AWS Certified Advanced Networking – Specialty (ANS-C01)Network Security, Compliance, and GovernanceHard

A financial services company operates a critical online banking application on AWS. They need to ensure that all network traffic between their Amazon EC2 instances within a VPC is inspected for malicious content and potential data exfiltration without introducing significant latency. The solution must be scalable and centrally managed. Which AWS service combination is MOST suitable for this requirement?

  1. AAWS Network Firewall with a Transit Gateway and VPC routing.
  2. BSecurity Groups and Network ACLs applied to EC2 instances and subnets.
  3. CAWS WAF in front of a Network Load Balancer (NLB) with EC2 instances.
  4. DAmazon GuardDuty for threat detection and AWS Shield for DDoS protection.
Show answer & explanation

Correct answer: A. AWS Network Firewall with a Transit Gateway and VPC routing.

AWS Network Firewall, combined with a Transit Gateway and proper VPC routing, allows for centralized, scalable inspection of all inter-VPC and intra-VPC traffic. This setup enables deep packet inspection for malicious content and data exfiltration prevention, meeting the requirements for security and scalability with minimal latency impact when correctly configured.

Why the other options are wrong

  • B. Security Groups and Network ACLs provide stateless/stateful packet filtering at Layer 3/4, but they don't offer deep packet inspection or advanced threat prevention capabilities like a firewall service.
  • C. AWS WAF operates at the application layer (Layer 7) and protects web applications, not general network traffic between EC2 instances. NLB is Layer 4.
  • D. GuardDuty is a threat detection service, and Shield protects against DDoS attacks. Neither performs inline network inspection or data exfiltration prevention for internal VPC traffic.

Centralized Network Inspection with AWS Network Firewall

This architecture uses AWS Network Firewall in an inspection VPC, routing all relevant traffic (e.g., inter-VPC, egress) through it via AWS Transit Gateway for deep packet inspection and threat prevention.

  • Provides stateful firewall, IPS, and domain filtering.
  • Scalable and highly available.
  • Integrates with Transit Gateway for centralized traffic routing.

Memory trick: Transit Gateway Routes, Network Firewall Scans, All VPC Traffic's Clean.

More Network Security, Compliance, and Governance questions