nerdexam
Amazon

ANS-C01 · Question #25

A global company operates all its non-production environments out of three AWS Regions: eu- west-1, us-east-1, and us-west-1. The company hosts all its production workloads in two on- premises data…

The correct answer is C. Create a transit gateway in each Region with multiple newly commissioned VPN connections. An AWS Transit Gateway provides the option of creating an IPsec VPN connection between your remote network and the Transit Gateway over the internet. A Transit Gateway is a regional https://docs.aws.amazon.com/whitepapers/latest/aws-vpc-connectivity-options/aws-transit…

Submitted by rania.sa· Mar 6, 2026Design and Implement Hybrid Connectivity

Question

A global company operates all its non-production environments out of three AWS Regions: eu- west-1, us-east-1, and us-west-1. The company hosts all its production workloads in two on- premises data centers. The company has 60 AWS accounts and each account has two VPCs in each Region. Each VPC has a virtual private gateway where two VPN connections terminate for resilient connectivity to the data centers. The company has 360 VPN tunnels to each data center, resulting in high management overhead. The total VPN throughput for each Region is 500 Mbps. The company wants to migrate the production environments to AWS. The company needs a solution that will simplify the network architecture and allow for future growth. The production environments will generate an additional 2 Gbps of traffic per Region back to the data centers. This traffic will increase over time. Which solution will meet these requirements?

Options

  • ASet up an AWS Direct Connect connection from each data center to AWS in each Region. Create
  • BCreate a single transit gateway with VPN connections from each data center. Share the transit
  • CCreate a transit gateway in each Region with multiple newly commissioned VPN connections
  • DPeer all the VPCs in each Region to a new VPC in each Region that will function as a centralized

How the community answered

(46 responses)
  • A
    15% (7)
  • B
    28% (13)
  • C
    50% (23)
  • D
    7% (3)

Explanation

An AWS Transit Gateway provides the option of creating an IPsec VPN connection between your remote network and the Transit Gateway over the internet. A Transit Gateway is a regional https://docs.aws.amazon.com/whitepapers/latest/aws-vpc-connectivity-options/aws-transit- gateway-vpn.html You can use AWS Resource Access Manager (RAM) to share a transit gateway for VPC attachments across accounts or across your organization in AWS Organizations. That helps reducing the VPN connections. https://docs.aws.amazon.com/vpc/latest/tgw/transit-gateway-share.html AWS Transit Gateway can scale up to 50 Gbps throughput aggregating multiple VPN tunnels. https://docs.aws.amazon.com/vpc/latest/tgw/transit-gateway-quotas.html#bandwidth-quotas

Topics

#AWS Transit Gateway#AWS Direct Connect#Hybrid Cloud Networking#VPN Connectivity

Community Discussion

No community discussion yet for this question.

Full ANS-C01 Practice