AWS Certified DevOps Engineer – ProfessionalSecurity and ComplianceHard

A DevOps team is developing a new application that will process highly sensitive customer data. The application will run on Amazon EC2 instances within a private subnet. The security team mandates that all outgoing internet traffic from these instances must be inspected and filtered by a third-party firewall appliance running in an inspection VPC before reaching the public internet to ensure compliance with data exfiltration policies. How can this network architecture be implemented MOST effectively?

  1. ADeploy the firewall appliance within the application VPC's private subnet and configure a default route to it.
  2. BSet up a Transit Gateway to connect the application VPC to the inspection VPC, routing internet-bound traffic through the firewall appliance.
  3. CUse a VPC Endpoint for S3 and other AWS services to prevent direct internet access, and manually configure proxy settings on EC2 instances for other internet traffic.
  4. DConfigure a NAT Gateway in the private subnet and route all traffic through it to the internet.
Show answer & explanation

Correct answer: B. Set up a Transit Gateway to connect the application VPC to the inspection VPC, routing internet-bound traffic through the firewall appliance.

Using a Transit Gateway to connect the application VPC to an inspection VPC (where the firewall appliance resides) allows for centralized routing and inspection of all internet-bound traffic, fulfilling the requirement for mandatory third-party firewall inspection before reaching the public internet.

Why the other options are wrong

  • A. Deploying the firewall within the application VPC doesn't allow for a centralized inspection model across multiple VPCs or enforce inspection for all outbound traffic if multiple subnets or routes exist.
  • C. VPC Endpoints secure access to AWS services, but don't address general internet outbound traffic inspection by a third-party firewall.
  • D. A NAT Gateway allows outbound internet access but does not provide a mechanism to route traffic through a third-party firewall in a separate inspection VPC.

Centralized Egress Inspection with TGW

A Transit Gateway (TGW) facilitates centralized egress traffic inspection by routing all internet-bound traffic from spoke VPCs through an inspection VPC containing a firewall appliance, before reaching the Internet Gateway.

  • TGW simplifies inter-VPC routing at scale.
  • Enables hub-and-spoke network topology.
  • Allows for mandatory traffic inspection before internet access.

Memory trick: All 'traffic' must 'pass' through the 'transit' 'inspection' 'gate'.

More Security and Compliance questions