SAP-C02 Practice Question: Accelerate Workload Migration and Modernization
A company is migrating a stateful firewall appliance to AWS. The appliance currently inspects traffic between multiple on-premises segments. In AWS, the company wants to deploy the appliance in a VPC to inspect traffic between subnets. Which architecture should the company use to ensure that the appliance can inspect all traffic?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Deploy the appliance behind a Gateway Load Balancer in an inspection VPC and use a Transit Gateway to route traffic through it.
A Gateway Load Balancer (GWLB) can be deployed in an inspection VPC and used with a Transit Gateway to route traffic from subnets through the appliance for inspection. Option A is wrong because an Application Load Balancer cannot inspect traffic and is designed for HTTP/HTTPS. Option C is wrong because a Network Load Balancer does not inspect traffic; it forwards traffic without inspection. Option D is wrong because VPC Gateway Endpoints are used to access AWS services privately, not for traffic inspection.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Deploy the appliance behind an Application Load Balancer and configure the VPC route tables.
Why it's wrong here
An ALB operates at layer 7 and terminates connections, so it cannot transparently pass arbitrary IP traffic to a stateful firewall appliance for inspection. It is tempting because ALBs distribute HTTP/HTTPS workloads, which would suit a web-tier scenario rather than subnet-to-subnet inspection.
- ✓
Deploy the appliance behind a Gateway Load Balancer in an inspection VPC and use a Transit Gateway to route traffic through it.
Why this is correct
Gateway Load Balancer uses GENEVE encapsulation to transparently redirect traffic to third-party appliances, while Transit Gateway routes inter-subnet and inter-VPC traffic through the inspection VPC. This combination satisfies the requirement to inspect all traffic between subnets without altering routing on each workload.
- ✗
Deploy the appliance behind a Network Load Balancer and configure the VPC route tables to send traffic to the NLB.
Why it's wrong here
An NLB forwards traffic to registered targets but does not make the appliance an inline next hop; route tables pointing at an NLB endpoint are not supported for general subnet-to-subnet inspection. It is tempting because NLBs preserve source IPs for TCP/UDP load balancing.
- ✗
Use VPC Gateway Endpoints to route traffic through the appliance.
Why it's wrong here
Gateway endpoints only route traffic privately to Amazon S3 and DynamoDB, so they cannot carry general inter-subnet traffic through a firewall appliance. They are tempting because they avoid NAT and internet gateways for those specific AWS service destinations.
Visual reference
Go deeper
Related to this question
About these practice questions
Courseiva writes every SAP-C02 question from scratch — 984 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SAP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAP-C02 exam.