AWS Certified Solutions Architect – ProfessionalDesign Solutions for Organizational ComplexityHard

A large enterprise has several applications running in different AWS accounts and on-premises data centers. Each AWS account has its own VPCs, and the on-premises networks need to securely and efficiently communicate with specific application tiers in these VPCs. The current setup involves multiple site-to-site VPNs and complex routing tables, leading to management overhead and potential network bottlenecks. The company needs a centralized network connectivity solution that simplifies routing, provides high bandwidth, and supports thousands of connections across VPCs and on-premises networks. Which AWS service should be implemented?

  1. AAWS Direct Connect Gateway with multiple Direct Connect connections
  2. BAmazon Route 53 Resolver Endpoints for hybrid DNS resolution
  3. CAWS Transit Gateway with VPNs and Direct Connect attachments
  4. DVPC Peering connections between all relevant VPCs and VPNs to on-premises
Show answer & explanation

Correct answer: C. AWS Transit Gateway with VPNs and Direct Connect attachments

AWS Transit Gateway acts as a central hub for connecting VPCs and on-premises networks. It greatly simplifies network topology by eliminating the need for complex peering connections and multiple VPNs. Supporting thousands of connections and integrating with VPNs and Direct Connect, it provides high bandwidth, centralized routing, and reduces management overhead for large-scale hybrid environments.

Why the other options are wrong

  • A. Direct Connect Gateway is primarily for connecting on-premises networks to multiple VPCs across regions via Direct Connect. While it offers high bandwidth, it doesn't simplify VPC-to-VPC routing within AWS or act as a central hub for thousands of connections as comprehensively as Transit Gateway.
  • B. Route 53 Resolver Endpoints are for hybrid DNS resolution, not for centralizing network connectivity and routing for data plane traffic across VPCs and on-premises networks.
  • D. VPC Peering creates a 1:1 connection between VPCs, which becomes unmanageable and complex with 'thousands of connections'. It also doesn't provide a centralized solution for on-premises connectivity.

AWS Transit Gateway

A network transit hub that connects Virtual Private Clouds (VPCs) and on-premises networks into a single gateway.

  • Simplifies network topology by acting as a central hub.
  • Supports thousands of VPCs and on-premises network connections.
  • Provides high bandwidth and reduces operational complexity for hybrid networking.
  • Integrates with AWS Direct Connect and Site-to-Site VPN.

Memory trick: Transit Gateway is the central traffic cop for your hybrid network.

More Design Solutions for Organizational Complexity questions