exam questions

Exam ANS-C00 All Questions

View all questions & answers for the ANS-C00 exam

Exam ANS-C00 topic 1 question 47 discussion

Exam question from Amazon's ANS-C00
Question #: 47
Topic #: 1
[All ANS-C00 Questions]

Your hybrid networking environment consists of two application VPCs, a shared services VPC, and your corporate network. The corporate network is connected to the shared services VPC via an IPsec VPN with dynamic (BGP) routing enabled.
The applications require access to a common authentication service in the shared services VPC. You need to enable native network access from the corporate network to both application VPCs.
Which step should you take to meet the requirements?

  • A. Use VPC peering to peer the application VPCs with the shared services VPC, and enable associated routing in the shared services VPC via the corporate VPN.
  • B. Configure an IPsec VPN between the virtual private gateway in each application VPC to the virtual private gateway in the shared services VPC.
  • C. Configure additional IPsec VPNs for each application VPC back to the corporate network, and enable VPC peering to the shared services VPC.
  • D. Enable CloudHub functionality to route traffic between the three VPCs and the corporate network using dynamic BGP routing.
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
aviz
Highly Voted 3 years, 8 months ago
I think the answer is C
upvoted 9 times
...
walkwolf3
Highly Voted 3 years, 7 months ago
C A. VPC peering doesn't allow transit communication. So coporate network can't go through shared VPC to reach out to application VPCs https://docs.aws.amazon.com/vpc/latest/peering/invalid-peering-configurations.html B. IPSec VPN can be built between virtual private gateway and EC2 router. https://docs.aws.amazon.com/whitepapers/latest/aws-vpc-connectivity-options/transit-vpc-option.html D. Cloudhub is to set up network between remote sites(onpremise) being routed over their AWS VPN connections instead of VPCs. https://docs.aws.amazon.com/whitepapers/latest/aws-vpc-connectivity-options/aws-vpn-cloudhub.html
upvoted 6 times
A_Wolf
3 years, 7 months ago
ill just take the chance to say thank you walkwolf for all your contribution past month, it helped alot.
upvoted 5 times
...
...
PavanKushwah123
Most Recent 2 years, 5 months ago
Correct Answer C
upvoted 1 times
...
clooudy
3 years, 1 month ago
Selected Answer: C
Answer C
upvoted 1 times
...
StelSen
3 years, 7 months ago
To me the correct Answer is B. Look at this. Exact scenario. https://docs.aws.amazon.com/whitepapers/latest/aws-vpc-connectivity-options/transit-vpc-option.html Option-C will also work. But imagine, you will end up adding 3 VPNs and 2 VPC peering. Rather I would use Option-B which uses 3 VPNs only.
upvoted 1 times
wahlbergusa
3 years, 7 months ago
B mentions establishing VPN between VGWs. There is no such thing.
upvoted 2 times
...
...
zenfox
3 years, 7 months ago
C is clearly the answer here 1 - Corp to applications VPCs will use new IPSec 2 - Application to share will use vpc peering
upvoted 1 times
...
Huntkey
3 years, 7 months ago
Cloudhub is not a feature you can enable. Also, why are you trying to make app VPC to shared VPC traffic going through the VPN tunnels to the corp network? Isn't it a better idea to use VPC peering for that?
upvoted 1 times
...
Kentik
3 years, 7 months ago
I would go for C
upvoted 1 times
...
Justu
3 years, 7 months ago
D: Enable CloudHub functionality to route traffic between the three VPCs and the corporate network using dynamic BGP routing.
upvoted 1 times
...
liono
3 years, 7 months ago
CloudHub enables your remote sites to communicate with each other, and not just with the VPC. It operates on a simple hub-and-spoke model that you can use with or without a VPC. This design is suitable for customers with multiple branch offices and existing internet connections who would like to implement a convenient, potentially low-cost hub-and-spoke model for primary or backup connectivity between these remote offices.
upvoted 1 times
Kentik
3 years, 7 months ago
CloudHub is for when you want have branch to branch connection and not VPC to VPC, in order to connect a VPC to a VGW you need a software VPN on that VPN, i would go for C
upvoted 3 times
...
...
Kafin
3 years, 8 months ago
D for me, CloudHub allows several sources (VPCs and On-premises) to exchange route through a VGW. I would love to see the complete wording... Option C will be very labor intensive to administer.
upvoted 1 times
...
guruguru
3 years, 8 months ago
Answer is C. A, cannot associate route table to onprem with peering. B, VPN from VGW to VGW won't work. Need EC2 VPN or Onprem VPN to initiate the connection. D, CloudHub is for one VPC to multiple onprem sites.
upvoted 4 times
...
Neil101
3 years, 8 months ago
C. https://aws.amazon.com/answers/networking/aws-multiple-vpc-vpn-connection-sharing/
upvoted 1 times
guruguru
3 years, 8 months ago
The design in the link is updated to transit gateway design. Not relevant anymore.
upvoted 1 times
...
...
Ajani
3 years, 8 months ago
Ambiguous questions ; Native Network Access could imply or mean Direct/original(not going through another source). If so, we end up with a full mesh of connections , which seems reasonable. Hence C for me. To be absolutely sure we need to know what they really meant by Native network access from corp.
upvoted 1 times
...
CloudTrail
3 years, 8 months ago
C is the only relevant answer. A- with VPC peering you cannot transit a VPC. B - You cannot establish between vpn gateways in 2 different VPNs.
upvoted 2 times
...
BillyC
3 years, 8 months ago
C for me
upvoted 1 times
...
Puma4843
3 years, 8 months ago
A is wrong since it will not allow on-premise to access app VPCs due to VPC does not support transitive routing
upvoted 1 times
azeemk7860
3 years, 7 months ago
But isn't shared services VPC aka transit VPC's functionality to enable transitive routing. I go with A.
upvoted 1 times
azeemk7860
3 years, 7 months ago
sorry changing to C as it mentions VPC peering which is non transitive
upvoted 1 times
...
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...