AWS Certified Security – SpecialtyDomain 3: Infrastructure SecurityHard

A financial services company is deploying a new application on AWS that handles highly sensitive customer data. The application will run on Amazon EC2 instances within a private subnet and requires outbound internet access for patching and updates, but no inbound internet access. The security team mandates that all outbound internet traffic must be inspected by a third-party firewall appliance for deep packet inspection and intrusion prevention. How should the security architect design the network to meet these requirements securely?

  1. ADeploy the third-party firewall appliance as an EC2 instance in the application VPC's public subnet. Route all outbound traffic from the private subnet through the firewall appliance's ENI, then directly to the internet.
  2. BConfigure an Internet Gateway in the application VPC and attach it to the private subnet's route table. Deploy the third-party firewall appliance as an EC2 instance in the private subnet and configure its security group to allow outbound internet access.
  3. CConfigure a NAT Gateway in the private subnet and route all outbound traffic through it. Deploy the third-party firewall appliance as an EC2 instance in a public subnet and configure security group rules to allow necessary traffic.
  4. DDeploy a NAT Gateway in a public subnet. Create a dedicated inspection VPC with the third-party firewall appliance deployed as an EC2 instance. Use AWS Transit Gateway to route traffic from the application VPC's private subnets to the inspection VPC, through the firewall, and then to the internet via the NAT Gateway.
Show answer & explanation

Correct answer: D. Deploy a NAT Gateway in a public subnet. Create a dedicated inspection VPC with the third-party firewall appliance deployed as an EC2 instance. Use AWS Transit Gateway to route traffic from the application VPC's private subnets to the inspection VPC, through the firewall, and then to the internet via the NAT Gateway.

Option B provides a robust and scalable solution for centralized outbound internet inspection. By using a dedicated inspection VPC and AWS Transit Gateway, all outbound traffic can be forced through the third-party firewall before reaching the internet via a NAT Gateway, ensuring deep packet inspection and intrusion prevention as required.

Why the other options are wrong

  • A. Routing traffic directly from a private subnet through a firewall in a public subnet and then directly to the internet is not a standard or secure pattern for centralized inspection and doesn't leverage NAT for private subnet internet access. It also bypasses deep packet inspection for all traffic.
  • B. Attaching an Internet Gateway directly to a private subnet's route table would expose the private subnet directly to the internet, violating the requirement for no inbound internet access and bypassing any intended inspection.
  • C. This option does not route traffic through a third-party firewall for inspection before reaching the internet; the NAT Gateway provides direct internet access.

Centralized Egress Inspection with Transit Gateway

A network architecture pattern where all outbound internet traffic from multiple VPCs is routed through a central inspection VPC containing security appliances (like firewalls) before reaching the internet, typically using AWS Transit Gateway.

  • Enhances security by forcing all egress traffic through inspection devices.
  • Provides a scalable and manageable solution for multi-VPC environments.
  • Utilizes AWS Transit Gateway for inter-VPC routing and NAT Gateway for internet access.

Memory trick: Transit Gateway routes traffic through the 'Inspection Checkpoint' before it goes to the Internet.

More Domain 3: Infrastructure Security questions