ANS-C01 Network Security, Compliance and Governance Practice Question
A company is designing a multi-VPC architecture with AWS Transit Gateway. The security requirements include: (1) all inter-VPC traffic must be inspected by a central firewall, (2) traffic to the internet must egress through a centralized egress VPC, and (3) traffic to on-premises via Direct Connect must go through the same inspection firewall. Which THREE components are required to meet these requirements?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
AWS Network Firewall in an inspection VPC
The correct components are B, C, and E. Option B (AWS Network Firewall in an inspection VPC) provides the central firewall to inspect inter-VPC traffic. Option C (Virtual Private Gateway (VGW) attachment to the inspection VPC) enables on-premises Direct Connect traffic to be routed through the inspection VPC and firewall. Option E (AWS Transit Gateway with multiple route tables) allows segmentation of traffic and ensures that inter-VPC traffic and traffic to/from on-premises is routed through the inspection VPC. Option A (VPC peering connections between all VPCs) is not needed because Transit Gateway provides the connectivity. Option D (NAT gateways in each VPC) is not required because internet egress is centralized through an egress VPC, not through individual NAT gateways.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
VPC peering connections between all VPCs
Why it's wrong here
Transit Gateway replaces peering for transitive routing.
- ✓
AWS Network Firewall in an inspection VPC
Why this is correct
Provides centralized traffic inspection.
- ✓
Virtual Private Gateway (VGW) attachment to the inspection VPC
Why this is correct
Allows Direct Connect traffic to enter the inspection VPC for firewall inspection.
- ✗
NAT gateways in each VPC
Why it's wrong here
NAT gateways are not needed if internet egress is centralized.
- ✓
AWS Transit Gateway with multiple route tables
Why this is correct
Route tables steer traffic between VPCs and to inspection VPC.
Visual reference
Go deeper
Related to this question
About these practice questions
One of 1,621 original ANS-C01 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This ANS-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the ANS-C01 exam.