AWS Certified Advanced Networking – Specialty (ANS-C01)Network ImplementationMedium
A network architect is designing a multi-VPC environment where different application teams manage their own VPCs. They need to ensure that traffic between these VPCs can be routed efficiently without creating a complex mesh of peering connections. Additionally, the architects want to enforce centralized network policies and visibility. Which AWS networking component should be used to achieve this?
- AInternet Gateway
- BVirtual Private Gateway
- CAWS Transit Gateway
- DVPC Peering
Show answer & explanationAnswer & explanation
Correct answer: C. AWS Transit Gateway
AWS Transit Gateway acts as a network hub, connecting multiple VPCs and on-premises networks. This simplifies the network topology by eliminating the need for a full mesh of peering connections, and allows for centralized routing, network policies, and traffic visibility.
Why the other options are wrong
- A. An Internet Gateway connects a VPC to the public internet, not for inter-VPC communication.
- B. A Virtual Private Gateway is used to connect an on-premises VPN or Direct Connect connection to a single VPC, not to connect multiple VPCs to each other.
- D. VPC Peering connections are point-to-point and become unmanageable and complex in a multi-VPC environment (N*(N-1)/2 connections).
AWS Transit Gateway
A network transit hub that you can use to interconnect your virtual private clouds (VPCs) and on-premises networks.
- Simplifies network topology (hub-and-spoke).
- Enables inter-VPC and hybrid connectivity.
- Provides centralized routing and network management.
Memory trick: Transit Gateway is the 'Central Station' for all VPC routes.