AWS Certified Solutions Architect Professional SAP-C02 Practice Question
A multinational corporation is establishing a hybrid cloud environment, connecting their on-premises data center to a new VPC in the us-east-1 region. The connection must be highly available and support an aggregate throughput of up to 2 Gbps for large data transfers. The company's on-premises network uses BGP for dynamic routing. A Direct Connect link has been ordered but will not be operational for six months. The company requires a scalable interim solution that can be implemented immediately.
Which approach meets all these requirements?
Launch two EC2 instances in public subnets. Install and configure third-party VPN software on each instance and configure VPC route tables to distribute traffic between them.
Deploy a Transit Gateway. Create a Site-to-Site VPN connection with two tunnels terminating on the Transit Gateway, and enable Equal-Cost Multi-Path (ECMP) on the VPN attachment.
Deploy a Virtual Private Gateway (VGW) attached to the VPC. Create a Site-to-Site VPN connection with two tunnels to the VGW and use BGP for dynamic routing.
Configure an Accelerated Site-to-Site VPN connection with two tunnels to a Virtual Private Gateway (VGW) to leverage the AWS global network for increased performance.
The correct solution is to use a Transit Gateway with a Site-to-Site VPN connection and enable Equal-Cost Multi-Path (ECMP) routing. An individual AWS Site-to-Site VPN tunnel has a maximum throughput of 1.25 Gbps. To meet the 2 Gbps requirement, traffic must be load-balanced across multiple tunnels. A Transit Gateway supports ECMP on VPN attachments, which allows it to load-balance traffic across two or more tunnels to the same destination, thereby aggregating their bandwidth. This configuration also provides high availability, as the failure of one tunnel will not disrupt connectivity. Using a Transit Gateway is also a scalable solution for connecting additional VPCs in the future.
A Virtual Private Gateway (VGW) supports two tunnels for high availability, but it operates in an active/passive configuration and does not support ECMP. Therefore, it cannot aggregate bandwidth beyond the 1.25 Gbps limit of a single active tunnel. An Accelerated Site-to-Site VPN improves performance by reducing latency over the public internet but does not increase the maximum bandwidth of a VPN tunnel. While deploying a software-based VPN on EC2 instances is technically possible, it introduces significant management overhead and is not the AWS-native, fully managed, and scalable solution that Transit Gateway provides.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is a Transit Gateway, and why is it useful in hybrid cloud setups?
Open an interactive chat with Bash
What is Equal-Cost Multi-Path (ECMP), and how does it enhance VPN performance?
Open an interactive chat with Bash
Why is the Virtual Private Gateway (VGW) approach insufficient for meeting the 2 Gbps requirement?
Open an interactive chat with Bash
AWS Certified Solutions Architect Professional SAP-C02
Accelerate Workload Migration and Modernization
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
IT & Cybersecurity Package Join Premium for Full Access