A company has configured an AWS Cloud WAN core network with edge locations in the us-east-1
Region and the us-west-1 Region. Each edge location has two segments: development and staging.
The segments use the default core network policy.
The company has attached VPCs to the core network. A development VPC is attached to the
development segment in us-east-1 and is configured to use the 10.0.0.0 CIDR block. A staging VPC
is attached to the staging segment in us-west-1 and is configured to use the 10.5.0.0 CIDR block. The company has updated the route tables for both VPCs with a route that directs any traffic for
0.0.0.0/0 to the core network.
The companys network team needs to establish communication between the two VPCs by using the
AWS Cloud WAN core network. The network team is not receiving a response during tests of
communication between the VPCs. The network team has verified that security groups and network
ACLs are not blocking the traffic.
What should the network team do to establish this communication?
A network engineer needs to build an encrypted connection between an on-premises data center
and a VPC. The network engineer attaches the VPC to a virtual private gateway and sets up an AWS
Site-to-Site VPN connection. The VPN tunnel is UP after configuration and is working. However,
during rekey for phase 2 of the VPN negotiation, the customer gateway device is receiving different
parameters than the parameters that the device is configured to support.
The network engineer checks the IPsec configuration of the VPN tunnel. The network engineer
notices that the customer gateway device is configured with the most secure encryption algorithms
that the AWS Site-to-Site VPN configuration file provides.
What should the network engineer do to troubleshoot and correct the issue?
Company A recently acquired Company B. Company A has a hybrid AWS and on-premises
environment that uses a hosted AWS Direct Connect connection, a Direct Connect gateway, and a
transit gateway. Company A has a transit VIF to access the resources in its production environment in
the us-east-1 Region.
Company B has applications that run across multiple VPCs in the us-west-2 Region in a single AWS
account. A transit gateway connects all Company B's application VPCs. The CIDR blocks for both
companies do not overlap.
Company A needs to use the existing Direct Connect connection to access Company Bs applications
from the on-premises environment.
Which solution will meet these requirements?
A consulting company manages AWS accounts for its customers. One of the company's customers
needs to add intrusion prevention for its environment without having to re-architect the
environment. The customer's environment includes five VPCs in two AWS Regions in the United
States. VPC-to-VPC connectivity is achieved through VPC peering. The customer does not plan to
increase the number of VPCs within the next 2 years. The solution must accommodate unencrypted
traffic.
Which solution will meet these requirements?
A company recently implemented a security policy that prohibits developers from launching VPC
network infrastructure. The policy states that any time a NAT gateway is launched in a VPC, the
company's network security team must immediately receive an alert to terminate the NAT gateway.
The network security team needs to implement a solution that can be deployed across AWS accounts
with the least possible administrative overhead. The solution also must provide the network security
team with a simple way to view compliance history.
Which solution will meet these requirements?