ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 15 - ANS-C01 discussion

Report
Export

A company has multiple AWS accounts. Each account contains one or more VPCs. A new security guideline requires the inspection of all traffic between VPCs.

The company has deployed a transit gateway that provides connectivity between all VPCs. The company also has deployed a shared services VPC with Amazon EC2 instances that include IDS services for stateful inspection. The EC2 instances are deployed across three Availability Zones. The company has set up VPC associations and routing on the transit gateway. The company has migrated a few test VPCs to the new solution for traffic inspection.

Soon after the configuration of routing, the company receives reports of intermittent connections for traffic that crosses Availability Zones.

What should a network engineer do to resolve this issue?

A.
Modify the transit gateway VPC attachment on the shared services VPC by enabling cross- Availability Zone load balancing.
Answers
A.
Modify the transit gateway VPC attachment on the shared services VPC by enabling cross- Availability Zone load balancing.
B.
Modify the transit gateway VPC attachment on the shared services VPC by enabling appliance mode support.
Answers
B.
Modify the transit gateway VPC attachment on the shared services VPC by enabling appliance mode support.
C.
Modify the transit gateway by selecting VPN equal-cost multi-path (ECMP) routing support.
Answers
C.
Modify the transit gateway by selecting VPN equal-cost multi-path (ECMP) routing support.
D.
Modify the transit gateway by selecting multicast support.
Answers
D.
Modify the transit gateway by selecting multicast support.
Suggested answer: B

Explanation:

To resolve the issue of intermittent connections for traffic that crosses Availability Zones after configuring routing for traffic inspection between VPCs using a transit gateway and EC2 instances with IDS services in a shared services VPC, a network engineer should modify the transit gateway VPC attachment on the shared services VPC by enabling appliance mode support (Option B). This will ensure that traffic is routed to the same EC2 instance for stateful inspection and prevent intermittent connections.

asked 16/09/2024
Ishan Patel
31 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first