Courseiva
Network DesignhardMultiple ChoiceObjective-mapped

ANS-C01 Network Design Practice Question

A company has a VPC with multiple subnets. The security team requires that all outbound traffic from the VPC to the internet must traverse a centralized inspection appliance for traffic inspection. Which architecture should be used?

⚠ Common exam trap

AWS often tests the misconception that VPC Peering or NAT Gateway can provide centralized inspection, but they lack the transitive routing and traffic forwarding capabilities required for a hub-and-spoke inspection model.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Use Transit Gateway with VPC attached and route traffic through a shared services VPC containing the inspection appliance

A Transit Gateway with a shared services VPC architecture allows centralized inspection of all outbound internet traffic. By attaching the VPCs to a Transit Gateway and routing traffic through a shared services VPC that hosts the inspection appliance (e.g., a firewall or proxy), you can enforce security policies. The Transit Gateway acts as a hub, enabling transitive routing between VPCs while directing internet-bound traffic to the inspection appliance before it reaches an internet gateway or NAT gateway.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Use VPC Peering between all VPCs

    Why it's wrong here

    VPC Peering does not support centralized inspection.

  • Configure a NAT Gateway in each Availability Zone

    Why it's wrong here

    NAT Gateway only translates IPs, does not inspect traffic.

  • Use Transit Gateway with VPC attached and route traffic through a shared services VPC containing the inspection appliance

    Why this is correct

    Transit Gateway enables routing traffic through an inspection VPC.

  • Use AWS Direct Connect to route traffic on-premises

    Why it's wrong here

    Direct Connect is not for internet-bound traffic.

Visual reference

Inside (Private) PC-A 10.0.0.1 PC-B 10.0.0.2 NAT Router Outside (Public) 203.0.113.1 Inside Global Server PAT: many private IPs share one public IP via unique port numbers

About these practice questions

One of 1,621 original ANS-C01 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on ANS-C01

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. A company has a VPC with multiple subnets. The security team requires that all outbound traffic from the VPC to the internet goes through a centralized firewall. Which design should be used?

hard
  • A.Route all internet traffic through a centralized inspection VPC using Transit Gateway.
  • B.Attach an Internet Gateway to each VPC.
  • C.Use AWS Site-to-Site VPN to a third-party firewall.
  • D.Use VPC Endpoints for all services.

Why A: It uses a Transit Gateway to route all outbound internet traffic from the VPC to a centralized inspection VPC, where a firewall (e.g., AWS Network Firewall or a third-party appliance) inspects and forwards traffic to an Internet Gateway. This design meets the security requirement by enforcing a single egress point, ensuring all traffic is inspected before reaching the internet.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This ANS-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the ANS-C01 exam.