ANS-C01 Network Implementation Practice Question
An organization uses AWS Transit Gateway to connect multiple VPCs and on-premises networks via VPN. They want to implement traffic inspection between VPCs using a third-party firewall appliance in a central VPC. The firewall must inspect traffic for all inter-VPC flows. Which architecture meets this requirement?
⚠ Common exam trap
A common mix-up: candidates assume VPC peering or a Network Load Balancer can be used for transitive routing or traffic interception, but they fail to recognize that Transit Gateway with appliance mode is the only AWS-native way to force all inter-VPC traffic through a central inspection VPC while preserving stateful firewall session integrity.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Configure Transit Gateway route tables to send inter-VPC traffic to the inspection VPC's attachment, and enable appliance mode on the attachment.
Enabling appliance mode on a Transit Gateway attachment forces the Transit Gateway to preserve the source MAC address and use flow hash-based load balancing for traffic sent to the inspection VPC. This ensures that all inter-VPC traffic is routed through the third-party firewall appliance in the central VPC, allowing stateful inspection to work correctly. Without appliance mode, the Transit Gateway would perform MAC address rewriting, breaking the firewall's ability to track sessions.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Configure Transit Gateway route tables to send inter-VPC traffic to the inspection VPC's attachment, and enable appliance mode on the attachment.
Why this is correct
Appliance mode ensures that return traffic is sent back through the same firewall, enabling stateful inspection.
- ✗
Create VPC peering connections between all VPCs and route traffic through the central VPC.
Why it's wrong here
VPC peering does not support transitive routing; each pair requires a direct connection.
- ✗
Use a Network Load Balancer in the central VPC to distribute traffic to the firewall appliances.
Why it's wrong here
NLB does not perform packet inspection; it only load balances.
- ✗
Set up Direct Connect gateways and route all traffic through the on-premises network for inspection.
Why it's wrong here
This adds unnecessary latency and complexity, and does not use Transit Gateway.
Quick reference
Access Control Model Comparison
| Model | Acronym | Who Controls Access? | Best For |
|---|---|---|---|
| Discretionary Access Control | DAC | Resource owner | Small teams, file shares |
| Mandatory Access Control | MAC | System / security labels | Classified govt / military |
| Role-Based Access Control | RBAC | Administrator (via roles) | Enterprise environments |
| Attribute-Based Access Control | ABAC | Policy engine (user + resource attributes) | Fine-grained, dynamic policies |
| Rule-Based Access Control | RuBAC | System rules / ACLs | Firewall rules, network ACLs |
Go deeper
Related to this question
About these practice questions
This ANS-C01 question is part of Courseiva's 1,621-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This ANS-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the ANS-C01 exam.