AWS Transit Gateway Route Propagation for Dynamic CIDR Updates
A company runs workloads in multiple VPCs. The company needs to securely access a workload in one of the VPCs, named VPC-A, from an on-premises data center. A network engineer sets up an AWS Site-to-Site VPN connection to a transit gateway. The network engineer configures dynamic routing for the connection, and communication works properly. Recently, the owner of VPC-A added another CIDR range to the VPC. The VPC-A owner created workloads that use the additional CIDR range. The company's on-premises network is unable to reach the new workloads. The network engineer needs to resolve the network connectivity issue and ensure that connectivity will not be affected if additional VPC CIDR ranges are added to the VPC in the future. Which solution will meet these requirements with the MOST operational efficiency?
Community Votes
100% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
The core concept is that enabling route propagation allows the Transit Gateway to dynamically learn new prefixes from attached VPCs without manual intervention or complex automation.
This question tests the capability of AWS Transit Gateway route propagation to automatically update routes when VPC CIDR blocks change, ensuring seamless on-premises connectivity.
Candidates often choose options involving Lambda or EventBridge (C/D) thinking they need custom logic to detect changes, failing to realize that native route propagation handles this automatically.
Community Discussion (3 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
Enabling route propagation for a specific VPC attachment on the Transit Gateway's route table causes the TGW to automatically advertise all associated VPC CIDR ranges to connected VPN attachments. When the VPC owner adds a secondary CIDR block, the route propagation mechanism automatically includes this new range in the updates sent to the Site-to-Site VPN, allowing the on-premises router to learn the new path. This meets the requirement for operational efficiency as it requires zero code or manual steps.Why the Other Options Are Wrong
Option B requires manual updates every time a CIDR changes, violating the 'future-proof' and 'operational efficiency' requirements. Options C and D involve creating unnecessary infrastructure (Lambda, EventBridge/CloudWatch) to monitor for changes. While technically possible, this introduces significant operational overhead, complexity, and potential points of failure compared to the native feature provided by AWS.Community Comment Notes
Comments [1], [2], and [3] unanimously support Option A, highlighting that route propagation automatically handles the addition of new CIDRs to the VPN attachment route table without manual intervention.Official Reference
Exam Strategy
Always look for native AWS features that handle automation before considering custom solutions with Lambda or CloudWatch. If a service can natively propagate routes or states, using native capabilities is almost always the most operationally efficient choice.
Related Analysis
Practice All ANS-C01 Questions
Access 137 questions with complete answers and detailed explanations.
View Full ANS-C01 Practice Test →