For IndividualsFor Educators
ExpertMinds LogoExpertMinds
ExpertMinds

Ace your certifications with Practice Exams and AI assistance.

  • Browse Exams
  • For Educators
  • Blog
  • Privacy Policy
  • Terms of Service
  • Cookie Policy
  • Support
  • AWS SAA Exam Prep
  • PMI PMP Exam Prep
  • CPA Exam Prep
  • GCP PCA Exam Prep

© 2026 TinyHive Labs. Company number 16262776.

    PracticeAWS Solutions Architect Professional (SAP-C02)AWS Solutions Architect Professional SAP-C02 Practice Exam 7Question 12
    Hard1 markMultiple Choice
    Domain 3.2: Security ImprovementSecurityNetwork FirewallTransit Gateway

    AWS SAP-C02 · Question 12 · Domain 3.2: Security Improvement

    A security audit reveals that several Amazon EC2 instances in a VPC have unrestricted outbound internet access. The security team requires that all outbound traffic be inspected, and access to known malicious domains must be blocked. The solution must be highly available and scale automatically. Which combination of steps should the architect take? (Select TWO)

    Answer options:

    A.

    Deploy AWS Network Firewall in a dedicated inspection VPC.

    B.

    Configure Security Groups on all EC2 instances to block outbound traffic to malicious IP addresses.

    C.

    Deploy a fleet of open-source proxy servers on EC2 instances in an Auto Scaling group.

    D.

    Route all outbound traffic from the application VPCs through a Transit Gateway to the inspection VPC.

    E.

    Enable AWS WAF on the EC2 instances to filter outbound requests.

    F.

    Use Amazon Macie to detect malicious outbound network patterns.

    How to approach this question

    Look for the managed service designed for centralized egress inspection.

    Full Answer

    Deploy AWS Network Firewall in a dedicated inspection VPC., Route all outbound traffic from the application VPCs through a Transit Gateway to the inspection VPC.
    AWS Network Firewall is a managed service that provides domain filtering and stateful inspection. Deploying it in a centralized inspection VPC connected via Transit Gateway is the best practice for scalable egress filtering.

    Common mistakes

    Thinking Security Groups can filter by domain name.
    Question 11All questionsQuestion 13

    Practice the full AWS Solutions Architect Professional SAP-C02 Practice Exam 7

    75 questions · hints · full answers · grading

    Sign up freeTake the exam

    More questions from this exam

    Q01A global enterprise is designing a multi-region network architecture connecting 50 AWS accounts a...HardQ02A company is migrating its hybrid network to AWS. They have two 10 Gbps AWS Direct Connect connec...HardQ03An enterprise has 100 AWS accounts in AWS Organizations. The security team mandates that all Amaz...MediumQ04A financial company requires that all EBS volumes, S3 buckets, and RDS databases be encrypted usi...EasyQ05An enterprise is designing a disaster recovery strategy for a critical application running on Ama...Hard
    View all 75 questions →