AWS Certified Solutions Architect Professional SAP-C02 Practice Question
A financial services company uses AWS Organizations to manage dozens of AWS accounts. They have a hybrid network architecture using AWS Transit Gateway and Direct Connect to connect their VPCs and on-premises data centers. To meet strict compliance requirements, the company must centrally inspect and filter all network traffic, including inter-VPC traffic, traffic to and from the internet, and traffic between AWS and their on-premises network. The solution must be highly available and allow the central security team to manage firewall rules consistently across the entire organization without deploying and managing third-party appliances in each VPC.
Which solution should a solutions architect recommend to meet these requirements?
Deploy AWS Network Firewall endpoints into a centralized inspection VPC. Configure Transit Gateway to route all traffic through this inspection VPC. Use AWS Firewall Manager to centrally create and apply Network Firewall policies across all accounts in the organization.
Enable Amazon GuardDuty in all accounts and configure a delegated administrator account. In the central security account, use Amazon Detective to analyze and investigate GuardDuty findings.
Configure VPC security groups and network ACLs (NACLs) in each VPC. Use AWS Config conformance packs to audit and report on security group and NACL rules across the organization.
Deploy an AWS WAF web ACL and associate it with all Application Load Balancers and CloudFront distributions. Use AWS Shield Advanced for DDoS protection.
The correct solution is to use AWS Network Firewall in a centralized inspection VPC, with AWS Transit Gateway routing traffic through it, and AWS Firewall Manager for policy administration.
AWS Network Firewall with Transit Gateway: This combination creates a centralized inspection point for all traffic flows (East-West between VPCs, and North-South to/from the internet and on-premises networks). By routing all traffic from spoke VPCs through an inspection VPC that contains Network Firewall endpoints, the company can enforce consistent security policies on all traffic passing through the Transit Gateway. This architecture is a standard AWS pattern for centralized network security.
AWS Firewall Manager: This service is designed to centrally configure and manage firewall rules across multiple accounts and resources within an AWS Organization. By using Firewall Manager, the central security team can create a single set of Network Firewall policies and apply them hierarchically and consistently across all required VPCs, meeting the central management requirement.
The other options are incorrect for the following reasons:
Using AWS WAF is incorrect because WAF is a web application firewall that operates at Layer 7 to protect against web exploits like SQL injection. It cannot inspect all network traffic types, such as non-HTTP/HTTPS protocols or general inter-VPC traffic.
Relying solely on security groups and NACLs is incorrect because these are decentralized controls managed on a per-VPC/subnet basis. This approach does not provide true deep packet inspection and creates significant operational overhead for central management at scale.
Using Amazon GuardDuty and Amazon Detective is incorrect because these are threat detection and investigation services, respectively. GuardDuty analyzes logs to identify malicious activity but does not actively filter or block network traffic based on configured rules, which is the core requirement.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is AWS Network Firewall and how does it work?
Open an interactive chat with Bash
How does AWS Transit Gateway work with AWS Network Firewall?
Open an interactive chat with Bash
What is AWS Firewall Manager and why is it essential in this architecture?
Open an interactive chat with Bash
AWS Certified Solutions Architect Professional SAP-C02
Continuous Improvement for Existing Solutions
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
IT & Cybersecurity Package Join Premium for Full Access