 connections).

AWS Transit Gateway

A network transit hub that you can use to interconnect your virtual private clouds (VPCs) and on-premises networks.

  • Simplifies network topology (hub-and-spoke).
  • Enables inter-VPC and hybrid connectivity.
  • Provides centralized routing and network management.

Memory trick: Transit Gateway is the 'Central Station' for all VPC routes.

More Network Implementation questions