Reviewed by Aditya Kumar · Last reviewed 2026-03-24
**Why VPC Peering**: Direct private connectivity without traversing the public internet—lower latency, no egress charges for cross-account traffic within the same region. **Architecture**: (1) In Account A, create a peering connection request to Account B using peer account ID...
This hard-level Cloud/Tools question appears frequently in data engineering interviews at companies like Persistent Systems. While less common, it tests deeper understanding that distinguishes strong candidates.
This is a senior-level question that tests architectural thinking. Lead with the high-level design, then drill into specifics. Discuss trade-offs explicitly - there is rarely one correct answer. Show awareness of scale, fault tolerance, and operational complexity.
Why VPC Peering: Direct private connectivity without traversing the public internet—lower latency, no egress charges for cross-account traffic within the same region. Architecture: (1) In Account A, create a peering connection request to Account B using peer account ID and VPC ID. (2) Account B accepts. (3) Update route tables in both VPCs—add routes to peer CIDR via pcx-xxx. (4) Update security groups to allow peer CIDR. (5) Ensure no overlapping CIDR blocks—transitive peering is not supported. Scalability trade-off: Peering is non-transitive; with N VPCs you need N*(N-1)/2 peering connections—a 10-VPC mesh = 45 connections. Beyond ~20 VPCs, Transit Gateway is the right pattern. Cost: Same-region peering has no data transfer charge; cross-region peering incurs $0.02/GB (both sides). At 10TB/month cross-region, that's $400+—Transit Gateway may be cheaper for complex topologies. Implementation: Terraform/CloudFormation for repeatability. Enable DNS resolution in peering for private hosted zones. Use separate route tables per subnet if you need to restrict which traffic goes peer vs. internet.
Pro-Move: Mention using VPC Flow Logs post-peering to validate traffic and detect unexpected flows—shows operational maturity. Red Flag: Forgetting CIDR overlap or not considering Transit Gateway for multi-VPC—indicates inexperience with large-scale networking.
Some links below are affiliate links. If you buy through them we may earn a small commission at no extra cost to you — it helps keep DataEngPrep free.
According to DataEngPrep.tech, this is one of the most frequently asked Cloud/Tools interview questions, reported at 1 company. DataEngPrep.tech maintains an editor-reviewed database of 1,863 data engineering interview questions across 7 categories.