Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Amazon Exam ANS-C01 Topic 4 Question 24 Discussion

Actual exam question for Amazon's ANS-C01 exam
Question #: 24
Topic #: 4
[All ANS-C01 Questions]

A company's network engineer is designing an active-passive connection to AWS from two on-premises data centers. The company has set up AWS Direct Connect connections between the on-premises data centers and AWS. From each location, the company is using a transit VIF that connects to a Direct Connect gateway that is associated with a transit gateway.

The network engineer must ensure that traffic from AWS to the data centers is routed first to the primary data center. The traffic should be routed to the failover data center only in the case of an outage.

Which solution will meet these requirements?

Show Suggested Answer Hide Answer
Suggested Answer: C

The correct solution is to use an S3 interface endpoint and an on-premises DNS resolver. An S3 interface endpoint allows you to access Amazon S3 using private IP addresses within your VPC. An on-premises DNS resolver can be configured to forward the DNS queries for the S3 domain names to the S3 interface endpoint, so that the on-premises workloads can access Amazon S3 privately over the VPN connection. This solution is operationally efficient, as it does not require any additional infrastructure or changes to the existing workloads. The VPC workloads can continue to use the S3 gateway endpoint, which provides lower latency and higher throughput than the S3 interface endpoint.


Contribute your Thoughts:

Rachael
1 days ago
Wait, are we supposed to be setting the BGP community tags to 9100 and 9300? That seems a bit odd, but I'll give it a shot.
upvoted 0 times
...
Layla
5 days ago
Ah, I see! The primary data center prefixes need to be preferred over the failover data center prefixes. This should do the trick.
upvoted 0 times
...
Annalee
12 days ago
Hmm, I see your point. Setting the BGP community tag for the primary data center to 7224:9100 does make sense for routing traffic first to the primary data center.
upvoted 0 times
...
Luisa
16 days ago
I disagree, I believe the correct answer is D) Set the BGP community tag for all prefixes from the primary data center to 7224:9100.
upvoted 0 times
...
Luis
18 days ago
Hmm, this looks tricky. I need to make sure I understand the routing requirements correctly.
upvoted 0 times
...
Annalee
22 days ago
I think the answer is A) Set the BGP community tag for all prefixes from the primary data center to 7224:7100.
upvoted 0 times
...

Save Cancel
az-700  pass4success  az-104  200-301  200-201  cissp  350-401  350-201  350-501  350-601  350-801  350-901  az-720  az-305  pl-300  

Warning: Cannot modify header information - headers already sent by (output started at /pass.php:70) in /pass.php on line 77