AWS Certified Security – SpecialtyDomain 3: Infrastructure SecurityMedium

A global software company maintains a single AWS account with multiple VPCs across different regions. They need to establish private, low-latency, and high-bandwidth connectivity between these VPCs for microservices communication, ensuring that traffic does not traverse the public internet. The solution must be scalable and simplify network management as more VPCs are added. Which AWS networking service should be used to achieve this?

  1. AAWS Direct Connect.
  2. BVPC Peering connections between all VPC pairs.
  3. CSite-to-Site VPN connections between all VPC pairs.
  4. DAWS Transit Gateway.
Show answer & explanation

Correct answer: D. AWS Transit Gateway.

AWS Transit Gateway acts as a central hub for connecting VPCs and on-premises networks. It simplifies inter-VPC connectivity, especially across regions, by reducing the number of connections needed compared to VPC peering and keeping traffic private and within the AWS backbone.

Why the other options are wrong

  • A. AWS Direct Connect provides dedicated connectivity between on-premises and AWS, not primarily for inter-VPC communication within AWS.
  • B. VPC Peering connections are point-to-point and become unmanageable and unscalable for a large number of VPCs (N*(N-1)/2 connections).
  • C. Site-to-Site VPN connections are encrypted but typically use the public internet (unless combined with DX) and are not designed for high-bandwidth, low-latency inter-VPC communication within the AWS backbone itself, nor do they scale well for many VPCs.

AWS Transit Gateway

AWS Transit Gateway is a network transit hub that you can use to interconnect your virtual private clouds (VPCs) and on-premises networks to a single gateway.

  • Simplifies network topology for many VPCs.
  • Enables inter-region VPC connectivity.
  • Traffic stays within the AWS global network.
  • Supports dynamic routing and centralized management.

Memory trick: Transit Gateway Takes on Topology Troubles.

More Domain 3: Infrastructure Security questions