問題文
A team must let an on-premises system call an app in a Private Space, and must let the app call a service in the team's AWS VPC. Which mechanisms are needed for each direction?
選択肢
- Peering for both directions, because a peering connection is bidirectional and therefore also governs which callers from the on-premises network are permitted to reach the applications that run inside the space over their public hostnames.
- Trusted IP ranges to admit the on-premises system's addresses inbound, and peering to reach the VPC outbound.
- Internal routing for the inbound direction and a VPN for the outbound direction, since internal routing is what admits named external callers.
- Stable outbound addresses for both directions, and the same list of addresses admits callers into the space and identifies dynos to the VPC.