Topic 1 Question 244
A company is planning to migrate to AWS and use multiple VPCs in multiple AWS Regions. A network engineer must connect the eu-west-1 and eu-central-1 Regions to the company headquarters and branch office, respectively.
The network engineer created a production VPC, named Prod A, with a CIDR block of 10.0.0.0/16. Prod A runs in an account in eu-west-1. The network engineer then created another production VPC, named Prod B, with a CIDR block of 10.1.0.0/16. Prod В runs in a different account in eu-central-1.
The network engineer performed the following steps to try to achieve the required connectivity:
- Created one transit gateway in each Region
- Shared and accepted the transit gateways with the production accounts in both Regions
- Configured the peering attachment between both transit gateways
- Attached both VPCs to the respective Region transit gateway
- Created both transit gateway route tables and associated the attachments with the route tables
- Configured a static route in both transit gateway route tables to send traffic to the remote VPC in the other Region
- Activated route propagation on the VPC route tables in each Region
After the configuration, the network engineer tried to connect from Prod A to Prod B. However, the connection was unsuccessful.
What should the network engineer do to achieve the required connectivity?
Modify the IP address of the peering attachment to a wider range.
Delete the static routes that were in the transit gateway route table to send traffic to the remote VPC and enable route propagation instead.
Create a new route destined to 10.0.0.0/8 in both production VPC route tables with the Region transit gateway as the target.
Modify the transit gateway route tables from the production accounts to propagate routes dynamically between the production VPCs.
ユーザの投票
コメント(3)
- 正解だと思う選択肢: C
C: because TGW routes are NOT propagated to VPC route tables (manual update as to take place)
👍 2c1193d42025/01/06 - 正解だと思う選択肢: C
A ❌ Eliminate TGW peering attachments don’t have IP addresses. B ❌ Eliminate TGW peering requires static routes; propagation is not supported. C ⚠️ Technically Valid (but bad design) Broad CIDR route (10.0.0.0/8) works but is ugly. D ❌ Eliminate Cannot propagate routes dynamically between VPCs.
👍 2secdaddy2025/02/03 - 正解だと思う選択肢: C
C is correct because:
Adding a route for 10.0.0.0/8 in both VPC route tables pointing to the transit gateway will:
Enable traffic to flow between the VPCs Cover both VPC CIDR ranges (10.0.0.0/16 and 10.1.0.0/16) Complete the routing path in both directions
👍 1woorkim2025/01/11
シャッフルモード