Hard1 markMultiple Choice
Domain 1.2: Secure WorkloadsDomain 1SecurityTransit GatewayNetwork Firewall

AWS SAA-C03 · Question 14 · Domain 1.2: Secure Workloads

A company has 50 VPCs across multiple AWS accounts. They want to inspect all traffic leaving the VPCs for the internet using a centralized firewall appliance. What is the MOST scalable architecture?

Answer options:

A.

Deploy AWS Network Firewall in every VPC.

B.

Use VPC Peering to connect all VPCs in a full mesh.

C.

Connect all VPCs to an AWS Transit Gateway. Route traffic to a central inspection VPC.

D.

Use AWS WAF on the internet gateways of all VPCs.

How to approach this question

Look for a hub-and-spoke network architecture.

Full Answer

C.Connect all VPCs to an AWS Transit Gateway. Route traffic to a central inspection VPC.✓ Correct
Connect all VPCs to an AWS Transit Gateway. Route internet-bound traffic to a central inspection VPC containing AWS Network Firewall.
AWS Transit Gateway acts as a central hub. Routing traffic to a dedicated inspection VPC allows centralized security inspection using AWS Network Firewall.

Common mistakes

Choosing VPC Peering for a large number of VPCs.

Practice the full AWS SAA-C03 Practice Exam 2

65 questions · hints · full answers · grading

More questions from this exam