How to Connect On-Premises to Another Account's Transit Gateway via Existing Direct Connect?

Company A recently acquired Company B. Company A has a hybrid AWS and on-premises environment that uses a hosted AWS Direct Connect connection, a Direct Connect gateway, and a transit gateway. Company A has a transit VIF to access the resources in its production environment in the us-east-1 Region. Company B has applications that run across multiple VPCs in the us-west-2 Region in a single AWS account. A transit gateway connects all Company B's application VPCs. The CIDR blocks for both companies do not overlap. Company A needs to use the existing Direct Connect connection to access Company B’s applications from the on-premises environment. Which solution will meet these requirements?

  1. Create a new Direct Connect gateway in the Company B account. Associate the Company B transit gateway with the new Direct Connect gateway. Create a transit VIF on the existing hosted connection for Company B.
  2. Create an association proposal from the Company B account to associate the Company B transit gateway with the Company A Direct Connect gateway. Accept the transit gateway association proposal by logging into the Company A account. Source Reference Answer
  3. Create multiple virtual private gateways. Attach the virtual private gateways to each of Company B's application VPCs. Create a hosted private VIF for each virtual private gateway.
  4. Create a new Direct Connect gateway in the Company B account. Associate the Company B transit gateway with the new Direct Connect gateway. Create a hosted private VIF for Company B.

Community Votes

B
100%

100% of anonymous learners picked answer B. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

This question tests your understanding of inter-account transit gateway associations with Direct Connect gateways, where the key trap is assuming a new VIF or Direct Connect gateway is required instead of using an association proposal.

Learn the correct way to extend an existing AWS Direct Connect connection to access applications in another AWS account's transit gateway. The community agrees that creating a transit gateway association proposal is the most efficient solution.

A common mistake is choosing Option A, which incorrectly assumes you need to create a new Direct Connect gateway and transit VIF for Company B. In reality, a hosted Direct Connect connection can only have one transit VIF, and the existing Direct Connect gateway can be associated with the other account's transit gateway through a proposal.

Community Discussion (5 comments)

AzureDP900 👍 1
B is right Both companies have different AWS accounts, making it impossible for them to directly share a transit gateway. The existing hosted connection is in the us-east-1 Region, while Company B's applications are located in the us-west-2 Region, and they do not overlap with each other. Therefore, using the same transit VIF would not be viable without some sort of shared resource between them.
woorkim 👍 1
B is right! In Company B's account, create an association proposal to link the transit gateway in us-west-2 to Company A's Direct Connect gateway. In Company A's account, accept the association proposal. Update routing configurations to allow traffic from Company A's on-premises environment to reach Company B's applications via the Direct Connect gateway and transit gateway.
Akshay0403 👍 3 Selected: B
Option B is the most efficient solution for connecting Company A’s on-premises environment to Company B’s applications. It leverages the existing Direct Connect infrastructure, minimizing the need for additional hardware and configuration, and uses Direct Connect gateway and transit gateway association for seamless integration between the two companies’ environments.
Blitz1 👍 2 Selected: B
https://docs.aws.amazon.com/directconnect/latest/UserGuide/multi-account-associate-tgw.html
veyisceylan 👍 1
it is B. Hosted connection allows only one VIF(transit, public or private)

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

Option B is correct because it uses the existing Direct Connect gateway from Company A and establishes an association with Company B's transit gateway via a cross-account association proposal. This leverages the existing infrastructure, avoids creating duplicate Direct Connect resources, and is the recommended AWS pattern for sharing a Direct Connect gateway across accounts. The process involves creating an association proposal in Company B's account and accepting it in Company A's account, after which routing can be configured seamlessly.

Why the Other Options Are Wrong

Option A is wrong because a hosted connection can only have one VIF (transit, public, or private). Creating a second transit VIF on the same hosted connection is not permitted, and a new Direct Connect gateway would be unnecessary and costly. Option C is inefficient and incorrect because it requires multiple virtual private gateways and hosted private VIFs for each VPC, which is complex and does not leverage the existing transit gateway architecture. Option D is wrong because it still creates a new Direct Connect gateway and hosted private VIF, failing to take advantage of the existing Direct Connect gateway and transit gateway association capability.

Community Comment Notes

Commenters consistently voted for Option B and noted that the two companies have different AWS accounts, making direct transit gateway sharing impossible without a shared resource like a Direct Connect gateway. One commenter highlighted that the existing hosted connection already has a transit VIF, so only an association proposal is needed. Another provided the official AWS documentation link showing the multi-account transit gateway association procedure, which aligns with the accepted answer.

Official Reference

Exam Strategy

When you see a Direct Connect gateway and a transit gateway in different AWS accounts, immediately think of cross-account association proposals rather than creating new Direct Connect resources. Remember that a hosted connection supports only one VIF, so reusing the existing transit VIF is mandatory.

Related Analysis

Practice All ANS-C01 Questions

Access 137 questions with complete answers and detailed explanations.

View Full ANS-C01 Practice Test →

← Back to ANS-C01 Study Guide