AWS Certified Solutions Architect – ProfessionalDesign Solutions for Organizational ComplexityMedium

A global media company has multiple development teams, each managing its own AWS accounts and deploying applications using various CI/CD pipelines. They frequently share data, APIs, and microservices across accounts and need to establish secure, high-bandwidth, and low-latency connectivity between these accounts and to a central shared services VPC. The solution must also allow for centralized network visibility and control. Which AWS networking service should be primarily used to meet these requirements?

  1. AAmazon Route 53 Resolver for cross-account DNS resolution and traffic routing.
  2. BAWS Direct Connect to establish dedicated connections from each team's account to the shared services VPC.
  3. CAWS Transit Gateway, configured with attachments to all application VPCs and the shared services VPC.
  4. DVPC Peering connections between all individual VPCs and the shared services VPC.
Show answer & explanation

Correct answer: C. AWS Transit Gateway, configured with attachments to all application VPCs and the shared services VPC.

AWS Transit Gateway acts as a central hub for connecting multiple VPCs and on-premises networks. It simplifies network management, enables high-bandwidth, low-latency connectivity between many VPCs, and supports centralized routing decisions, which is ideal for complex, multi-account environments requiring shared services.

Why the other options are wrong

  • A. Amazon Route 53 Resolver is for DNS resolution, not for establishing the underlying network connectivity or managing routing between VPCs.
  • B. AWS Direct Connect provides on-premises to AWS connectivity, not inter-VPC connectivity between AWS accounts. Even if combined with a Transit Gateway, it's not the primary service for cross-account VPC connections.
  • D. VPC Peering creates a mesh network for many VPCs (N*(N-1)/2 connections), which becomes unmanageable and does not scale well for centralized control in a multi-account environment.

AWS Transit Gateway

AWS Transit Gateway is a network transit hub that you can use to interconnect your virtual private clouds (VPCs) and on-premises networks. It scales to hundreds of VPCs, simplifies network management, and provides centralized control.

  • Central hub for VPC and on-premises connections
  • Simplifies network architecture for many VPCs
  • Enables inter-VPC routing and traffic inspection
  • Supports cross-account sharing

Memory trick: Transit Gateway: The central hub for all your AWS networks.

More Design Solutions for Organizational Complexity questions