AWS Certified Advanced Networking – Specialty (ANS-C01)Network DesignEasy

A global enterprise is migrating several critical applications to AWS. These applications reside in different VPCs across multiple AWS accounts, all within the same AWS Region. The enterprise requires secure and high-throughput communication between these VPCs, without exposing traffic to the public internet. They also need to simplify network management and avoid complex peering relationships. Which AWS networking service is the most appropriate solution to meet these requirements?

  1. AAWS Direct Connect
  2. BAWS Transit Gateway
  3. CVPC Peering
  4. DAWS Site-to-Site VPN
Show answer & explanation

Correct answer: B. AWS Transit Gateway

AWS Transit Gateway simplifies network architecture by acting as a central hub for connecting multiple VPCs and on-premises networks. It eliminates the need for complex, many-to-many VPC peering connections, providing high-throughput and secure private communication.

Why the other options are wrong

  • A. AWS Direct Connect establishes private connectivity between on-premises data centers and AWS, not directly for inter-VPC communication within AWS.
  • C. VPC Peering is suitable for connecting a small number of VPCs but becomes unmanageable and non-transitive with many VPCs.
  • D. AWS Site-to-Site VPN creates secure tunnels between on-premises networks and AWS VPCs, not primarily for inter-VPC communication within AWS.

AWS Transit Gateway

A network transit hub that connects VPCs and on-premises networks, simplifying network architecture and enabling centralized management.

  • Connects thousands of VPCs and on-premises networks.
  • Eliminates complex peering relationships.
  • Provides high-throughput and secure private connectivity.
  • Supports routing between connected networks.

Memory trick: Transit Gateway is the central traffic cop for all your VPCs.

More Network Design questions