PrepAway - Latest Free Exam Questions & Answers

Which two methods increases the fault tolerance of the connection to VPC-1?

A company has configured and peered two VPCs: VPC-1 and VPC-2. VPC-1 contains only private subnets, and
VPC-2 contains only public subnets. The company uses a single AWS Direct Connect connection and private
virtual interface to connect their on-premises network with VPC-1. Which two methods increases the fault
tolerance of the connection to VPC-1? Choose 2 answers

PrepAway - Latest Free Exam Questions & Answers

A.
Establish a hardware VPN over the internet between VPC-2 ana the on-premises network.

B.
Establish a hardware VPN over the internet between VPC-1 and the on-premises network.

C.
Establish a new AWS Direct Connect connection and private virtual interface in the same region as VPC-2.

D.
Establish a new AWS Direct Connect connection and private virtual interface in a different AWS region than
VPC-1.

E.
Establish a new AWS Direct Connect connection and private virtual interface in the same AWS region as
VPC-1

22 Comments on “Which two methods increases the fault tolerance of the connection to VPC-1?

      1. Tuan says:

        we can setting VPC Peering/PVN Connection between VPC1 and VPC2 to make connection but in this question, There is not any information about this setting. But in my thinking, BC maybe correct.




        0



        0
        1. mutiger91 says:

          I’m not sure you understood @gopa’s response.

          Each VPC has its own virtual router. Each router has interfaces to internal traffic (within the VPC) and to external traffic (outside of the VPC). For EC2 instances or other services launched in the VPC, you can create routes to anything that your VPC router can see. However, a VPC router will never take traffic that originates outside of the VPC and pass it through to another destination outside of the VPC.

          That means that even if you do create a 0/0 route to the peering interface from VPC2, VPC1 virtual router will simply drop all packets not destined for the IP range in VPC1. It will not forward.

          Also, another clue that BC is wrong is because @networkmanagers says it is correct.




          4



          0
  1. Vlad says:

    BE
    “Establish a new AWS Direct Connect connection and private virtual interface in the same region as VPC-2” – Different VPC and Transitive Peering does not work




    6



    0
    1. shaam says:

      D can’t be correct, it talks about a new AWS direct connect in a different AWS region than VPC-1. VPC peering works only where both VPCs are in the same region.




      2



      0
  2. thinker says:

    B C

    we are talking about fault tolerance. In the case of direct connect line failure between on-premises to vpc1, we need other ways to connect on-premises with vpc1:
    vpn is using internet connection, we can set up vpn between on-premises and vpc1
    or
    DC between on-premise and vpc2. since there is peer connection between vpc2 and vpc1. we are still able to connect to vpc1




    0



    1
    1. shaam says:

      B and C are correct. Technically A should also be true since Hardware VPN between on premises and VPC2 can also help, but that’s a very indirect. B and C are more closer.




      0



      0

Leave a Reply

Your email address will not be published. Required fields are marked *