AWS Certified Solutions Architect – ProfessionalDesign Solutions for Organizational ComplexityHard

A multinational corporation has multiple business units, each with its own AWS accounts. They want to implement a centralized network architecture that allows secure and controlled communication between all accounts and on-premises data centers, while also enabling internet access for specific applications. The solution must simplify network management, enforce security policies consistently, and support future expansion. Which networking construct should a solutions architect recommend?

  1. ACreate a large, shared VPC for all business units, manage subnets centrally, and use Network ACLs and Security Groups for inter-business unit traffic control.
  2. BUse VPC Peering connections between all relevant VPCs and establish separate Direct Connect connections for each account to the on-premises data centers.
  3. CImplement AWS PrivateLink for secure connectivity between services across accounts and use AWS Client VPN for remote access to specific applications requiring internet access.
  4. DDeploy AWS Transit Gateway in a dedicated networking account, connect all business unit VPCs and Direct Connect Gateways to it, and route internet traffic through a centralized NAT Gateway in the networking account.
Show answer & explanation

Correct answer: D. Deploy AWS Transit Gateway in a dedicated networking account, connect all business unit VPCs and Direct Connect Gateways to it, and route internet traffic through a centralized NAT Gateway in the networking account.

AWS Transit Gateway centralizes network connectivity for multiple VPCs and on-premises networks, simplifying routing and management. Placing it in a dedicated networking account ensures segregation. Centralized NAT Gateway provides controlled and auditable internet access. This approach scales well and enforces consistent security.

Why the other options are wrong

  • A. A large, shared VPC can lead to complex security management and potential resource contention between business units, defeating the purpose of separate accounts. It also doesn't inherently simplify on-premises connectivity.
  • B. VPC Peering does not scale well for a large number of VPCs (n*n connections) and doesn't simplify routing. Separate Direct Connect connections for each account would be costly and complex to manage.
  • C. AWS PrivateLink provides private connectivity to specific services, not a general network routing solution for inter-VPC and on-premises communication. AWS Client VPN is for remote user access, not for centralized application internet access.

AWS Transit Gateway

A network transit hub that connects VPCs and on-premises networks, simplifying network architecture and centralizing routing.

  • Acts as a regional virtual router.
  • Simplifies network management for multi-VPC/multi-account environments.
  • Supports VPN, Direct Connect, and VPC attachments.

Memory trick: Transit Gateway centralizes, simplifying all connections.

More Design Solutions for Organizational Complexity questions