exam questions

Exam ANS-C00 All Questions

View all questions & answers for the ANS-C00 exam

Exam ANS-C00 topic 1 question 84 discussion

Exam question from Amazon's ANS-C00
Question #: 84
Topic #: 1
[All ANS-C00 Questions]

An organization has multiple applications running in VPCs across multiple AWS accounts. The network engineer has deployed a central VPC with a pair of software VPN instances that run IPSec tunnels with dynamic routing to VGWs of all application VPCs. This central VPC is connected to on-premises resources via a Direct Connect connection using a private VIF.
What additional configuration is required to enable the applications in VPCs to communicate with each other and access on-premises resources?

  • A. Configure each application VPC with a static route entry pointing the on-premises CIDR block to the software VPN instances.
  • B. Configure the central VPC with a static route entry pointing the on-premises CIDR block to local VGWs.
  • C. Advertise all application VPC CIDR blocks to on-premises resources via the VGW in the central VPC.
  • D. Configure IPSec tunnels from the on-premises router into the software VPN instances with dynamic routing.
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
lunt
Highly Voted 3 years, 7 months ago
A. Nope. BGP in use. B. Nope. VGW not in use. C. I thought it was this but deep dive made this the wrong answer. The private VIF connects to the VGW - this is mandatory - its how it functions. VGW uses gateway route tables, which inherently come the limitation that it only advertises out it local VPC CIDR. C will only send the local central VPC CIDR. You cannot force the VGW to send any more routes. Answer is D. The only way to get the advertisement of the routes from App VPC > centeral VPC > VGW > Private VIF > DX Link > LAN/DC is via IPSEC VPN from LAN/DC to Centeral VPC and BGP routing. This bypasses the whole VGW limitation and life is fun again. Answer is D.
upvoted 20 times
examinfo
3 years, 7 months ago
agreed
upvoted 3 times
...
Kentik
3 years, 7 months ago
yeap, aggreed
upvoted 1 times
...
Huy
3 years, 6 months ago
D is correct but traffic flow is lot like you said. All Traffic travel via 2 VPNs. The Software VPN will be a Router as well.
upvoted 3 times
...
...
Huntkey
Highly Voted 3 years, 6 months ago
D. That was how my company was set up before moved to TGW. on-prem establishes VPN to the Cisco CSR in the transit VPC. Cisco CSR establishes VPNs with application VPCs on their VGWs. On-prem advertise corp prefixes to Cisco CSR via BGP, then advertised to VGWs in the other VPCs natrually. All the other solution either makes many assumptions or incomplete.
upvoted 11 times
sapien45
3 years, 2 months ago
Thanks for sharing experiences
upvoted 1 times
...
...
PorkChop1999
Most Recent 1 year, 1 month ago
Selected Answer: D
I think it is D. https://docs.aws.amazon.com/whitepapers/latest/aws-vpc-connectivity-options/transit-vpc-option.html
upvoted 1 times
...
clooudy
3 years ago
Selected Answer: D
answer:D Huntkey's explanation below
upvoted 1 times
...
NSF2
3 years, 6 months ago
C seems to be the most appropriate
upvoted 2 times
...
Ishu_awsguy
3 years, 6 months ago
Answer is D , I have configured it with Checkpoint for a client
upvoted 2 times
...
JamesTR
3 years, 6 months ago
Watch “AWS re:Invent 2017: Networking Many VPCs” https://www.youtube.com/watch?v=KGKrVO9xlqI They create two VPNs between on premises routers and software VPN instances. On-premises look just like another spoke. Answer D then.
upvoted 4 times
...
student2020
3 years, 6 months ago
I think A would do the trick. Lets say on-prem CIDR is 10.0.0.0/8. You create a static route on Application VPCs pointing traffic destined for 10.0.0.0/8 to the software VPN tunnel. Traffic gets to the instance running VPN software where the traffic is source Nat'd to the IP address of the VPN instance. Traffic is then sent to on-prem from VPN instance using a subnet route table which has an entry to 10.0.0.0/8 via the VGW which came from the DX BGP router.
upvoted 2 times
...
sairam
3 years, 6 months ago
"This central VPC is connected to on-premises resources via a Direct Connect connection using a private VIF." This rules out D so C looks like the right answer
upvoted 3 times
...
Justu
3 years, 7 months ago
I would go for D, because question doesn't state that there is non-attached VGW, which is mandatory for option C.
upvoted 4 times
...
originaly
3 years, 7 months ago
it's C, the VGW is not directly attached to the VPC => https://docs.aws.amazon.com/solutions/latest/cisco-based-transit-vpc/appendix-d.html
upvoted 5 times
inf
3 years, 7 months ago
Some more info on the advertisements of spoke VPCs to the Transit VPC, https://nicovibert.com/2019/07/02/aws-transit-vpc/
upvoted 1 times
...
Johnny_Green
3 years, 7 months ago
I reviewed the provided link and noticed the following: "This is the recommended approach for customers who have up to 1 Gbps AWS Direct Connect connections. For larger AWS Direct Connect connections, we recommend establishing tunnels directly to the transit VPC CSR instances over either a public or private VIF." Since the question itself does not mention the Direct Connect is 1 Gbps or 10 Gbps, I am still not 100% sure because it looks like both C and D are valid. If I have to pick one, I will pick D.
upvoted 2 times
...
...
aduda
3 years, 7 months ago
The question states that the Central VPC doesn't have a VGW but only has EC2 instances running VPN software. C cannot be right because you dont need a VPG in this case. Best option is to also have an iBGP/eBGP connection from the the on-prem router which can exchange routes to the applucation VPCs.
upvoted 2 times
...
Jatin77
3 years, 7 months ago
why D cant able option. BGP advertisement will take care of end to end route propogation https://docs.aws.amazon.com/whitepapers/latest/aws-vpc-connectivity-options/transit-vpc.html
upvoted 6 times
Vlan
3 years, 6 months ago
exactly
upvoted 1 times
...
...
kvirk
3 years, 7 months ago
Ans is C
upvoted 2 times
...
skjs
3 years, 8 months ago
C. To leverage the dynamic routing already in place
upvoted 5 times
...
LexyA
3 years, 8 months ago
Its C Vpcs have already dynamic routing enabled, routing to onprem has to be established
upvoted 2 times
...
pechung1206
3 years, 8 months ago
A. https://docs.aws.amazon.com/vpn/latest/clientvpn-admin/scenario-onprem.html
upvoted 4 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago