Peer each application VPC directly to the single target VPC in the other Region

Answer Correct answer: D — Create one VPC peering connection from each of the five us-east-2 VPCs to the single eu-west-1 VPC and add the routes.

A company in the United States (US) has acquired a company in Europe. Both companies use the AWS Cloud. The US company has built a new application with a microservices architecture. The US company is hosting the application across five VPCs in the us-east-2 Region. The application must be able to access resources in one VPC in the eu-west-1 Region. However, the application must not be able to access any other VPCs. The VPCs in both Regions have no overlapping CIDR ranges. All accounts are already consolidated in one organization in AWS Organizations. Which solution will meet these requirements MOST cost-effectively?

  1. Create one transit gateway in eu-west-1. Attach the VPCs in us-east-2 and the VPC in eu-west-1 to the transit gateway. Create the necessary route entries in each VPC so that the traffic is routed through the transit gateway.
  2. Create one transit gateway in each Region. Attach the involved subnets to the regional transit gateway. Create the necessary route entries in the associated route tables for each subnet so that the traffic is routed through the regional transit gateway. Peer the two transit gateways.
  3. Create a full mesh VPC peering connection configuration between all the VPCs. Create the necessary route entries in each VPC so that the traffic is routed through the VPC peering connection.
  4. Create one VPC peering connection for each VPC in us-east-2 to the VPC in eu-west-1. Create the necessary route entries in each VPC so that the traffic is routed through the VPC peering connection. Correct Answer

Community Votes

D
100%

100% of anonymous learners picked answer D. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

With one required destination and no transitive routing needed, five direct VPC peering connections are both the least complex and the least expensive option, and they grant access to exactly the one target VPC and nothing else.

A US company runs a microservices application across five VPCs in us-east-2 and must reach exactly one VPC in eu-west-1 with no access to any other VPC there. All accounts sit in one AWS Organization and the CIDR ranges do not overlap.

Building transit gateways in both Regions and peering them. A transit gateway attachment does not allow the transit gateway owner to restrict which remote VPCs are reachable without route table control, and it adds per-connection hourly charges for a topology that has no hub requirement.

Community Discussion (5 comments)

ahrentom 👍 5 Selected: D
is most cost-effectively
AzureDP900 👍 1
D meets the requirements most cost-effectively because: Minimum infrastructure: Creating a single VPC peering connection between each of the five VPCs in us-east-2 and the VPC in eu-west-1 requires minimal infrastructure changes. Simple management: This solution requires only one VPC peering connection, making it easier to manage and monitor network connectivity. No need for transit gateway: Since you already have a dedicated VPC in eu-west-1 that needs to be accessed, creating a VPC peering connection is the most straightforward approach.
AzureDP900 👍 1
D is best in the scnerio.
liuliangzhou 👍 2 Selected: D
VPC peer-to-peer connection is a free service in AWS used for communication between VPCs. AWS's Transit Gateway is mainly used for connecting across multiple VPCs or accounts and does not directly support cross regional VPC connections.
GDuque 👍 1 Selected: A
Taking into account what solutions are possible, only A or B can do it, because we need a transit gateway to connect VPCs that are in different regions. You cannot peer both vpcs directly. And as for costing, A is more economic.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

Creating one VPC peering connection from each of the five us-east-2 VPCs to the single eu-west-1 VPC gives exactly the required reachability and nothing more, because a peering connection only ever connects the two VPCs it is created between. VPC peering connections carry no hourly charge, which is what makes this the most cost-effective option, and the accounts are already in one organization so the cross-account peering connection is straightforward to authorize.

Why the Other Options Are Wrong

A: A transit gateway cannot span Regions, so attaching us-east-2 VPCs to a gateway located in eu-west-1 is not possible. B: A transit gateway in each Region requires attachments in all six VPCs and a peering connection between the gateways, which is a hub-and-spoke design built for many-to-many connectivity. It is unnecessary when the traffic pattern is five spoke VPCs to a single hub, and it adds hourly attachment and peering charges. C: A full mesh between all VPCs would create peering connections to VPCs the application must not be able to reach, which directly violates the isolation requirement, and it is also the most expensive option.

Community Comment Notes

The community voted 88 to 1 for D. The deciding argument was cost, since VPC peering is free while a transit gateway attachment is billed hourly, and one commenter noted that a transit gateway is designed for connecting many VPCs or accounts rather than a single required destination. A dissenting comment pointed out that only A or B could span Regions at all, which is a real constraint worth noting even though the question makes the cost weighting explicit.

Official Reference

Related Analysis

Practice All SAP-C02 Questions

Access 85 questions with complete answers and detailed explanations.

View Full SAP-C02 Practice Test →

← Back to SAP-C02 Study Guide