Hard1 markMultiple Choice
Domain 1.1: Network ConnectivityNetworkingTransit GatewaySecurity

AWS SAP-C02 · Question 56 · Domain 1.1: Network Connectivity

An enterprise is building a centralized network inspection architecture using AWS Transit Gateway. They have a dedicated Inspection VPC containing AWS Network Firewall. They want to ensure that traffic between any two application VPCs is routed through the Inspection VPC. How should the Transit Gateway route tables be configured?

Answer options:

A.

Use a single TGW route table and enable appliance mode on all VPC attachments.

B.

Create two TGW route tables. Associate application VPCs with a route table that routes all traffic to the Inspection VPC. Associate the Inspection VPC with a route table that has routes to all application VPCs.

C.

Configure VPC peering between all application VPCs and the Inspection VPC.

D.

Enable AWS Shield Advanced on the Transit Gateway.

How to approach this question

Understand Transit Gateway route table isolation.

Full Answer

B.Create two TGW route tables. Associate application VPCs with a route table that routes all traffic to the Inspection VPC. Associate the Inspection VPC with a route table that has routes to all application VPCs.✓ Correct
Create two TGW route tables. Associate application VPCs with a route table that routes all traffic to the Inspection VPC. Associate the Inspection VPC with a route table that has routes to all application VPCs.
To route traffic through a central inspection VPC, you need at least two Transit Gateway route tables. One for the spoke VPCs (routing everything to the inspection VPC) and one for the inspection VPC (routing traffic to its final destination).

Common mistakes

Trying to use a single route table, which creates a loop.

Practice the full AWS Solutions Architect Professional SAP-C02 Practice Exam 7

75 questions · hints · full answers · grading

More questions from this exam