AWS Certified Advanced Networking – Specialty (ANS-C01)Network Security, Compliance, and GovernanceHard

An enterprise requires all network traffic leaving their AWS VPCs to pass through a centralized inspection VPC before reaching the internet. This includes traffic from multiple spoke VPCs in different accounts. The solution must provide deep packet inspection and intrusion prevention capabilities. Which networking and security constructs are essential to implement this architecture efficiently and securely?

  1. AAWS PrivateLink, AWS Global Accelerator, and Amazon GuardDuty
  2. BVPC Peering, NAT Gateways, and Security Groups
  3. CDirect Connect Gateway, Route 53 Resolver Endpoints, and AWS WAF
  4. DAWS Transit Gateway, Centralized Egress VPC, and AWS Network Firewall
Show answer & explanation

Correct answer: D. AWS Transit Gateway, Centralized Egress VPC, and AWS Network Firewall

This scenario describes a centralized egress architecture. AWS Transit Gateway is crucial for connecting multiple spoke VPCs to a central inspection VPC. The Centralized Egress VPC acts as the hub for all outbound traffic. AWS Network Firewall, deployed within this inspection VPC, provides the required deep packet inspection and intrusion prevention capabilities for all traffic passing through it.

Why the other options are wrong

  • A. PrivateLink is for private service access. Global Accelerator improves performance. GuardDuty is for threat detection, not inline prevention or traffic routing.
  • B. VPC Peering is for point-to-point connections, not scalable for many VPCs. NAT Gateways provide outbound internet access but not deep inspection. Security Groups are host-level firewalls.
  • C. Direct Connect Gateway is for hybrid connectivity. Route 53 Resolver Endpoints are for DNS. AWS WAF protects web applications, not general egress traffic.

Centralized Egress with Transit Gateway

An AWS network architecture pattern where all outbound internet traffic from multiple VPCs is routed through a single, dedicated inspection VPC using AWS Transit Gateway.

  • Uses AWS Transit Gateway for scalable VPC connectivity.
  • A dedicated 'Egress VPC' houses security appliances.
  • AWS Network Firewall often deployed in the Egress VPC for inspection.

Memory trick: TRANSIT to the central 'EGRESS' for FIREWALL 'INSPECTION'.

More Network Security, Compliance, and Governance questions