AWS Certified Advanced Networking – Specialty (ANS-C01)Network Management and OperationsMedium
A large enterprise uses AWS Organizations to manage multiple AWS accounts and has a strict policy that all internet-bound traffic from EC2 instances must be inspected by a centralized set of security appliances in a dedicated security VPC. They also need to ensure that this policy is automatically enforced across all new and existing VPCs without manual intervention. Which AWS service combination provides the most efficient and compliant solution?
- AAWS Transit Gateway with static routes and AWS Config rules
- BAWS Transit Gateway with Route Analyzer and AWS CloudFormation
- CAWS Transit Gateway with Appliance Mode and AWS Firewall Manager
- DAWS VPN with EC2 instances and AWS Systems Manager
Show answer & explanationAnswer & explanation
Correct answer: C. AWS Transit Gateway with Appliance Mode and AWS Firewall Manager
AWS Transit Gateway with Appliance Mode allows routing traffic through a specific network appliance (like a firewall) in a centralized VPC. AWS Firewall Manager can then automatically deploy and manage the necessary Transit Gateway routes and firewall rules across all accounts and VPCs within an AWS Organization, ensuring consistent and automated enforcement of the security policy.
Why the other options are wrong
- A. AWS Config rules can check compliance but don't automatically enforce the routing configuration across TGW and VPCs for centralized inspection.
- B. Route Analyzer helps troubleshoot routing, and CloudFormation can deploy infrastructure, but neither provides the automated, centralized policy enforcement for traffic inspection.
- D. AWS VPN and EC2 instances can be part of a solution, but Systems Manager doesn't provide the centralized routing and automated policy enforcement capabilities of Transit Gateway Appliance Mode and Firewall Manager for this scale and requirement.
TGW Appliance Mode & Firewall Manager
A combination of AWS services for centralized network traffic inspection and automated security policy enforcement across an AWS Organization.
- Transit Gateway Appliance Mode enables routing traffic through a security VPC.
- Firewall Manager centralizes security policy deployment across accounts.
- Ensures all internet-bound traffic is inspected consistently.
Memory trick: TGW Appliance Mode and Firewall Manager make Inspection and Enforcement Effortless!