Expose a shared NLB through a VPC endpoint service when CIDR blocks overlap
A company provides a centralized Amazon EC2 application hosted in a single shared VPC. The centralized application must be accessible from client applications running in the VPCs of other business units. The centralized application front end is configured with a Network Load Balancer (NLB) for scalability. Up to 10 business unit VPCs will need to be connected to the shared VPC. Some of the business unit VPC CIDR blocks overlap with the shared VPC, and some overlap with each other Network connectivity to the centralized application in the shared VPC should be allowed from authorized business unit VPCs only. Which network configuration should a solutions architect use to provide connectivity from the client applications in the business unit VPCs to the centralized application in the shared VPC?
Community Votes
100% of anonymous learners picked answer B. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
A VPC endpoint service gives each consumer VPC a private ENI address in its own address space, so overlapping CIDR blocks never have to be resolved, and enabling require endpoint acceptance makes the shared VPC owner explicitly approve each consumer before traffic flows.
A centralized EC2 application sits in a shared VPC behind a Network Load Balancer and up to ten business unit VPCs need to reach it. Some business unit CIDR blocks overlap the shared VPC and some overlap each other, and only authorized business unit VPCs may connect.
Using a transit gateway or VPC peering with overlapping address space. Neither can route between networks whose CIDR ranges overlap because the return traffic cannot be disambiguated, and a transit gateway with automatic route propagation would also make every attached VPC reachable, which violates the authorized-VPC-only requirement.
Community Discussion (11 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
The defining constraint is overlapping CIDR blocks, and that eliminates every routing-based option. A VPC endpoint service fronts the existing Network Load Balancer, and consumers create a VPC endpoint in their own VPC using the endpoint service name, which gives them a private network interface inside their own address space. The consumer's traffic therefore never needs a routable path into the shared VPC, so overlapping ranges are irrelevant. Enabling the require endpoint acceptance option means the shared VPC administrator must accept each endpoint request from the endpoint service console, which is exactly the authorized-VPC-only control the requirement asks for, and it uses the existing NLB without redesigning the frontend.Why the Other Options Are Wrong
A: A transit gateway cannot connect networks with overlapping CIDR blocks, because the gateway cannot determine which destination the return traffic belongs to, and with automatic route propagation a single shared route table would make all ten VPCs mutually reachable, which breaks the authorized-only requirement. C: VPC peering requires non-overlapping CIDR blocks by definition, so the overlapping ranges make peering impossible, and peering is also not the mechanism for controlling which business units are authorized. D: A virtual private gateway with Site-to-Site VPN is for connecting a VPC to an on-premises network through customer gateways, and it inherits the same routing limitation with overlapping address space.Community Comment Notes
The community voted 100 to 0 for B, with the top-voted comments stating that a VPC endpoint service is the only way to work around overlapping IP ranges and linking the AWS networking blog on connecting networks with overlapping IP ranges. One dissenting comment argued for a transit gateway on the grounds that cost was not mentioned, but it did not address the overlapping CIDR constraint, which is the decisive factor.Official Reference
Related Analysis
Practice All SAP-C02 Questions
Access 85 questions with complete answers and detailed explanations.
View Full SAP-C02 Practice Test →