exam questions

Exam AWS Certified Solutions Architect - Professional All Questions

View all questions & answers for the AWS Certified Solutions Architect - Professional exam

Exam AWS Certified Solutions Architect - Professional topic 1 question 68 discussion

Your company previously configured a heavily used, dynamically routed VPN connection between your on-premises data center and AWS. You recently provisioned a DirectConnect connection and would like to start using the new connection.
After configuring DirectConnect settings in the AWS Console, which of the following options win provide the most seamless transition for your users?

  • A. Delete your existing VPN connection to avoid routing loops configure your DirectConnect router with the appropriate settings and verity network traffic is leveraging DirectConnect.
  • B. Configure your DirectConnect router with a higher BGP priority man your VPN router, verify network traffic is leveraging Directconnect and then delete your existing VPN connection.
  • C. Update your VPC route tables to point to the DirectConnect connection configure your DirectConnect router with the appropriate settings verify network traffic is leveraging DirectConnect and then delete the VPN connection.
  • D. Configure your DirectConnect router, update your VPC route tables to point to the DirectConnect connection, configure your VPN connection with a higher BGP priority, and verify network traffic is leveraging the DirectConnect connection.
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
amog
Highly Voted 3 years, 7 months ago
Answer is B We can have only 1 VGW on VPC, so no need to configure route in VPC anymore https://acloud.guru/forums/aws-certified-solutions-architect-professional/discussion/-KWVDow4aXPEdVfmBcZD/after-configuring-directconnect-settings-in-the-aws-console-which-of-the-followi
upvoted 13 times
kakashi
3 years, 7 months ago
What does higher priority mean? In networking sometimes this means less preferable. Anyway the important here is the traffic has to use the same path (DX) from the VPC to on-premise and from on-premise to the VPC.
upvoted 1 times
...
01037
3 years, 6 months ago
I think it's B. It's client side configuration. VPC automatically prioritize DX, but client side doesn't, so it needs the adjustment.
upvoted 4 times
...
...
cpal012
Highly Voted 3 years, 6 months ago
Definitely not C. This is a common test trap. You cant point to a DC connection, only the VGW. Who sets the answers on this site?
upvoted 5 times
...
amministrazione
Most Recent 8 months, 3 weeks ago
B. Configure your DirectConnect router with a higher BGP priority man your VPN router, verify network traffic is leveraging Directconnect and then delete your existing VPN connection.
upvoted 1 times
...
TigerInTheCloud
2 years, 4 months ago
Selected Answer: B
AWS prefers DX, but return traffic from outside AWS needs to set a higher BGP priority to use DX
upvoted 1 times
...
kzqc
2 years, 5 months ago
Selected Answer: B
B. Updating VPC routing table is useless here because AWS will always use DC over VPN when sending traffic to on-premise. But changing DC router and vpn router (both on-prem) will affect return traffic from on-prem to AWS. Higher BGP priority really means high BGP local preference. https://docs.aws.amazon.com/whitepapers/latest/hybrid-connectivity/vpn-connection-as-a-backup-to-aws-dx-connection-example.html
upvoted 2 times
...
hilft
2 years, 9 months ago
I will go for C. Still super confused. Networking specialty
upvoted 1 times
...
TechX
2 years, 10 months ago
Selected Answer: C
Answer: C Explanation: Direct Connect takes priority over Dynamically configured VPN connections.
upvoted 1 times
...
RVivek
3 years, 4 months ago
Your company previously configured a heavily used, dynamically routed VPN connection between your on-premises data center and AWS. You recently provisioned a DirectConnect connection and would like to start using the new connection. After configuring DirectConnect settings in the AWS Console, which of the following options win provide the most seamless transition for your users?
upvoted 2 times
RVivek
3 years, 4 months ago
So even if you dont perfrom steps the mentioned in option B it is going to be take care sutomatically
upvoted 1 times
...
RVivek
3 years, 4 months ago
copy paste mistake. Answer is as B is not required Q. Can I use AWS Direct Connect and a VPN Connection to the same VPC simultaneously? Yes. However, only in fail-over scenarios. The Direct Connect path will always be preferred, when established, regardless of AS path prepending. Reference: https://aws.amazon.com/directconnect/faqs/
upvoted 2 times
...
...
FERIN_01
3 years, 6 months ago
Not sure on high BGP Priority, as BGP Priority numbers got different meaning. But option C. for sure, will work. Also need not delete VPN as it can be used alternative if direct link goes down
upvoted 2 times
...
pt8
3 years, 6 months ago
B is missing 'update the VPC route table', so C is correct
upvoted 1 times
tvs
3 years, 6 months ago
BGP does that.
upvoted 2 times
...
...
hihismkskks
3 years, 6 months ago
B is right. Becuase only BGP makes priorities in Direct Connect
upvoted 1 times
...
RomanTsai
3 years, 6 months ago
Answer is B
upvoted 1 times
...
wind
3 years, 6 months ago
C is correct, you don't need to care BGP.
upvoted 1 times
...
MHKyaw
3 years, 6 months ago
Keyword in question is " After Configuring DirectConnect settings,". So, we don't need to configure DirectConnect again. I go with C.
upvoted 1 times
...
qkhanhpro
3 years, 6 months ago
Answer is B "Important: Be sure that Direct Connect is the preferred route from your end, and not over VPN when the Direct Connect virtual interface is up in order to avoid asymmetric routing; this might cause traffic to be dropped. We always prefer a Direct Connect connection over VPN routes" Quoted from AWS. On the client side, the client's router must prefer DX to avoid traffix going in through VPC while going out through DX
upvoted 1 times
...
ipindado2020
3 years, 6 months ago
Agree with B
upvoted 1 times
...
ashendy
3 years, 6 months ago
Answer is B You don't need to make any change in the routing table, because BGP will automatically handle any needed changes in the route tables
upvoted 3 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago