Hard1 markMultiple Choice
Domain 1.1: Network ConnectivityNetworkingTransit GatewayGWLB

AWS SAP-C02 · Question 02 · Domain 1.1: Network Connectivity

An organization has 50 VPCs across two AWS Regions connected via Transit Gateways (TGW). The TGWs are peered. The security team mandates that all inter-VPC traffic must be inspected by a centralized fleet of third-party firewall appliances. How should the architect design this network?

Answer options:

A.

Deploy firewall appliances on EC2 instances in each VPC. Update VPC route tables to route traffic through the local firewall.

B.

Deploy Gateway Load Balancers (GWLB) with the firewall appliances in a centralized inspection VPC in each region. Route traffic from TGW to the GWLB endpoints.

C.

Use AWS Network Firewall in every VPC and peer them using VPC peering instead of TGW.

D.

Deploy an Application Load Balancer in a central VPC and route all TGW traffic through it.

How to approach this question

Look for the service designed specifically for transparent inline inspection using third-party appliances.

Full Answer

B.Deploy Gateway Load Balancers (GWLB) with the firewall appliances in a centralized inspection VPC in each region. Route traffic from TGW to the GWLB endpoints.✓ Correct
Gateway Load Balancer (GWLB) is designed to deploy, scale, and manage third-party virtual appliances transparently.

Common mistakes

Choosing Network Load Balancer, which requires complex NAT configurations for inline inspection.

Practice the full AWS Solutions Architect Professional SAP-C02 Practice Exam 6

75 questions · hints · full answers · grading

More questions from this exam