Soru

Zorluk: OrtaHybrid and Multi-Account Network Connectivity Design

A logistics company is designing a hybrid network architecture to connect its on-premises inventory system with 12 spoke VPCs across three AWS accounts in the us-west-2 Region. The architecture must support dynamic routing, provide high availability with automatic failover, and minimize administrative overhead. The company has provisioned an AWS Direct Connect connection at a partner colocation facility.

Which TWO configurations must the solutions architect implement to establish this connectivity in accordance with AWS best practices? (Select TWO.)

  1. Deploy a centralized AWS Transit Gateway in a dedicated network services account, and use AWS Resource Access Manager (RAM) to share it with the spoke VPC accounts.Cevap
  2. Create an AWS Direct Connect Gateway, attach it to the Transit Gateway using a Transit Gateway association, and configure a backup IPSec VPN connection from the on-premises router to the Transit Gateway.Cevap
  3. C
    Establish an AWS Direct Connect Gateway and attach it directly to all 12 spoke VPCs via Virtual Private Gateways (VGWs) to bypass the Transit Gateway.
  4. D
    Create a Route 53 Private Hosted Zone in the network services account and associate it only with a central Shared Services VPC to enable cross-account DNS resolution automatically for all spoke VPCs.
  5. E
    Deploy a single NAT Gateway in one Availability Zone of the network services account to route outbound internet traffic from all spoke VPCs.

Cevap

The correct configurations are deploying a centralized AWS Transit Gateway in a dedicated network services account shared via AWS Resource Access Manager (RAM), and creating an AWS Direct Connect Gateway attached to the Transit Gateway with a backup VPN connection.
Deploying a centralized Transit Gateway and sharing it via AWS Resource Access Manager (RAM) establishes a scalable, hub-and-spoke architecture that simplifies routing across multiple accounts. Attaching the Transit Gateway to a Direct Connect Gateway routes the primary traffic over the Direct Connect connection, while configuring a backup VPN connection to the Transit Gateway provides highly available path redundancy with automatic failover.

Adım Adım Çözüm

1
Select a hub-and-spoke topology to connect the 12 spoke VPCs across multiple accounts.
Deploy an AWS Transit Gateway in a central account and share it with the spoke accounts using AWS RAM.
This establishes a single point of connectivity for all VPCs, reducing administrative overhead and supporting scaling beyond the 10 VPC limit of Direct Connect Gateway.
2
Connect the on-premises system to the Transit Gateway using the primary and backup connections.
Attach the Transit Gateway to an AWS Direct Connect Gateway for the primary connection, and set up a backup Site-to-Site VPN directly to the Transit Gateway.
This ensures dynamic routing with failover capabilities between the high-speed Direct Connect and the backup VPN path.

Anahtar Kavram

Centralized hub-and-spoke networking using AWS Transit Gateway, AWS Direct Connect Gateway, and AWS RAM for multi-account hybrid environments.
Bu soruyu puanla