nerdexam
Amazon

ANS-C01 · Question #140

A company has an AWS account with four VPCs in the us-east-1 Region. The VPCs consist of a development VPC and three production VPCs that host various workloads. The company has extended its…

The correct answer is A. Associate the production VPC attachments with the existing transit gateway route table. C. Associate the Direct Connect gateway attachment with the existing transit gateway route table. E. Create a new transit gateway route table. Associate the new route table with the development. Options B, D, and F don't adhere to the provided requirements. Option B would not provide the required isolation for the development VPC. Option D won't be effective as the restriction should be on the routing level, not on the security group level. Option F would create…

Submitted by kim_seoul· Mar 6, 2026Implement Network Solutions

Question

A company has an AWS account with four VPCs in the us-east-1 Region. The VPCs consist of a development VPC and three production VPCs that host various workloads. The company has extended its on-premises data center to AWS with AWS Direct Connect by using a Direct Connect gateway. The company now wants to establish connectivity to its production VPCs and development VPC from on premises. The production VPCs are allowed to route data to each other. However, the development VPC must be isolated from the production VPCs. No data can flow between the development VPC and the production VPCs. In preparation to implement this solution, a network engineer creates a transit gateway with a single transit gateway route table. Default route table association and default route table propagation are turned off. The network engineer attaches the production VPCs, the development VPC, and the Direct Connect gateway to the transit gateway. For each VPC route table, the network engineer adds a route to 0.0.0.0/0 with the transit gateway as the next destination. Which combination of steps should the network engineer take next to complete this solution? (Choose three.)

Options

  • AAssociate the production VPC attachments with the existing transit gateway route table.
  • BAssociate all the attachments with the existing transit gateway route table. Propagate the routes
  • CAssociate the Direct Connect gateway attachment with the existing transit gateway route table.
  • DChange the security group inbound rules on the existing transit gateway network interfaces in the
  • ECreate a new transit gateway route table. Associate the new route table with the development
  • FCreate a new transit gateway with default route table association and default route table

How the community answered

(49 responses)
  • A
    55% (27)
  • B
    6% (3)
  • D
    24% (12)
  • F
    14% (7)

Explanation

Options B, D, and F don't adhere to the provided requirements. Option B would not provide the required isolation for the development VPC. Option D won't be effective as the restriction should be on the routing level, not on the security group level. Option F would create unnecessary complexity and potential overlap in connectivity.

Topics

#AWS Transit Gateway#TGW Route Tables#Direct Connect Gateway#Network Isolation

Community Discussion

No community discussion yet for this question.

Full ANS-C01 Practice