Topic 1 Question 15
A company has multiple AWS accounts. Each account contains one or more VPCs. A new security guideline requires the inspection of all traffic between VPCs. The company has deployed a transit gateway that provides connectivity between all VPCs. The company also has deployed a shared services VPC with Amazon EC2 instances that include IDS services for stateful inspection. The EC2 instances are deployed across three Availability Zones. The company has set up VPC associations and routing on the transit gateway. The company has migrated a few test VPCs to the new solution for traffic inspection. Soon after the configuration of routing, the company receives reports of intermittent connections for traffic that crosses Availability Zones. What should a network engineer do to resolve this issue?
Modify the transit gateway VPC attachment on the shared services VPC by enabling cross-Availability Zone load balancing.
Modify the transit gateway VPC attachment on the shared services VPC by enabling appliance mode support.
Modify the transit gateway by selecting VPN equal-cost multi-path (ECMP) routing support.
Modify the transit gateway by selecting multicast support.
ユーザの投票
コメント(7)
Please note "IDS services for stateful inspection" - this implies the same appliance is followed for the life of the connection. This is only achieved by on the shared services VPC by enabling appliance mode support
👍 7study_aws12023/03/19- 正解だと思う選択肢: B👍 3Cappy467892023/03/21
- 正解だと思う選択肢: B
Appliance mode should be enabled to ensure that the returning traffic (in case of stateful connections) takes the same path as incoming traffic, otherwise it might go to different AZs
👍 3navi72023/03/22
シャッフルモード