AWS Certified Advanced Networking – Specialty (ANS-C01)Network Security, Compliance, and GovernanceHard

A cybersecurity firm is deploying a network intrusion detection/prevention system (IDPS) in their AWS environment. They need to inspect all ingress and egress traffic for multiple VPCs in a centralized manner for deep packet inspection and threat analysis. The solution must be highly available, scalable, and minimize operational overhead. Which architectural pattern and AWS service facilitate this requirement?

  1. ADeploy an EC2-based IDPS appliance in each VPC and manage it individually.
  2. BUse a centralized inspection VPC with AWS Transit Gateway and AWS Network Firewall.
  3. CConfigure VPC Flow Logs to send data to Amazon Kinesis and then process with AWS Lambda.
  4. DImplement AWS WAF on all public-facing load balancers and CloudFront distributions.
Show answer & explanation

Correct answer: B. Use a centralized inspection VPC with AWS Transit Gateway and AWS Network Firewall.

A centralized inspection VPC with AWS Transit Gateway allows routing all ingress and egress traffic from spoke VPCs through a dedicated inspection VPC. AWS Network Firewall, being a managed, scalable, and highly available service, can then perform deep packet inspection and threat analysis within this inspection VPC, minimizing operational overhead compared to self-managing EC2-based appliances.

Why the other options are wrong

  • A. Deploying and managing individual EC2-based IDPS appliances in each VPC is operationally intensive and does not provide centralized inspection or minimize overhead.
  • C. VPC Flow Logs provide metadata about traffic but do not perform deep packet inspection or active intrusion prevention; processing with Kinesis/Lambda is for analysis, not inline inspection.
  • D. AWS WAF protects web applications (Layer 7) from common exploits, but it does not provide deep packet inspection for all network traffic (Layers 3-4) or intrusion detection/prevention for the entire VPC environment.

Centralized Inspection VPC with Transit Gateway & Network Firewall

An architectural pattern where all network traffic (ingress/egress) from multiple VPCs is routed through a central inspection VPC for deep packet inspection and threat analysis using AWS Network Firewall, managed by AWS Transit Gateway.

  • Transit Gateway routes traffic to/from inspection VPC.
  • AWS Network Firewall performs stateful deep packet inspection, IDS/IPS.
  • Centralized security for multiple spoke VPCs.
  • Highly available, scalable, managed service.
  • Minimizes operational overhead compared to self-managed appliances.

Memory trick: Transit Gateway 'routes all cars' to the Network Firewall 'inspection station' for security.

More Network Security, Compliance, and Governance questions