ANS-C01 Transit Gateway Route Table Practice Question
A company uses AWS Transit Gateway to connect multiple VPCs and on-premises networks. The security team wants to ensure that traffic between VPCs is inspected by a centralized security appliance running in a security VPC. Which configuration should be used?
⚠ Common exam trap
Option B incorrectly uses 'blackhole route' which drops traffic; the intended configuration is to route traffic to the security VPC attachment, not use a blackhole.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Attach the VPCs to the Transit Gateway and configure route tables to send inter-VPC traffic to the security VPC via a route pointing to the security VPC's attachment.
AWS Transit Gateway enables centralized traffic inspection by attaching VPCs and configuring route tables to route inter-VPC traffic to the security VPC's attachment. Note that the route must point to the security VPC attachment, not a blackhole route (which drops traffic). Option A is incorrect because network ACLs control traffic at the subnet level and cannot route traffic to another VPC. Option C is incorrect because VPC peering does not provide a centralized inspection point without complex routing. Option D is incorrect because NAT gateways are for outbound internet traffic, not inter-VPC inspection.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Configure network ACLs in each VPC to deny traffic directly between VPCs.
Why it's wrong here
Does not enable inspection, just blocks.
- ✓
Attach the VPCs to the Transit Gateway and configure route tables to send inter-VPC traffic to the security VPC via a route pointing to the security VPC's attachment.
Why this is correct
Forces traffic through the security VPC for inspection.
- ✗
Create VPC peering connections between each VPC and the security VPC, then update route tables.
Why it's wrong here
Does not scale and requires transitive routing.
- ✗
Use NAT gateways in each VPC to route traffic through the security VPC.
Why it's wrong here
NAT gateways are for internet traffic, not inter-VPC.
Visual reference
Go deeper
Related to this question
About these practice questions
This ANS-C01 question is part of Courseiva's 1,621-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This ANS-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the ANS-C01 exam.