AWS Certified Solutions Architect – ProfessionalContinuously Improve Existing SolutionsMedium

A global enterprise has several applications deployed on Amazon EC2 instances within a single VPC. The security team has identified a critical requirement to implement granular, stateful traffic inspection and filtering for all ingress and egress traffic across all VPC subnets, including traffic between subnets. The solution must be centrally managed and easily scalable without deploying and managing individual firewalls on each EC2 instance. Which AWS service should the Solutions Architect recommend?

  1. AAWS WAF (Web Application Firewall) deployed in front of the EC2 instances.
  2. BNetwork Access Control Lists (NACLs) configured at the subnet level.
  3. CAWS Network Firewall deployed at the VPC boundary.
  4. DSecurity Groups configured for each EC2 instance.
Show answer & explanation

Correct answer: C. AWS Network Firewall deployed at the VPC boundary.

AWS Network Firewall provides highly granular, stateful network traffic inspection and filtering for all traffic entering or leaving your VPCs, including traffic between subnets. It's a fully managed service, centrally deployable, and scalable, eliminating the need for per-instance firewall management.

Why the other options are wrong

  • A. AWS WAF operates at the application layer (Layer 7) and protects against common web exploits. It is not designed for granular, stateful inspection of all network traffic (Layers 3-4) across VPC subnets.
  • B. NACLs are stateless and operate at the subnet level, offering basic packet filtering. They do not provide granular, stateful inspection or centralized management across all traffic types as required.
  • D. Security Groups are stateful and operate at the instance level, controlling traffic to/from an instance. While essential, they are not centrally managed for all VPC traffic and do not provide the deep, centralized inspection capabilities required for an enterprise-wide solution.

AWS Network Firewall

AWS Network Firewall is a managed service that makes it easier to deploy essential network protections for all of your Amazon VPCs. It provides granular traffic inspection and filtering rules.

  • Stateful inspection for ingress, egress, and intra-VPC traffic.
  • Centrally managed and highly scalable.
  • Supports intrusion prevention systems (IPS) and URL filtering.

Memory trick: Network Firewall Narrows Network Noise.

More Continuously Improve Existing Solutions questions