Courseiva
Network ImplementationhardMultiple ChoiceObjective-mapped

ANS-C01 Network Implementation Practice Question

An organization uses AWS Transit Gateway to connect multiple VPCs and on-premises networks via VPN. They want to implement traffic inspection between VPCs using a third-party firewall appliance in a central VPC. The firewall must inspect traffic for all inter-VPC flows. Which architecture meets this requirement?

⚠ Common exam trap

A common mix-up: candidates assume VPC peering or a Network Load Balancer can be used for transitive routing or traffic interception, but they fail to recognize that Transit Gateway with appliance mode is the only AWS-native way to force all inter-VPC traffic through a central inspection VPC while preserving stateful firewall session integrity.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Configure Transit Gateway route tables to send inter-VPC traffic to the inspection VPC's attachment, and enable appliance mode on the attachment.

Enabling appliance mode on a Transit Gateway attachment forces the Transit Gateway to preserve the source MAC address and use flow hash-based load balancing for traffic sent to the inspection VPC. This ensures that all inter-VPC traffic is routed through the third-party firewall appliance in the central VPC, allowing stateful inspection to work correctly. Without appliance mode, the Transit Gateway would perform MAC address rewriting, breaking the firewall's ability to track sessions.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Configure Transit Gateway route tables to send inter-VPC traffic to the inspection VPC's attachment, and enable appliance mode on the attachment.

    Why this is correct

    Appliance mode ensures that return traffic is sent back through the same firewall, enabling stateful inspection.

  • Create VPC peering connections between all VPCs and route traffic through the central VPC.

    Why it's wrong here

    VPC peering does not support transitive routing; each pair requires a direct connection.

  • Use a Network Load Balancer in the central VPC to distribute traffic to the firewall appliances.

    Why it's wrong here

    NLB does not perform packet inspection; it only load balances.

  • Set up Direct Connect gateways and route all traffic through the on-premises network for inspection.

    Why it's wrong here

    This adds unnecessary latency and complexity, and does not use Transit Gateway.

Quick reference

Access Control Model Comparison

ModelAcronymWho Controls Access?Best For
Discretionary Access ControlDACResource ownerSmall teams, file shares
Mandatory Access ControlMACSystem / security labelsClassified govt / military
Role-Based Access ControlRBACAdministrator (via roles)Enterprise environments
Attribute-Based Access ControlABACPolicy engine (user + resource attributes)Fine-grained, dynamic policies
Rule-Based Access ControlRuBACSystem rules / ACLsFirewall rules, network ACLs

About these practice questions

This ANS-C01 question is part of Courseiva's 1,621-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This ANS-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the ANS-C01 exam.