AWS Certified Advanced Networking – Specialty (ANS-C01)Network DesignMedium
A company is migrating its critical applications to AWS and requires a network architecture that provides isolated environments for different departments (Finance, HR, Engineering) within the same AWS account. Each department needs its own IP address space, and communication between departments should be restricted by default but selectively allowed through a central firewall. Which networking construct is best suited to achieve this segmentation?
- AMultiple subnets within a single VPC with Network ACLs
- BMultiple Availability Zones within a single VPC with Security Groups
- CSeparate VPCs for each department connected via AWS Transit Gateway
- DSeparate VPCs for each department connected via VPC Peering
Show answer & explanationAnswer & explanation
Correct answer: C. Separate VPCs for each department connected via AWS Transit Gateway
Using separate VPCs for each department provides strong isolation and dedicated IP spaces. Connecting them via AWS Transit Gateway allows centralized routing and the ability to route traffic through a shared firewall VPC for inspection, meeting the requirement for restricted but selectively allowed inter-department communication.
Why the other options are wrong
- A. Subnets within a single VPC do not provide strong isolation or dedicated IP spaces for departments. Network ACLs are stateless and harder to manage for inter-department traffic.
- B. Availability Zones are for high availability within a VPC, not for departmental segmentation with distinct IP spaces and centralized firewalling.
- D. VPC Peering connects VPCs directly, making it difficult to centralize traffic inspection through a shared firewall. Each peering connection is 1:1.
Multi-VPC Segmentation with TGW
Using separate VPCs for strong departmental or environment isolation, connected and routed centrally via AWS Transit Gateway, often with a shared security VPC.
- Provides strong network isolation (departmental, environment).
- Each VPC has its own CIDR block, preventing overlaps.
- Transit Gateway acts as a central hub for inter-VPC routing.
- Enables centralized firewalling or inspection for all cross-VPC traffic.
Memory trick: VPCs are your segmented boxes, Transit Gateway's the highway, Firewall's the gatekeeper.