ANS-C01 · Question #84
A company has hundreds of Amazon EC2 instances that are running in two production VPCs across all Availability Zones in the us-east-1 Region. The production VPCs are named VPC A and VPC B. A new…
The correct answer is C. Enable transit gateway appliance mode on the VPC attachment in the shared VPC. https://docs.aws.amazon.com/vpc/latest/tgw/transit-gateway-appliance-scenario.html
Question
A company has hundreds of Amazon EC2 instances that are running in two production VPCs across all Availability Zones in the us-east-1 Region. The production VPCs are named VPC A and VPC B. A new security regulation requires all traffic between production VPCs to be inspected before the traffic is routed to its final destination. The company deploys a new shared VPC that contains a stateful firewall appliance and a transit gateway with a VPC attachment across all VPCs to route traffic between VPC A and VPC B through the firewall appliance for inspection. During testing, the company notices that the transit gateway is dropping the traffic whenever the traffic is between two Availability Zones. What should a network engineer do to fix this issue with the LEAST management overhead?
Options
- AIn the shared VPC, replace the VPC attachment with a VPN attachment. Create a VPN tunnel
- BEnable transit gateway appliance mode on the VPC attachment in VPC A and VPC B.
- CEnable transit gateway appliance mode on the VPC attachment in the shared VPC.
- DIn the shared VPC, configure one VPC peering connection to VPC A and another VPC peering
How the community answered
(35 responses)- A20% (7)
- B9% (3)
- C66% (23)
- D6% (2)
Explanation
https://docs.aws.amazon.com/vpc/latest/tgw/transit-gateway-appliance-scenario.html
Topics
Community Discussion
No community discussion yet for this question.