AWS Transit Gateway Route Propagation for Dynamic CIDR Updates

A company runs workloads in multiple VPCs. The company needs to securely access a workload in one of the VPCs, named VPC-A, from an on-premises data center. A network engineer sets up an AWS Site-to-Site VPN connection to a transit gateway. The network engineer configures dynamic routing for the connection, and communication works properly. Recently, the owner of VPC-A added another CIDR range to the VPC. The VPC-A owner created workloads that use the additional CIDR range. The company's on-premises network is unable to reach the new workloads. The network engineer needs to resolve the network connectivity issue and ensure that connectivity will not be affected if additional VPC CIDR ranges are added to the VPC in the future. Which solution will meet these requirements with the MOST operational efficiency?

  1. Configure route propagation for VPC-A to the VPN attachment route table. Source Reference Answer
  2. Manually update the VPN attachment route table to include the new CIDR range.
  3. Configure an Amazon EventBridge rule to invoke an AWS Lambda function when the rule to matches an update to the VPC-A CIDR range. Configure the Lambda function to update the VPN attachment route table.
  4. Configure an Amazon CloudWatch alarm to invoke an AWS Lambda function when there is an update to the VPC-A CIDR range. Configure the Lambda function to update the VPN attachment route table. Restart the VPN tunnels.

Community Votes

A
100%

100% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

The core concept is that enabling route propagation allows the Transit Gateway to dynamically learn new prefixes from attached VPCs without manual intervention or complex automation.

This question tests the capability of AWS Transit Gateway route propagation to automatically update routes when VPC CIDR blocks change, ensuring seamless on-premises connectivity.

Candidates often choose options involving Lambda or EventBridge (C/D) thinking they need custom logic to detect changes, failing to realize that native route propagation handles this automatically.

Community Discussion (3 comments)

ashk123456 👍 1 Selected: A
When VPC-A adds a new CIDR, the route should automatically propagate to the VPN attachment route table, ensuring that the on-premises network learns the new CIDR without manual updates.
woorkim 👍 1 Selected: A
By enabling route propagation for VPC-A to the VPN attachment route table, any new CIDR ranges added to VPC-A will automatically be propagated to the VPN attachment route table. This ensures that on-premises networks can reach the new workloads in VPC-A without manual updates.
c1193d4 👍 1 Selected: A
The 2nd CIDR will be automatically added to the VPC-A and will be propagated to the VPN attachment RT.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

Enabling route propagation for a specific VPC attachment on the Transit Gateway's route table causes the TGW to automatically advertise all associated VPC CIDR ranges to connected VPN attachments. When the VPC owner adds a secondary CIDR block, the route propagation mechanism automatically includes this new range in the updates sent to the Site-to-Site VPN, allowing the on-premises router to learn the new path. This meets the requirement for operational efficiency as it requires zero code or manual steps.

Why the Other Options Are Wrong

Option B requires manual updates every time a CIDR changes, violating the 'future-proof' and 'operational efficiency' requirements. Options C and D involve creating unnecessary infrastructure (Lambda, EventBridge/CloudWatch) to monitor for changes. While technically possible, this introduces significant operational overhead, complexity, and potential points of failure compared to the native feature provided by AWS.

Community Comment Notes

Comments [1], [2], and [3] unanimously support Option A, highlighting that route propagation automatically handles the addition of new CIDRs to the VPN attachment route table without manual intervention.

Official Reference

Exam Strategy

Always look for native AWS features that handle automation before considering custom solutions with Lambda or CloudWatch. If a service can natively propagate routes or states, using native capabilities is almost always the most operationally efficient choice.

Related Analysis

Practice All ANS-C01 Questions

Access 137 questions with complete answers and detailed explanations.

View Full ANS-C01 Practice Test →

← Back to ANS-C01 Study Guide