ANS-C01 · Question #15
A company has multiple AWS accounts. Each account contains one or more VPCs. A new security guideline requires the inspection of all traffic between VPCs. The company has deployed a transit gateway…
The correct answer is B. Modify the transit gateway VPC attachment on the shared services VPC by enabling appliance. To resolve the issue of intermittent connections for traffic that crosses Availability Zones after configuring routing for traffic inspection between VPCs using a transit gateway and EC2 instances with IDS services in a shared services VPC, a network engineer should modify the…
Question
A company has multiple AWS accounts. Each account contains one or more VPCs. A new security guideline requires the inspection of all traffic between VPCs. The company has deployed a transit gateway that provides connectivity between all VPCs. The company also has deployed a shared services VPC with Amazon EC2 instances that include IDS services for stateful inspection. The EC2 instances are deployed across three Availability Zones. The company has set up VPC associations and routing on the transit gateway. The company has migrated a few test VPCs to the new solution for traffic inspection. Soon after the configuration of routing, the company receives reports of intermittent connections for traffic that crosses Availability Zones. What should a network engineer do to resolve this issue?
Options
- AModify the transit gateway VPC attachment on the shared services VPC by enabling cross-
- BModify the transit gateway VPC attachment on the shared services VPC by enabling appliance
- CModify the transit gateway by selecting VPN equal-cost multi-path (ECMP) routing support.
- DModify the transit gateway by selecting multicast support.
How the community answered
(32 responses)- A9% (3)
- B63% (20)
- C6% (2)
- D22% (7)
Explanation
To resolve the issue of intermittent connections for traffic that crosses Availability Zones after configuring routing for traffic inspection between VPCs using a transit gateway and EC2 instances with IDS services in a shared services VPC, a network engineer should modify the transit gateway. VPC attachment on the shared services VPC by enabling appliance mode support (Option B). This will ensure that traffic is routed to the same EC2 instance for stateful inspection and prevent intermittent connections. https://docs.aws.amazon.com/vpc/latest/tgw/transit-gateway-appliance-scenario.html
Topics
Community Discussion
No community discussion yet for this question.