A large medical research institution uses AWS to host sensitive patient data and genomic analysis applications. Due to strict compliance requirements (e.g., HIPAA), all network traffic, including traffic between EC2 instances within the same VPC and between VPCs, must be inspected by a centralized set of security appliances (e.g., firewalls, IDS/IPS). The institution uses AWS Transit Gateway for inter-VPC connectivity. Which architectural pattern, supported by AWS Transit Gateway, should be implemented to ensure all traffic passes through the centralized inspection VPC?
- ADecentralized architecture with Security Groups on each EC2 instance.
- BDirect Connect Gateway with centralized on-premises firewalls.
- CMesh architecture with direct VPC peering.
- DHub-and-spoke architecture with a centralized inspection VPC.
Show answer & explanationAnswer & explanation
Correct answer: D. Hub-and-spoke architecture with a centralized inspection VPC.
A hub-and-spoke architecture with AWS Transit Gateway, where the 'hub' is a centralized inspection VPC, is the recommended pattern for enforcing security appliance inspection. All 'spoke' VPCs are attached to the Transit Gateway, and routing rules on the Transit Gateway ensure that all traffic between spoke VPCs, or between spokes and external networks, is first routed through the inspection VPC where the security appliances reside.
Why the other options are wrong
- A. Security Groups provide instance-level firewalling but don't centralize inspection or provide a mechanism to force all traffic through a dedicated set of appliances.
- B. Direct Connect Gateway connects on-premises networks to AWS; it does not solve the problem of centralized *intra-AWS* traffic inspection between VPCs.
- C. Mesh architecture with VPC peering does not inherently support centralized inspection without complex and unmanageable routing for every pair of VPCs.
TGW Centralized Inspection
An architectural pattern using AWS Transit Gateway in a hub-and-spoke topology, where a central 'inspection VPC' hosts security appliances to inspect all inter-VPC and egress traffic.
- Uses Transit Gateway for routing.
- Enforces traffic through a dedicated inspection VPC.
- Essential for compliance and advanced security enforcement.
Memory trick: The hub inspects all spokes to keep the network safe.