SCS-C02 exam dumps

SCS-C02 practice question 216 of 504

AWS Certified Security - Specialty. Expert level, Amazon Web Services. Free question with the correct answer and a full explanation.

SCS-C02 Question 216

Single answer

A company has multiple VPCs in a single AWS Region for development, staging, and production environments. The security team has mandated that all inter-VPC traffic must be routed through a single service to centralize monitoring and enforce security policies. Additionally, they require minimal overhead in managing route tables across the environment. Which solution best satisfies these requirements?

  1. A

    Create VPC peering connections between all VPCs and use Network ACLs to monitor traffic.

  2. B

    Use an AWS Transit Gateway to connect all VPCs and enable centralized monitoring through VPC flow logs.

  3. C

    Deploy a NAT Gateway in each VPC and route traffic between VPCs through the NAT Gateways.

  4. D

    Use VPC endpoints to connect all VPCs and enforce security policies with endpoint policies.

Show answer and explanation

Correct answer: B

Explanation

AWS Transit Gateway is the ideal solution for inter-VPC connectivity in this scenario. It provides a centralized hub for routing traffic between VPCs, simplifying management and enabling centralized monitoring through VPC flow logs. With its ability to enforce security policies, AWS Transit Gateway addresses the company's need for both centralized traffic monitoring and security policy enforcement, while reducing the complexity of managing route tables.

  • A. Incorrect.

    VPC peering connections can connect VPCs, but they create a complex mesh architecture when multiple VPCs are involved. Additionally, VPC peering does not natively support centralized monitoring or security policy enforcement, making this solution unsuitable.

  • B. Correct.

    AWS Transit Gateway provides a hub-and-spoke architecture, simplifying inter-VPC connectivity. It supports centralized monitoring through VPC flow logs and enables security policy enforcement by routing traffic through a centralized gateway. This satisfies the requirements effectively.

  • C. Incorrect.

    NAT Gateways are designed for internet-bound traffic, not inter-VPC communication. Using NAT Gateways for this purpose would lead to unnecessary costs and complexity, and they do not offer centralized monitoring or policy enforcement.

  • D. Incorrect.

    VPC endpoints are used to privately connect VPCs to supported AWS services, not for inter-VPC connectivity. Endpoint policies apply only to traffic destined for the associated AWS service, so this solution is not suitable for the stated requirements.

Timed practice exam

Take a SCS-C02 practice test under exam conditions

65 questions in 170 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam