AWS Certified Advanced Networking – Specialty (ANS-C01)Network Security, Compliance, and GovernanceHard

A large enterprise needs to establish secure and private communication between hundreds of VPCs across multiple AWS Regions and their on-premises data centers, ensuring all traffic is routed through a central network appliance (e.g., a firewall virtual appliance) for inspection. The solution must be highly scalable and simplify network management. Which combination of AWS services would best meet these complex networking and security requirements?

  1. AVPC peering connections with individual Site-to-Site VPNs to on-premises.
  2. BAWS VPN CloudHub and AWS Direct Connect for each VPC.
  3. CAWS Transit Gateway with VPC attachments, Direct Connect Gateway, and a central inspection VPC.
  4. DAmazon Virtual Private Cloud (VPC) with multiple Internet Gateways and Network ACLs.
Show answer & explanation

Correct answer: C. AWS Transit Gateway with VPC attachments, Direct Connect Gateway, and a central inspection VPC.

AWS Transit Gateway provides a central hub for connecting thousands of VPCs and on-premises networks across regions. By attaching all VPCs to a Transit Gateway and routing all traffic through a central inspection VPC (where the firewall appliance is deployed), and connecting on-premises via Direct Connect Gateway attached to the TGW, this solution offers high scalability, centralized routing, and enforced traffic inspection.

Why the other options are wrong

  • A. VPC peering connections do not scale well for hundreds of VPCs and do not centralize traffic inspection through a single appliance or simplify cross-region/on-premises connectivity.
  • B. VPN CloudHub is less scalable than TGW for this scenario and doesn't inherently support centralized inspection VPC routing or Direct Connect integration for multiple VPCs as efficiently as TGW.
  • D. Multiple Internet Gateways and Network ACLs are basic VPC components and do not provide the centralized routing, scalability, or traffic inspection capabilities required for a complex multi-VPC, multi-region, hybrid cloud environment.

Centralized Inspection VPC with TGW & DX Gateway

A network architecture using AWS Transit Gateway to connect multiple VPCs and on-premises networks, routing all traffic through a dedicated inspection VPC for centralized security services like firewall appliances.

  • AWS Transit Gateway acts as a central hub for VPC and hybrid connectivity.
  • Direct Connect Gateway integrates on-premises networks with TGW across regions.
  • A dedicated inspection VPC hosts shared security appliances (e.g., Network Firewall).
  • All inter-VPC and hybrid traffic can be forced through the inspection VPC for scrutiny.
  • Simplifies network management and ensures consistent security policy enforcement.

Memory trick: Transit Gateway routes all traffic through the inspection VPC.

More Network Security, Compliance, and Governance questions