SCS-C02 Infrastructure Security Practice Question
A company is using AWS Transit Gateway to connect multiple VPCs and on-premises networks via VPN. The security team wants to inspect all traffic between VPCs before it reaches its destination. Which architecture should be used?
⚠ Common exam trap
Watch out — candidates often confuse VPC Peering (Option D) as a valid inspection method, but it lacks a central inspection point and cannot enforce traffic inspection between VPCs without complex, non-scalable configurations.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use a Transit Gateway with a central inspection VPC that hosts security appliances and route all inter-VPC traffic through it.
AWS Transit Gateway can route inter-VPC traffic through a central inspection VPC that hosts security appliances (e.g., firewalls, IDS/IPS). By attaching the Transit Gateway to the inspection VPC and configuring route tables to force all traffic between VPCs to pass through the inspection VPC, the security team can inspect all traffic before it reaches its destination. This architecture provides centralized, scalable traffic inspection without requiring traffic to leave the AWS network.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Use a VPN CloudHub to connect VPCs and inspect traffic at the VPN endpoint.
Why it's wrong here
VPN CloudHub is a hub-and-spoke model that connects multiple remote customer networks through a single AWS virtual private gateway. It is not designed to connect VPCs within the same AWS region, nor does it introduce any packet inspection capability at the VPN endpoint; it only provides IPsec connectivity. Even if remote networks use it, it doesn't centralize inspection of VPC-to-VPC traffic, making it unsuitable.
- ✗
Use AWS Direct Connect to connect VPCs and inspect traffic on-premises.
Why it's wrong here
AWS Direct Connect creates a private, dedicated physical link between your data center and AWS, lowering bandwidth costs and providing consistent latency, but it does not interconnect VPCs or provide stateful inspection. For inter-VPC traffic, traffic would have to leave AWS entirely through the Direct Connect link to be inspected, which is impractical, high-latency, and incurs data transfer costs; it also doesn't solve the requirement of routing inter-VPC traffic through a central inspection point.
- ✓
Use a Transit Gateway with a central inspection VPC that hosts security appliances and route all inter-VPC traffic through it.
Why this is correct
AWS Transit Gateway acts as a hub to connect multiple VPCs and on-premises networks, enabling you to implement a hub-and-spoke routing architecture without VPC peering complexities. By attaching a dedicated inspection VPC to the Transit Gateway and configuring route tables so that all inter-VPC traffic is sent to that inspection VPC as a next hop, security appliances (e.g., Palo Alto, Fortinet) can inspect and filter all traffic. This provides centralized visibility and control over east-west traffic while avoiding the scaling limits and meshed connections of VPC peering.
- ✗
Use VPC Peering and configure security groups on each VPC to allow only necessary traffic.
Why it's wrong here
VPC peering creates a direct, one-to-one network connection between exactly two VPCs and does not support transitive routing, so every VPC pair would need its own peering connection. While security groups and network ACLs provide some filtering, they act only at the VPC boundaries and cannot redirect traffic to a central inspection appliance because peered traffic flows directly between the two VPCs. This makes it operationally complex and deficient for the requirement of centralized inspection of all inter-VPC traffic.
Go deeper
Related to this question
About these practice questions
This SCS-C02 question is part of Courseiva's 1,205-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.