AWS Certified Solutions Architect Professional SAP-C02 Practice Question
A financial services company uses AWS for its primary cloud operations, with multiple VPCs in us-east-1 connected via an AWS Transit Gateway. The company has an existing 10 Gbps AWS Direct Connect connection to its on-premises data center. A new strategic partner requires a highly available and secure connection between the company's AWS environment and the partner's application, which runs in a Microsoft Azure VNet in the East US 2 region. The solution must support a sustained throughput of 1 Gbps, and all traffic must remain on private networks, never traversing the public internet. Which of the following connectivity strategies best meets all the requirements?
Establish a Site-to-Site VPN connection with two tunnels for redundancy between the AWS Transit Gateway and a Virtual Network Gateway in the partner's Azure VNet. Configure dynamic routing using BGP over the VPN.
Order a 1 Gbps AWS Direct Connect hosted connection from a cloud exchange provider. Through the same provider, provision an Azure ExpressRoute circuit and establish a cross-connect between them. Associate the new transit VIF with a Direct Connect gateway that is attached to the AWS Transit Gateway.
Create a new public virtual interface (VIF) on the existing Direct Connect connection. Route traffic from the AWS VPCs to the public IP addresses of the partner's application in Azure. The partner will configure their Network Security Group to allow traffic only from the company's public IP range.
Configure an AWS PrivateLink endpoint service fronted by a Network Load Balancer in a central VPC. Instruct the partner to create an Azure Private Link connection that targets the public DNS of the AWS endpoint service to establish a private link.
The correct approach is to leverage a cloud exchange provider to connect the existing AWS Direct Connect to an Azure ExpressRoute circuit. This solution creates a completely private, high-bandwidth, and low-latency path between AWS and Azure. By using a Direct Connect gateway associated with the Transit Gateway, the connectivity can be extended to all VPCs attached to the Transit Gateway, providing a scalable and centrally managed solution. A transit VIF on the Direct Connect gateway is the proper way to integrate with a Transit Gateway for scalable hybrid connectivity.
A Site-to-Site VPN, while encrypted, routes traffic over the public internet, which violates a key requirement and generally offers less predictable performance and latency compared to a dedicated connection like Direct Connect and ExpressRoute.
AWS PrivateLink and Azure Private Link are designed to provide private access to specific services within their respective clouds or from a customer's VPC to a partner's service endpoint within the same cloud platform. They cannot be used to establish a direct network bridge between an entire AWS VPC and an Azure VNet.
A public VIF on a Direct Connect connection is used to access public AWS service endpoints (like S3 or DynamoDB) without traversing the internet to reach the AWS network edge. However, traffic from AWS to Azure would still need to traverse the public internet, violating the core security requirement.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is a Transit Virtual Interface (VIF) and how does it work with Direct Connect?
Open an interactive chat with Bash
What is a cloud exchange provider and how does it facilitate private connections between AWS and Azure?
Open an interactive chat with Bash
Why doesn’t an AWS PrivateLink endpoint or Site-to-Site VPN connection meet the requirements in this scenario?
Open an interactive chat with Bash
AWS Certified Solutions Architect Professional SAP-C02
Design Solutions for Organizational Complexity
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .