nerdexam
Amazon

ANS-C01 · Question #273

A company is planning to use an AWS Transit Gateway hub and spoke architecture to migrate to AWS. The current on-premises multi-protocol label switching (MPLS) network has strict controls that…

The correct answer is D. Configure a Transit Gateway Connect attachment for each MPLS VPN between the company's. Transit Gateway Connect Attachments: Transit Gateway Connect attachments support dynamic routing via BGP and can segment traffic using VRFs, which aligns with the company's requirement for logical network segmentation similar to MPLS VPNs. Each Connect attachment can represent…

Submitted by carlos_mx· Mar 6, 2026Hybrid Connectivity

Question

A company is planning to use an AWS Transit Gateway hub and spoke architecture to migrate to AWS. The current on-premises multi-protocol label switching (MPLS) network has strict controls that enforce network segmentation by using MPLS VPNs. The company has provisioned two 10 Gbps AWS Direct Connect connections to provide resilient, high-speed, low-latency connectivity to AWS. A security engineer needs to apply the concept of network segmentation to the AWS environment to ensure that virtual routing and forwarding (VRF) is logically separated for each of the company's software development environments. The number of MPLS VPNs will increase in the future. On-premises MPLS VPNs will have overlapping address space. The company's AWS network design must support overlapping address space for the VPNs. Which solution will meet these requirements with the LEAST operational overhead?

Options

  • ADeploy a software-defined WAN (SD-WAN) head-end virtual appliance and an SD-WAN
  • BConfigure IPsec VPNs on the company edge routers for each MPLS VPN for each of the
  • CCreate a transit VPC that terminates at the AWS Site-to-Site VRF-aware IPsec VPN. Configure
  • DConfigure a Transit Gateway Connect attachment for each MPLS VPN between the company's

How the community answered

(17 responses)
  • A
    12% (2)
  • B
    24% (4)
  • C
    6% (1)
  • D
    59% (10)

Explanation

Transit Gateway Connect Attachments: Transit Gateway Connect attachments support dynamic routing via BGP and can segment traffic using VRFs, which aligns with the company's requirement for logical network segmentation similar to MPLS VPNs. Each Connect attachment can represent a VRF from the on-premises MPLS network. Support for Overlapping Address Space: Transit Gateway Connect attachments allow the segmentation of routing through the use of separate transit gateway route tables for each development environment. This ensures that overlapping IP address spaces between the environments remain isolated. Low Operational Overhead leverages Transit Gateway's native capabilities for network segmentation and routing, minimizing the need for additional software-defined networking solutions or complex VPN configurations.

Community Discussion

No community discussion yet for this question.

Full ANS-C01 Practice