AWS Certified Solutions Architect Professional SAP-C02 Practice Question

A financial services company uses AWS Organizations to manage dozens of AWS accounts. They have a hybrid network architecture using AWS Transit Gateway and Direct Connect to connect their VPCs and on-premises data centers. To meet strict compliance requirements, the company must centrally inspect and filter all network traffic, including inter-VPC traffic, traffic to and from the internet, and traffic between AWS and their on-premises network. The solution must be highly available and allow the central security team to manage firewall rules consistently across the entire organization without deploying and managing third-party appliances in each VPC.

Which solution should a solutions architect recommend to meet these requirements?

  • Deploy AWS Network Firewall endpoints into a centralized inspection VPC. Configure Transit Gateway to route all traffic through this inspection VPC. Use AWS Firewall Manager to centrally create and apply Network Firewall policies across all accounts in the organization.

  • Enable Amazon GuardDuty in all accounts and configure a delegated administrator account. In the central security account, use Amazon Detective to analyze and investigate GuardDuty findings.

  • Configure VPC security groups and network ACLs (NACLs) in each VPC. Use AWS Config conformance packs to audit and report on security group and NACL rules across the organization.

  • Deploy an AWS WAF web ACL and associate it with all Application Load Balancers and CloudFront distributions. Use AWS Shield Advanced for DDoS protection.

AWS Certified Solutions Architect Professional SAP-C02
Continuous Improvement for Existing Solutions
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot