AWS Certified Advanced Networking – Specialty (ANS-C01)Network Management and OperationsHard

A financial institution requires strict network segmentation and isolation for different environments (e.g., development, staging, production) within a single AWS account. Each environment has its own set of VPCs, and direct communication between them is strictly prohibited unless explicitly allowed through a central inspection point. How can this be architected using AWS Transit Gateway to enforce strict isolation and controlled inter-VPC communication?

  1. AUse AWS PrivateLink to connect specific services between VPCs in different environments.
  2. BCreate a central inspection VPC and attach all environment VPCs to the Transit Gateway, routing all inter-VPC traffic through the inspection VPC.
  3. CAttach all VPCs to a single Transit Gateway and use Transit Gateway route tables to control traffic between them.
  4. DDeploy separate Transit Gateways for each environment (Dev, Staging, Prod) and do not peer them.
Show answer & explanation

Correct answer: B. Create a central inspection VPC and attach all environment VPCs to the Transit Gateway, routing all inter-VPC traffic through the inspection VPC.

To enforce strict isolation and controlled inter-VPC communication through a central inspection point, the best approach is to attach all environment VPCs to a single Transit Gateway, and then route all traffic destined for other environments through a dedicated inspection VPC. This allows security appliances (e.g., firewalls, IDS/IPS) in the inspection VPC to scrutinize and filter all cross-environment traffic, ensuring strict adherence to security policies before it reaches its destination.

Why the other options are wrong

  • A. PrivateLink is for consuming specific services privately, not for general inter-VPC communication and central inspection of all traffic.
  • C. While Transit Gateway route tables can control traffic, they don't inherently force traffic through a central inspection point for deep packet inspection unless specifically configured with an inspection VPC.
  • D. Deploying separate Transit Gateways for each environment achieves isolation but prevents any inter-VPC communication, even controlled, which contradicts the 'explicitly allowed through a central inspection point' requirement.

Transit Gateway Centralized Inspection

A pattern where all inter-VPC traffic is routed through a dedicated inspection VPC attached to a Transit Gateway, enabling centralized security policy enforcement.

  • Uses a dedicated 'inspection' VPC with security appliances.
  • All spoke VPCs attach to a Transit Gateway.
  • Transit Gateway route tables are configured to direct cross-VPC traffic via the inspection VPC.

Memory trick: For 'strict' inter-VPC control, 'inspect' all traffic 'centrally'.

More Network Management and Operations questions