
Ultimate access to all questions.
A company operates hundreds of Amazon EC2 instances across two production VPCs (VPC A and VPC B) in all Availability Zones of the us-east-1 Region. To comply with a new security regulation, all traffic between the production VPCs must be inspected before reaching its destination. The company has implemented a shared VPC containing a stateful firewall appliance and a transit gateway with VPC attachments to route traffic between VPC A and VPC B through the firewall for inspection. However, during testing, the transit gateway drops traffic when it traverses between two Availability Zones. What should a network engineer do to resolve this issue with minimal management overhead?
A
In the shared VPC, replace the VPC attachment with a VPN attachment. Create a VPN tunnel between the transit gateway and the firewall appliance. Configure BGP.
B
Enable transit gateway appliance mode on the VPC attachment in VPC A and VPC B.
C
Enable transit gateway appliance mode on the VPC attachment in the shared VPC.
D
In the shared VPC, configure one VPC peering connection to VPC A and another VPC peering connection to VPC B.