A global media company has multiple development teams, each managing its own AWS accounts and deploying applications using various CI/CD pipelines. They frequently share data, APIs, and microservices across accounts and need to establish secure, high-bandwidth, and low-latency connectivity between these accounts and to a central shared services VPC. The solution must also allow for centralized network visibility and control. Which AWS networking service should be primarily used to meet these requirements?
- AAmazon Route 53 Resolver for cross-account DNS resolution and traffic routing.
- BAWS Direct Connect to establish dedicated connections from each team's account to the shared services VPC.
- CAWS Transit Gateway, configured with attachments to all application VPCs and the shared services VPC.
- DVPC Peering connections between all individual VPCs and the shared services VPC.
Show answer & explanationAnswer & explanation
Correct answer: C. AWS Transit Gateway, configured with attachments to all application VPCs and the shared services VPC.
AWS Transit Gateway acts as a central hub for connecting multiple VPCs and on-premises networks. It simplifies network management, enables high-bandwidth, low-latency connectivity between many VPCs, and supports centralized routing decisions, which is ideal for complex, multi-account environments requiring shared services.
Why the other options are wrong
- A. Amazon Route 53 Resolver is for DNS resolution, not for establishing the underlying network connectivity or managing routing between VPCs.
- B. AWS Direct Connect provides on-premises to AWS connectivity, not inter-VPC connectivity between AWS accounts. Even if combined with a Transit Gateway, it's not the primary service for cross-account VPC connections.
- D. VPC Peering creates a mesh network for many VPCs (N*(N-1)/2 connections), which becomes unmanageable and does not scale well for centralized control in a multi-account environment.
AWS Transit Gateway
AWS Transit Gateway is a network transit hub that you can use to interconnect your virtual private clouds (VPCs) and on-premises networks. It scales to hundreds of VPCs, simplifies network management, and provides centralized control.
- Central hub for VPC and on-premises connections
- Simplifies network architecture for many VPCs
- Enables inter-VPC routing and traffic inspection
- Supports cross-account sharing
Memory trick: Transit Gateway: The central hub for all your AWS networks.