ETExamTower
Q6Network Security, Compliance, and Governance

A company operates workloads across multiple VPCs. The company must securely access a workload in one of the VPCs, called VPC-A, from an on-premises data center. A network engineer establishes an AWS Site-to-Site VPN connection to a transit gateway. The network engineer configures dynamic routing for the connection, and communication functions correctly. Recently, the owner of VPC-A added an additional CIDR range to the VPC. The VPC-A owner created workloads that use the added CIDR range. The company's on-premises network cannot reach the new workloads. The network engineer must resolve the network connectivity issue and ensure that connectivity is not affected if more VPC CIDR ranges are added to the VPC in the future. Which solution meets these requirements with the **MOST** operational efficiency?

← → navigate · a answer
Community votes
A
100% (4)
B
0% (0)
C
0% (0)
D
0% (0)
Discussion · 3
A 2
By enabling route propagation for VPC-A to the VPN attachment route table, any new CIDR ranges added to VPC-A will automatically be propagated to the VPN attachment route table. This ensures that on-premises networks can reach the new workloads in VPC-A without manual updates.
A 2
When VPC-A adds a new CIDR, the route should automatically propagate to the VPN attachment route table, ensuring that the on-premises network learns the new CIDR without manual updates.
A 2
The 2nd CIDR will be automatically added to the VPC-A and will be propagated to the VPN attachment RT.