AWS Certified Solutions Architect Professional SAP-C02 Practice Question

A financial services company is modernizing a monolithic on-premises application by refactoring it into containerized microservices to be deployed on Amazon ECS. A key security requirement is that all east-west traffic (service-to-service communication) between the microservices must be routed through a fleet of third-party network security appliances for deep packet inspection. The company wants to use AWS Fargate to minimize infrastructure management overhead. Which architectural challenge must a solutions architect address to meet these requirements when using the Fargate launch type?

  • The use of an Application Load Balancer (ALB) for Fargate services encrypts all east-west traffic, which prevents network security appliances from performing deep packet inspection.

  • Fargate tasks use the awsvpc network mode, giving each task a dedicated ENI within a subnet, which complicates routing intra-VPC traffic to a centralized inspection appliance.

  • Fargate does not support the host network mode, which is required to bind the security appliances directly to the same underlying instance as the application containers.

  • AWS Fargate tasks cannot be assigned security groups, which prevents the implementation of the network traffic filtering rules required by the security appliances.

AWS Certified Solutions Architect Professional SAP-C02
Accelerate Workload Migration and Modernization
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot