exam questions

Exam AWS Certified Solutions Architect - Professional All Questions

View all questions & answers for the AWS Certified Solutions Architect - Professional exam

Exam AWS Certified Solutions Architect - Professional topic 1 question 772 discussion

A company has 50 AWS accounts that are members of an organization in AWS Organizations. Each account contains multiple VPCs. The company wants to use
AWS Transit Gateway to establish connectivity between the VPCs in each member account. Each time a new member account is created, the company wants to automate the process of creating a new VPC and a transit gateway attachment.
Which combination of steps will meet these requirements? (Choose two.)

  • A. From the management account, share the transit gateway with member accounts by using AWS Resource Access Manager.
  • B. From the management account, share the transit gateway with member accounts by using an AWS Organizations SCP.
  • C. Launch an AWS CloudFormation stack set from the management account that automatically creates a new VPC and a VPC transit gateway attachment in a member account. Associate the attachment with the transit gateway in the management account by using the transit gateway ID.
  • D. Launch an AWS CloudFormation stack set from the management account that automatically creates a new VPC and a peering transit gateway attachment in a member account. Share the attachment with the transit gateway in the management account by using a transit gateway service-linked role.
  • E. From the management account, share the transit gateway with member accounts by using AWS Service Catalog.
Show Suggested Answer Hide Answer
Suggested Answer: AC 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
AndySH
Highly Voted 3 years, 4 months ago
A and C
upvoted 12 times
...
janvandermerwer
Most Recent 2 years, 6 months ago
Selected Answer: AC
Process of elimination. B - no - SCP's are not really for sharing resources. D - No - "peering transit gateway attachment" - Meant to really be peering transit gateway to transit gateway. E - No - Sure, you can configure service catalog via account factory, however that leaves the part out of automating the gateway attachment process (potentially) https://controltower.aws-management.tools/networking/tgw/tgw-simple/
upvoted 2 times
...
Ell89
2 years, 7 months ago
Selected Answer: AC
A & C you need to share the TGW via the RAM. the VPC TGW attachment needs to be associated with the TGW.
upvoted 3 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...