For IndividualsFor Educators
ExpertMinds LogoExpertMinds
ExpertMinds

Ace your certifications with Practice Exams and AI assistance.

  • Browse Exams
  • For Educators
  • Blog
  • Privacy Policy
  • Terms of Service
  • Cookie Policy
  • Support
  • AWS SAA Exam Prep
  • PMI PMP Exam Prep
  • CPA Exam Prep
  • GCP PCA Exam Prep

© 2026 TinyHive Labs. Company number 16262776.

    PracticeAWS Solutions Architect Professional (SAP-C02)AWS Solutions Architect Professional SAP-C02 Practice Exam 7Question 72
    Medium1 markMultiple Choice
    Domain 1.2: Security ControlsSecurityNetworkingNetwork Firewall

    AWS SAP-C02 · Question 72 · Domain 1.2: Security Controls

    A company is designing a secure network architecture. They have a VPC with public and private subnets. EC2 instances in the private subnets need to download patches from the internet. The security team requires that all outbound traffic be inspected for malware and that access to specific domains can be blocked. Which combination of services should be used? (Select TWO)

    Answer options:

    A.

    Deploy a NAT Gateway in the public subnet.

    B.

    Deploy an Internet Gateway in the private subnet.

    C.

    Deploy AWS Network Firewall and route traffic from the private subnets through it.

    D.

    Use AWS WAF to inspect the outbound traffic.

    E.

    Configure Security Groups to block specific domains.

    F.

    Use Amazon GuardDuty to block the traffic.

    How to approach this question

    Combine internet access with outbound inspection.

    Full Answer

    Deploy a NAT Gateway in the public subnet., Deploy AWS Network Firewall and route traffic from the private subnets through it.
    To provide internet access to private subnets, a NAT Gateway is required. To inspect that outbound traffic for malware and block domains, AWS Network Firewall must be deployed in the routing path.

    Common mistakes

    Thinking WAF can inspect outbound traffic.
    Question 71All questionsQuestion 73

    Practice the full AWS Solutions Architect Professional SAP-C02 Practice Exam 7

    75 questions · hints · full answers · grading

    Sign up freeTake the exam

    More questions from this exam

    Q01A global enterprise is designing a multi-region network architecture connecting 50 AWS accounts a...HardQ02A company is migrating its hybrid network to AWS. They have two 10 Gbps AWS Direct Connect connec...HardQ03An enterprise has 100 AWS accounts in AWS Organizations. The security team mandates that all Amaz...MediumQ04A financial company requires that all EBS volumes, S3 buckets, and RDS databases be encrypted usi...EasyQ05An enterprise is designing a disaster recovery strategy for a critical application running on Ama...Hard
    View all 75 questions →