AWS Certified CloudOps Engineer Associate SOA-C03 Practice Question
A company connects its production VPC (10.0.0.0/16) to the on-premises network (10.1.0.0/16) through an AWS Transit Gateway and a Site-to-Site VPN attachment. Subnet routes in the VPC point 10.1.0.0/16 to the transit gateway, but the transit gateway route table lists only the VPC CIDR. EC2 instances cannot reach on-premises servers. What change will restore connectivity securely?
Change the VPC subnet route so that 10.1.0.0/16 targets the virtual private gateway used by the VPN.
Enable route propagation from the Site-to-Site VPN attachment to the transit gateway route table.
Add a 0.0.0.0/0 static route in the transit gateway route table that targets the VPN attachment.
Deploy a NAT gateway in each private subnet and route traffic to the NAT gateway instead of the transit gateway.
The transit gateway must know how to forward traffic destined for 10.1.0.0/16 to the VPN attachment. Enabling route propagation (or adding a specific static route) on the transit gateway route table publishes the 10.1.0.0/16 prefix that the VPN advertises through BGP. Once the route is present, the transit gateway can forward packets bidirectionally between the VPC and the on-premises network. Adding a NAT gateway changes source addresses and is unnecessary. Advertising 0.0.0.0/0 is broader than required and violates least-privilege routing. Pointing the VPC subnet route to a virtual private gateway is invalid because the VPC is attached to a transit gateway, not a VGW.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is route propagation in AWS Transit Gateway?
Open an interactive chat with Bash
How does BGP work with Site-to-Site VPN in this scenario?
Open an interactive chat with Bash
What is the difference between a Transit Gateway and a Virtual Private Gateway (VGW)?
Open an interactive chat with Bash
AWS Certified CloudOps Engineer Associate SOA-C03
Networking and Content Delivery
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .