AWS Certified Solutions Architect Professional SAP-C02 Practice Question

A financial services company is designing a centralized egress traffic inspection architecture on AWS. The design uses an AWS Transit Gateway to connect multiple application VPCs to a central inspection VPC. The inspection VPC hosts a fleet of third-party firewall appliances deployed behind a Gateway Load Balancer (GWLB). The GWLB endpoints (GWLBE) are deployed in dedicated subnets within the inspection VPC, one per Availability Zone.

The goal is to ensure that all internet-bound traffic (0.0.0.0/0) originating from the private subnets of the application VPCs is mandatorily routed through the firewall appliances for inspection before egressing to the internet via the inspection VPC's Internet Gateway.

Which combination of route table configurations will achieve this goal?

  • Configure the application VPC route tables with a default route to the Transit Gateway. Configure the Transit Gateway route table to forward all traffic to the inspection VPC attachment. Configure the route table for the Transit Gateway attachment subnets in the inspection VPC to have a default route targeting the Gateway Load Balancer Endpoints.

  • Configure the application VPC route tables with a default route targeting the Gateway Load Balancer Endpoints in the inspection VPC. Configure the inspection VPC's Internet Gateway route table to forward traffic from the GWLBEs to the internet.

  • Configure the application VPC route tables with a default route to the Transit Gateway. Configure the Transit Gateway route table to forward all traffic directly to a NAT Gateway in the inspection VPC. Configure the route table for the NAT Gateway subnet in the inspection VPC to have a default route to the Internet Gateway.

  • Configure the application VPC route tables with a default route to the Transit Gateway. Configure the Transit Gateway route table to forward all traffic directly to the inspection VPC's Internet Gateway. Associate all subnets in the inspection VPC with a route table that has a default route to the Internet Gateway.

AWS Certified Solutions Architect Professional SAP-C02
Design for New Solutions
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot