AWS Certified Advanced Networking – Specialty (ANS-C01)Network DesignEasy
A global enterprise with hundreds of AWS accounts and VPCs needs to establish private and secure connectivity between its on-premises data centers and its AWS resources. The solution must support thousands of routes, redundant connections, and centralize network management to reduce operational overhead. Which AWS networking service combination should the enterprise use?
- AAWS Direct Connect with Transit Gateway
- BVPC Endpoints with Internet Gateway
- CAWS Site-to-Site VPN with VPC Peering
- DAWS Client VPN with VPN CloudHub
Show answer & explanationAnswer & explanation
Correct answer: A. AWS Direct Connect with Transit Gateway
AWS Direct Connect provides a dedicated private connection, offering higher bandwidth and lower latency than VPN. Transit Gateway centralizes routing for thousands of VPCs and on-premises connections, simplifying network management significantly.
Why the other options are wrong
- B. VPC Endpoints are for private access to AWS services, and an Internet Gateway is for public internet access, neither addresses on-premises private connectivity to many VPCs.
- C. Site-to-Site VPN is suitable for secure connections but has lower bandwidth, higher latency, and VPC peering does not scale for hundreds of VPCs.
- D. Client VPN is for end-user access, and VPN CloudHub is for connecting multiple VPNs, but Direct Connect with Transit Gateway is superior for enterprise-grade private connectivity to many VPCs.
Direct Connect with Transit Gateway
Combines a dedicated private connection to AWS with a central hub for connecting thousands of VPCs and on-premises networks.
- Offers high bandwidth and low latency private connectivity.
- Centralizes routing for complex network architectures.
- Reduces operational overhead for managing many connections.
Memory trick: Directly connect the enterprise's data to the AWS cloud, transiting through a central hub.