How to Isolate AWS VPCs by Business Unit Across Regions? ANS-C01
A company uses the us-east-1 Region and the ap-south-1 Region for its business units (BUs). The BUS are named BU-1 and BU-Z. For each BU, there are two VPCs in us-east-1 and one VPC in ap-south-1. Because of workload isolation requirements, resources can communicate within the same BU but cannot communicate with resources in the other BU. The company plans to add more BUs and plans to expand into more Regions Which solution will meet these requirements with the MOST operational efficiency?
Community Votes
100% of anonymous learners picked answer D. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
The exam expects you to recognize that AWS Cloud WAN segments are purpose-built for per-workload or per-business-unit isolation across Regions, and the common trap is choosing deny route actions instead of native segment-level isolation.
This ANS-C01 question tests the most operationally efficient way to isolate VPCs by business unit across multiple AWS Regions. The community consensus is that AWS Cloud WAN segments provide native, scalable isolation (Option D), making it a better choice than transit gateway peering, deny-route actions, or isolate-attachments settings.
A common wrong answer is Option A, which uses segment actions to deny traffic between segments. While possible, this approach is less efficient and error-prone compared to defining separate segments for each BU, especially as the number of BUs and Regions increases.
Community Discussion (4 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
Option D is correct because AWS Cloud WAN segments directly map to each business unit (BU). By creating a segment per BU and attaching that BU's VPCs to the corresponding segment, the core network policy automatically isolates traffic between segments. This is the most operationally efficient solution because it avoids manually managing deny routes or complex route tables, and it scales naturally as more BUs and Regions are added.
Why the Other Options Are Wrong
Option A is wrong because using segment actions to deny traffic requires additional route policy configuration and is more error-prone than native segment isolation. Option B is wrong because transit gateway peering with per-Region transit gateways creates operational overhead for every pair of Regions and every BU; it does not scale well. Option C is wrong because the isolate-attachments parameter only isolates individual VPC attachments within a single segment—it does not provide logical separation between different BU segments.
Community Comment Notes
Community comments strongly support Option D. One comment (likes=2) highlights that segment-level isolation is the best option for traffic isolation, and another comment (likes=2) explains why A, B, and C are less efficient: deny actions are error-prone, transit gateway peering requires more maintenance, and isolate-attachments only isolates within a single segment. These comments align with the official AWS Cloud WAN design pattern of using segments for network segmentation across Regions.
Official Reference
Exam Strategy
When a networking scenario requires complete isolation between groups across multiple Regions, look for AWS Cloud WAN segments as the native, scalable solution. Avoid overcomplicating with deny route actions or manually peered transit gateways, and remember that isolate-attachments is not a substitute for segment-level separation.
Related Analysis
Practice All ANS-C01 Questions
Access 137 questions with complete answers and detailed explanations.
View Full ANS-C01 Practice Test →