ANS-C01 exam dumps

ANS-C01 practice question 213 of 513

AWS Certified Advanced Networking - Specialty. Expert level, Amazon Web Services. Free question with the correct answer and a full explanation.

ANS-C01 Question 213

Select 3

A company is deploying a third-party firewall appliance on AWS for inspecting and filtering outbound traffic from their VPC. The company wants to ensure that all outbound traffic from the VPC is inspected by the firewall appliance before reaching the internet. How can the company architect this solution while adhering to security best practices?

  1. A

    Deploy the firewall appliance in a dedicated subnet and configure route tables to send traffic from other subnets to the firewall appliance.

  2. B

    Enable VPC Flow Logs to send logs to the firewall appliance for inspection before traffic is forwarded to the internet gateway.

  3. C

    Place the firewall appliance behind an Application Load Balancer and update the route table to forward traffic through the load balancer.

  4. D

    Create a Transit Gateway and configure the firewall appliance to inspect traffic between VPCs and the internet.

  5. E

    Use a NAT Gateway in conjunction with the firewall appliance to ensure only inspected traffic reaches the internet.

Show answer and explanation

Correct answers: A, D, E

Explanation

To ensure all outbound traffic from a VPC is inspected by a firewall appliance, the appliance must be placed in the data path of the outbound traffic. This is typically achieved by deploying the appliance in a dedicated subnet and updating route tables to forward traffic to the appliance. Additionally, Transit Gateways and NAT Gateways can be used in conjunction with firewall appliances to centralize and enforce inspection policies for outbound traffic.

  • A. Correct.

    This is correct. Deploying the firewall appliance in a dedicated subnet allows you to centralize inspection and control traffic routing using route tables.

  • B. Incorrect.

    This is incorrect. VPC Flow Logs are used for monitoring and logging network traffic but cannot actively inspect or filter traffic.

  • C. Incorrect.

    This is incorrect. Application Load Balancers are not designed to handle network-level traffic inspection and routing for this use case.

  • D. Correct.

    This is correct. A Transit Gateway can facilitate centralized traffic inspection when used with a firewall appliance, allowing traffic between VPCs and the internet to be inspected.

  • E. Correct.

    This is correct. A NAT Gateway can be used to route outbound traffic through the firewall appliance before allowing it to reach the internet.

Timed practice exam

Take a ANS-C01 practice test under exam conditions

65 questions in 170 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam