Question 5
ACE Inc. currently uses AWS as their primary cloud provider with a strong desire to expand to Azure and GCP. IT team has strict security and control requirements from different business units that require isolation and control from each other. The different business units want
* to own their own transit architecture
* the ability to control firewall rules for their own application
* to not share same transit with other business units but have ability to connect to other business units if needed.
The architecture board has mandated that there needs to be a single design pattern that accommodates above
requirements irrespective of the public cloud vendor being used.
Choose the best design option to meet above needs. Each option presents a complete solution.
Use AWS Transit Gateway (TGW). Deploy several TGWs in each region and peer them together as needed. Use TGW
VPN to build IPSec tunnels to Azure Virtual WAN and Google Cloud VPN.
Correct answer: A