Expose a shared NLB through a VPC endpoint service when CIDR blocks overlap

Answer Correct answer: B — Create a VPC endpoint service from the NLB with acceptance required, then create and accept endpoints in each business unit VPC.

A company provides a centralized Amazon EC2 application hosted in a single shared VPC. The centralized application must be accessible from client applications running in the VPCs of other business units. The centralized application front end is configured with a Network Load Balancer (NLB) for scalability. Up to 10 business unit VPCs will need to be connected to the shared VPC. Some of the business unit VPC CIDR blocks overlap with the shared VPC, and some overlap with each other Network connectivity to the centralized application in the shared VPC should be allowed from authorized business unit VPCs only. Which network configuration should a solutions architect use to provide connectivity from the client applications in the business unit VPCs to the centralized application in the shared VPC?

  1. Create an AWS Transit Gateway. Attach the shared VPC and the authorized business unit VPCs to the transit gateway. Create a single transit gateway route table and associate it with all of the attached VPCs. Allow automatic propagation of routes from the attachments into the route table. Configure VPC routing tables to send traffic to the transit gateway.
  2. Create a VPC endpoint service using the centralized application NLB and enable the option to require endpoint acceptance. Create a VPC endpoint in each of the business unit VPCs using the service name of the endpoint service. Accept authorized endpoint requests from the endpoint service console. Correct Answer
  3. Create a VPC peering connection from each business unit VPC to the shared VPAccept the VPC peering connections from the shared VPC console. Configure VPC routing tables to send traffic to the VPC peering connection.
  4. Configure a virtual private gateway for the shared VPC and create customer gateways for each of the authorized business unit VPCs. Establish a Site-to-Site VPN connection from the business unit VPCs to the shared VPC. Configure VPC routing tables to send traffic to the VPN connection.

Community Votes

B
100%

100% of anonymous learners picked answer B. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

A VPC endpoint service gives each consumer VPC a private ENI address in its own address space, so overlapping CIDR blocks never have to be resolved, and enabling require endpoint acceptance makes the shared VPC owner explicitly approve each consumer before traffic flows.

A centralized EC2 application sits in a shared VPC behind a Network Load Balancer and up to ten business unit VPCs need to reach it. Some business unit CIDR blocks overlap the shared VPC and some overlap each other, and only authorized business unit VPCs may connect.

Using a transit gateway or VPC peering with overlapping address space. Neither can route between networks whose CIDR ranges overlap because the return traffic cannot be disambiguated, and a transit gateway with automatic route propagation would also make every attached VPC reachable, which violates the authorized-VPC-only requirement.

Community Discussion (11 comments)

sat2008 👍 7
B is the answer for me Only way to get around overlapping IP range is using endpoint service
0b43291 👍 3 Selected: B
By using a VPC endpoint service with the "require endpoint acceptance" option, the company can securely and efficiently provide connectivity from the client applications in the business unit VPCs to the centralized application in the shared VPC, while addressing the requirements of overlapping CIDR blocks and controlled access. A. AWS Transit Gateway: While Transit Gateway can connect multiple VPCs, it does not provide a mechanism to control access or handle overlapping CIDR blocks between VPCs. C. VPC Peering: VPC peering does not support overlapping CIDR blocks between VPCs, which is a requirement in this scenario. Additionally, managing multiple VPC peering connections can become complex and difficult to maintain as the number of VPCs increases. D. Site-to-Site VPN: No
AzureDP900 👍 1
By choosing Option B, you get secure, private connectivity between the client applications in the business unit VPCs and the centralized application in the shared VPC without introducing unnecessary complexity or costs. This configuration provides secure, private connectivity between the client applications in the business unit VPCs and the centralized application in the shared VPC.
Moghite 👍 2 Selected: B
only option to get around of IP overlapping https://aws.amazon.com/blogs/networking-and-content-delivery/connecting-networks-with-overlapping-ip-ranges/
43c89f4 👍 1
A is actually. they never mentioned cost effect or less effort solution. when they are not mentioned anything we need to prefer best option
career360guru 👍 1 Selected: B
option B
arberod 👍 2 Selected: B
B is the answer
HunkyBunky 👍 2 Selected: B
Answer is B Application already uses NLB so this is a best way for solve that task
kejam 👍 4 Selected: B
https://www.examtopics.com/discussions/amazon/view/46708-exam-aws-certified-solutions-architect-professional-topic-1/ https://aws.amazon.com/blogs/networking-and-content-delivery/connecting-networks-with-overlapping-ip-ranges/
master9 👍 1 Selected: B
VPC Endpoint Service can do the job
alexis123456 👍 4
Correct Answer is A

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

The defining constraint is overlapping CIDR blocks, and that eliminates every routing-based option. A VPC endpoint service fronts the existing Network Load Balancer, and consumers create a VPC endpoint in their own VPC using the endpoint service name, which gives them a private network interface inside their own address space. The consumer's traffic therefore never needs a routable path into the shared VPC, so overlapping ranges are irrelevant. Enabling the require endpoint acceptance option means the shared VPC administrator must accept each endpoint request from the endpoint service console, which is exactly the authorized-VPC-only control the requirement asks for, and it uses the existing NLB without redesigning the frontend.

Why the Other Options Are Wrong

A: A transit gateway cannot connect networks with overlapping CIDR blocks, because the gateway cannot determine which destination the return traffic belongs to, and with automatic route propagation a single shared route table would make all ten VPCs mutually reachable, which breaks the authorized-only requirement. C: VPC peering requires non-overlapping CIDR blocks by definition, so the overlapping ranges make peering impossible, and peering is also not the mechanism for controlling which business units are authorized. D: A virtual private gateway with Site-to-Site VPN is for connecting a VPC to an on-premises network through customer gateways, and it inherits the same routing limitation with overlapping address space.

Community Comment Notes

The community voted 100 to 0 for B, with the top-voted comments stating that a VPC endpoint service is the only way to work around overlapping IP ranges and linking the AWS networking blog on connecting networks with overlapping IP ranges. One dissenting comment argued for a transit gateway on the grounds that cost was not mentioned, but it did not address the overlapping CIDR constraint, which is the decisive factor.

Official Reference

Related Analysis

Practice All SAP-C02 Questions

Access 85 questions with complete answers and detailed explanations.

View Full SAP-C02 Practice Test →

← Back to SAP-C02 Study Guide