ETExamTower
Q27Network DesignMultiple answers

A company has five VPCs in the `us-east-1` Region. It hosts an internal web application in `us-east-1`. One company VPC, named VPC-A, must connect to an external partner's AWS environment. The partner environment is in the same AWS Region, where the partner hosts a new version of the company's web application in a VPC named VPC-B. The company has Amazon EC2 instances in VPC-A that must connect to the web application in VPC-B. A network engineer discovers that the partner's VPC-B and the company's VPC-A use the same IP space. The network engineer needs a solution that allows the EC2 instances to connect to the web application without negatively affecting the existing environment of either the company or the partner. Which combination of steps should the network engineer take to meet these requirements? (Choose two.)

Select 2 answers.
← → navigate · a answer
Community votes
B
50% (4)
C
50% (4)
A
0% (0)
D
0% (0)
E
0% (0)
Discussion · 3
B, C 4
B and C: see https://aws.amazon.com/blogs/networking-and-content-delivery/connecting-networks-with-overlapping-ip-ranges/
B, C 4
Handles overlapping IP ranges Doesn't require network changes Provides secure connectivity Uses AWS PrivateLink, which is designed for this scenario Maintains isolation between environments
B, C 3
AWS PrivateLink (which uses VPC endpoint services) is specifically designed to connect services across VPCs without requiring overlapping CIDR ranges to be routable between them. This solves the IP overlap problem without requiring IP address changes. The partner would create a VPC endpoint service backed by a Network Load Balancer that fronts their web application in VPC-B. The company would then create a VPC endpoint in VPC-A that connects to the partner's endpoint service, allowing EC2 instances to access the application using a private DNS name that resolves to a private IP within VPC-A's address space.