ANS-C01 exam dumps

ANS-C01 practice question 211 of 513

AWS Certified Advanced Networking - Specialty. Expert level, Amazon Web Services. Free question with the correct answer and a full explanation.

ANS-C01 Question 211

Select 2

You are designing a highly available and secure network architecture for an application hosted in Amazon VPC. The application requires a third-party firewall appliance for deep packet inspection. The solution must ensure redundancy and minimize downtime during maintenance or failure of the appliance. How should you architect the solution?

  1. A

    Deploy the firewall appliance in a single Availability Zone and associate it with a single Elastic Network Interface (ENI).

  2. B

    Deploy the firewall appliance in multiple Availability Zones using Auto Scaling groups and configure route tables to send traffic through the appliances.

  3. C

    Use AWS Gateway Load Balancer to distribute traffic across multiple firewall appliances deployed in different Availability Zones.

  4. D

    Route traffic through a Network Load Balancer and configure the Target Groups to include the IP addresses of the firewall appliances.

  5. E

    Deploy the firewall appliance in a single Availability Zone and use AWS Elastic Load Balancer to handle failover.

Show answer and explanation

Correct answers: B, C

Explanation

To ensure high availability and secure traffic inspection, the solution must use multiple firewall appliances deployed across different Availability Zones. AWS Gateway Load Balancer is specifically designed to distribute traffic to third-party appliances like firewalls, ensuring redundancy and failover. Alternatively, leveraging Auto Scaling groups with route table modifications allows traffic to flow through multiple appliances across Availability Zones, meeting the application's requirements.

  • A. Incorrect.

    Deploying the firewall appliance in a single Availability Zone and associating it with a single ENI introduces a single point of failure and does not meet the high availability requirement.

  • B. Correct.

    Deploying the firewall appliances in multiple Availability Zones using Auto Scaling groups ensures redundancy and high availability. Configuring route tables to send traffic through the appliances provides proper traffic flow for inspection.

  • C. Correct.

    AWS Gateway Load Balancer is purpose-built to handle traffic distribution for third-party appliances, including firewalls. Deploying appliances in different Availability Zones ensures redundancy and minimizes downtime during failures.

  • D. Incorrect.

    Routing traffic through a Network Load Balancer does not natively provide the deep integration required for third-party firewall appliances, and it lacks the purpose-built capabilities of AWS Gateway Load Balancer.

  • E. Incorrect.

    Deploying the appliance in a single Availability Zone and relying on AWS Elastic Load Balancer does not provide true high availability, as the appliance itself remains a single point of failure.

Timed practice exam

Take a ANS-C01 practice test under exam conditions

65 questions in 170 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam