LeetQuiz Logo
Privacy Policy•contact@leetquiz.com
© 2025 LeetQuiz All rights reserved.
AWS Certified Advanced Networking - Specialty

AWS Certified Advanced Networking - Specialty

Get started today

Ultimate access to all questions.


A company has set up connectivity between its on-premises data center in Paris, France, and the AWS Cloud using an AWS Direct Connect connection with a transit VIF linked to a transit gateway in the Europe (Paris) Region. The company operates workloads in private subnets across multiple VPCs attached to the transit gateway.

Following the acquisition of another corporation with on-premises workloads in Tokyo, Japan, the company needs to migrate these workloads to AWS within 5 days. The migrated workloads must access existing workloads in Paris, and connectivity must be established between the Tokyo office and the Paris data center.

In the Asia Pacific (Tokyo) Region, the company has created a new VPC with private subnets for the migration. The workloads must not be directly accessible from the internet.

What steps should a network engineer follow to fulfill these requirements?

Exam-Like



Explanation:

To meet the company's requirements, the network engineer needs to establish secure and efficient connectivity between the Tokyo office and the Paris data center, as well as between the workloads in the Tokyo VPC and the existing workloads in Paris. Option C is the correct choice because it outlines a comprehensive approach that includes setting up a transit gateway in the Asia Pacific (Tokyo) Region, creating peering connections between the Tokyo and Paris transit gateways, configuring an AWS Site-to-Site VPN connection from the Tokyo office to the Tokyo transit gateway, and configuring routing on both transit gateways to allow data flow. This approach ensures that the workloads are not directly accessible from the internet, meets the migration timeline, and establishes the necessary connectivity between the Tokyo office and the Paris data center. Option A is incorrect because it suggests creating public subnets and using an internet gateway, which contradicts the requirement that workloads cannot be directly accessible from the internet. Option B is incorrect because it proposes setting up a new Direct Connect connection, which may not be feasible within the 5-day migration timeline. Option D is incorrect because it suggests configuring an AWS Site-to-Site VPN connection directly to the Paris transit gateway without establishing a transit gateway in Tokyo, which does not fully meet the requirement for connectivity between the Tokyo VPC and the Paris workloads.

Powered ByGPT-5