AWS Certified Solutions Architect Professional SAP-C02 Practice Question

A financial services company utilizes a multi-account AWS environment with a hub-and-spoke network architecture centered around an AWS Transit Gateway. The security team is mandated to perform deep packet inspection (DPI) on all east-west traffic between spoke VPCs. The inspection must be conducted by a fleet of third-party intrusion detection system (IDS) appliances deployed on EC2 instances within a dedicated 'inspection' VPC. The solution must be highly scalable, have minimal performance impact on application workloads, and centralize the inspection tooling. Which approach should a solutions architect recommend to meet these requirements?

  • Deploy AWS Network Firewall in the inspection VPC. Configure the Transit Gateway to route all inter-VPC traffic through the Network Firewall endpoints for inspection.

  • Configure VPC Flow Logs for all traffic in the spoke VPCs. Stream the logs to a central Amazon S3 bucket and use Amazon Athena for analysis.

  • In the inspection VPC, configure a Gateway Load Balancer (GWLB) with the IDS appliance fleet as a target group. Create GWLB Endpoints in each spoke VPC and modify route tables to direct all traffic through the GWLB.

  • Configure VPC Traffic Mirroring on the source Elastic Network Interfaces (ENIs) in the spoke VPCs. Set the mirror target to a Network Load Balancer (NLB) in the inspection VPC that fronts the IDS appliance fleet.

AWS Certified Solutions Architect Professional SAP-C02
Design Solutions for Organizational Complexity
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot