Courseiva
Network Security, Compliance and GovernancehardMultiple SelectObjective-mapped

ANS-C01 Network Security, Compliance and Governance Practice Question

A company is designing a multi-VPC architecture with AWS Transit Gateway. The security requirements include: (1) all inter-VPC traffic must be inspected by a central firewall, (2) traffic to the internet must egress through a centralized egress VPC, and (3) traffic to on-premises via Direct Connect must go through the same inspection firewall. Which THREE components are required to meet these requirements?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

AWS Network Firewall in an inspection VPC

The correct components are B, C, and E. Option B (AWS Network Firewall in an inspection VPC) provides the central firewall to inspect inter-VPC traffic. Option C (Virtual Private Gateway (VGW) attachment to the inspection VPC) enables on-premises Direct Connect traffic to be routed through the inspection VPC and firewall. Option E (AWS Transit Gateway with multiple route tables) allows segmentation of traffic and ensures that inter-VPC traffic and traffic to/from on-premises is routed through the inspection VPC. Option A (VPC peering connections between all VPCs) is not needed because Transit Gateway provides the connectivity. Option D (NAT gateways in each VPC) is not required because internet egress is centralized through an egress VPC, not through individual NAT gateways.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • VPC peering connections between all VPCs

    Why it's wrong here

    Transit Gateway replaces peering for transitive routing.

  • AWS Network Firewall in an inspection VPC

    Why this is correct

    Provides centralized traffic inspection.

  • Virtual Private Gateway (VGW) attachment to the inspection VPC

    Why this is correct

    Allows Direct Connect traffic to enter the inspection VPC for firewall inspection.

  • NAT gateways in each VPC

    Why it's wrong here

    NAT gateways are not needed if internet egress is centralized.

  • AWS Transit Gateway with multiple route tables

    Why this is correct

    Route tables steer traffic between VPCs and to inspection VPC.

Visual reference

Inside (Private) PC-A 10.0.0.1 PC-B 10.0.0.2 NAT Router Outside (Public) 203.0.113.1 Inside Global Server PAT: many private IPs share one public IP via unique port numbers

About these practice questions

One of 1,621 original ANS-C01 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This ANS-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the ANS-C01 exam.