AWS Transit Gateway Route Optimization

A company uses transit gateways to route traffic between the company's VPCs. Each transit gateway has a single route table. Each route table contains attachments and routes for the VPCs that are in the same AWS Region as the transit gateway. The route tables in each VPC also contain routes to all the other VPC CIDR ranges that are available through the transit gateways. Some VPCs route to local NAT gateways. The company plans to add many new VPCs soon. A network engineer needs a solution to add new VPC CIDR ranges to the route tables in each VPC. Which solution will meet these requirements in the MOST operationally efficient way?

  1. Create a new customer-managed prefix list. Add all VPC CIDR ranges to the new prefix list. Update the route tables in each VPC to use the new prefix list ID as the destination and the appropriate transit gateway ID as the target. Source Reference Answer
  2. Turn on default route table propagation for the transit gateway route tables. Turn on route propagation for each route table in each VPC.
  3. Update the route tables in each VPC to use 0.0.0.010 as the destination and the appropriate transit gateway ID as the target.
  4. Turn on default route table association for the transit gateway route tables. Turn on route propagation for each route table in each VPC.

Community Votes

A
100%

100% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

The exam tests knowledge of AWS Transit Gateway routing mechanisms, specifically highlighting that manual static routes do not automatically propagate and that prefix lists reduce administrative overhead.

This question addresses the operational efficiency of managing dynamic route updates in AWS Transit Gateways using prefix lists. The community consensus confirms that customer-managed prefix lists are the optimal solution for scalable VPC CIDR management.

Candidates often select option B or D, mistakenly believing that enabling default association/propagation will automatically inject all new VPC routes into every local VPC route table without explicit configuration.

Community Discussion (3 comments)

woorkim 👍 1
answer is A Route propagation — A VPC, VPN connection, or Direct Connect gateway can dynamically propagate routes to a transit gateway route table. With a Connect attachment, the routes are propagated to a transit gateway route table by default. With a VPC, you must create static routes to send traffic to the transit gateway. With a VPN connection, routes are propagated from the transit gateway to your on-premises router using Border Gateway Protocol (BGP). With a Direct Connect gateway, allowed prefixes are originated to your on-premises router using BGP. With a peering attachment, you must create a static route in the transit gateway route table to point to the peering attachment.
jfedotov 👍 2 Selected: A
A https://docs.aws.amazon.com/vpc/latest/tgw/create-prefix-list-reference.html
kowal_001 👍 1 Selected: A
A. b -> won't work here c - > can break internet facing VPCs d -> also won't work

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

Option A is correct because it leverages a customer-managed prefix list to aggregate multiple VPC CIDRs into a single destination entry. When a new VPC is added, the engineer only needs to update the prefix list rather than modifying individual route tables across all regions. This significantly reduces operational effort compared to managing hundreds of static routes.

Why the Other Options Are Wrong

Options B and D rely on route propagation, which propagates routes from the Transit Gateway TO the VPCs, but the scenario describes VPCs needing specific routes TO other VPCs via the TGW. Furthermore, default associations (Option D) associate attachments with the default route table, not necessarily pushing routes to all local VPCs efficiently. Option C suggests a default route (0.0.0.0/0), which would send all internet-bound traffic through the Transit Gateway, breaking connectivity for VPCs using local NAT gateways as mentioned in the prompt.

Community Comment Notes

Comments [1] and [2] confirm that prefix lists are the standard best practice for this scenario. Comment [3] correctly identifies that options B and D are ineffective here because they do not solve the problem of populating local VPC route tables with specific external CIDRs efficiently, and warns that option C breaks internet access.

Official Reference

Exam Strategy

Always look for keywords like 'operationally efficient' and 'scalable' when dealing with network changes. If a task involves repetitive manual updates to many resources, look for a centralized abstraction layer like Prefix Lists or AWS Config rules.

Related Analysis

Practice All ANS-C01 Questions

Access 137 questions with complete answers and detailed explanations.

View Full ANS-C01 Practice Test →

← Back to ANS-C01 Study Guide