exam questions

Exam ANS-C00 All Questions

View all questions & answers for the ANS-C00 exam

Exam ANS-C00 topic 1 question 40 discussion

Exam question from Amazon's ANS-C00
Question #: 40
Topic #: 1
[All ANS-C00 Questions]

A corporate network routing table contains 624 individual RFC 1918 and public IP prefixes. You have two AWS Direct Connect connectors. You configure a private virtual interface on both connections to a virtual private gateway. The virtual private gateway is not currently attached to a VPC. Neither BGP session will maintain the Established state on the customer router. The AWS Management Console reports the private virtual interfaces as Down.
What could you do to address the problem so that the AWS Management Console reports the private virtual interface as Available?

  • A. Attach the virtual private gateway to a VPC and enable route propagation.
  • B. Filter the public IP pre?xes on the corporate network from the private virtual interface.
  • C. Change the BGP advertisements from the corporate network to only be a default route.
  • D. Attach the second virtual interface to an alternative virtual private gateway.
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
PavanKushwah123
2 years, 5 months ago
Correct Answer D
upvoted 1 times
...
clooudy
3 years ago
Selected Answer: C
Answer C 624 corporate prefixes, BGP on Pvif can only advertise 100 prefixes. Sending 0/0 from Onprem to AWS will bring up the session
upvoted 2 times
...
sapien45
3 years, 3 months ago
Aggregate your routes advertised from on-premises! C
upvoted 2 times
...
Jazz888
3 years, 3 months ago
A is the answer. https://docs.aws.amazon.com/directconnect/latest/UserGuide/virtualgateways.html A virtual private gateway that you associate with a Direct Connect gateway must be attached to a VPC.
upvoted 2 times
Jazz888
3 years, 3 months ago
Well sorry about that. It says DX Gateway I read it wrong. My initial answer was C. So might stick to that untill further reading
upvoted 1 times
...
...
jyrajan69
3 years, 4 months ago
There must be a reason for ''At the moment, the virtual private gateway is not connected to a VPC'', dont you need to connect it first? I will go with A
upvoted 1 times
...
AzureDP900
3 years, 4 months ago
I will go with C
upvoted 1 times
...
asjak
3 years, 7 months ago
correct answer is C-- https://aws.amazon.com/premiumsupport/knowledge-center/troubleshoot-bgp-dx/
upvoted 3 times
Jazz888
3 years, 4 months ago
Really good one! Thanks
upvoted 1 times
...
...
NSF2
3 years, 7 months ago
The answer must be C This is something I have experienced practically that if the amount of advertised prefixes exceed 100, virtual interface goes down.
upvoted 4 times
...
Huntkey
3 years, 8 months ago
The BGP will come up in full even without propagation. It just that your VPC's route-tables won't learn the on-prem routes until the propagation is enabled. I will go with B
upvoted 1 times
Huntkey
3 years, 8 months ago
I meant C
upvoted 3 times
...
...
jason2009
3 years, 8 months ago
Answer is C. https://aws.amazon.com/premiumsupport/knowledge-center/virtual-interface-bgp-down/
upvoted 3 times
walkwolf3
3 years, 7 months ago
C Your device is not advertising more than 100 prefixes to AWS by BGP. By default, AWS only accepts up to 100 prefixes using a BGP session on AWS Direct Connect.
upvoted 2 times
...
...
jpvdham
3 years, 8 months ago
Option B. I Agree with Kentik. With more then 100 routes AWS will take down the session.
upvoted 3 times
...
Paagee
3 years, 8 months ago
Routes per Border Gateway Protocol (BGP) session on a private virtual interface is 100 max. Beyond that BGP will not be established. I will chose C so that only default route is passed via the BGP to VGW
upvoted 3 times
...
douglasaws
3 years, 8 months ago
I would go with option A As far as I know, change or filter the advertised routes would have no effect on the VIF state. And letter D is just pointless
upvoted 2 times
...
Kentik
3 years, 8 months ago
A. Attach the virtual private gateway to a VPC and enable route propagation. B. This is valid, if you advertise more then 100 routes AWS will take down the session C. No, sending a default route to AWS wont make the BGP come up. D. No. A Virtual Private Gateway can only be attached to a single VPC, so creating another VGW and attaching it to the same VPC wont be possible. Also found this on the AWS page, which doesnt deny the option of assigning multiple VIF to the same VGW. Q: I’m attaching multiple private VIFs to a single virtual gateway. Can each VIF have a separate Amazon side ASN? A: No, you can assign/configure separate Amazon side ASN for each virtual gateway, not each VIF. Amazon side ASN for VIF is inherited from the Amazon side ASN of the attached virtual gateway. https://aws.amazon.com/vpn/faqs/ I would go with A since it says on AWS the interfaces shows as Down and i believe is because is waiting to be attached to something.
upvoted 3 times
hugo1111
3 years, 5 months ago
B is not a valid option...it is filtering the ips from aws side...which you cannot do that...
upvoted 1 times
...
eeghai7thioyaiR4
3 years, 8 months ago
Actually, C is right AWS has a prefix-limit of 100 prefixes: if you advertise more, the session is restarted
upvoted 2 times
...
...
KiSuu
3 years, 8 months ago
Change the BGP advertisements from the corporate network to only be a default route.
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...