AWS Certified Solutions Architect – ProfessionalDesign Solutions for Organizational ComplexityEasy
A multinational corporation has multiple business units, each operating in its own AWS account and Virtual Private Cloud (VPC) within the same AWS Region. They need to establish secure and efficient network connectivity between these VPCs and a shared services VPC (e.g., for Active Directory, logging, monitoring) without creating a mesh of peering connections. The solution must also allow for centralized network inspection and routing policies. Which AWS networking service should a Solutions Architect recommend?
- AAWS Transit Gateway for centralized VPC connectivity.
- BAWS Site-to-Site VPN connections between VPCs.
- CAWS Direct Connect Gateway for inter-VPC connectivity.
- DVPC Peering connections between all required VPCs.
Show answer & explanationAnswer & explanation
Correct answer: A. AWS Transit Gateway for centralized VPC connectivity.
AWS Transit Gateway simplifies network topology by acting as a central hub for connecting multiple VPCs and on-premises networks. It eliminates the need for complex VPC peering meshes, centralizes routing, and allows for centralized network inspection and policy enforcement, which is ideal for a multinational corporation with many business units and shared services.
Why the other options are wrong
- B. AWS Site-to-Site VPN connections are used for connecting on-premises networks to AWS VPCs over the public internet. While they can connect VPCs, creating a VPN mesh between many VPCs is inefficient, complex, and does not provide the centralized management capabilities of Transit Gateway.
- C. AWS Direct Connect Gateway is primarily for connecting on-premises networks to multiple VPCs across AWS Regions, not for inter-VPC connectivity within the same AWS Region or for centralized routing between multiple VPCs.
- D. VPC Peering connections create a direct network link between two VPCs. For multiple VPCs (N VPCs), this creates an N*(N-1)/2 mesh, which becomes unmanageable and complex for routing and security policies as the number of VPCs grows.
AWS Transit Gateway
A network transit hub that simplifies network topology by connecting thousands of Amazon Virtual Private Clouds (VPCs) and on-premises networks.
- Simplifies network architecture, eliminating complex peering meshes.
- Enables centralized routing and network inspection.
- Scalable to thousands of VPCs and VPN connections.
Memory trick: Transit Gateway: The central hub for all your VPCs.