Courseiva
Infrastructure Security →mediumMultiple Choice

SCS-C02 Infrastructure Security Practice Question

A company uses AWS Direct Connect to connect its on-premises data center to AWS. The company has a VPC with public and private subnets. The security team wants to ensure that all traffic between on-premises and the VPC goes through a set of security appliances (firewalls) deployed in the VPC. The appliances are in separate subnets. Currently, traffic is routed directly via the virtual private gateway. What is the MOST secure and scalable way to force traffic through the security appliances?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Deploy a Gateway Load Balancer and create Gateway Load Balancer endpoints in each subnet. Update the route tables to point to the endpoints.

Using a Gateway Load Balancer with Gateway Load Balancer endpoints in each subnet allows transparent traffic inspection and scaling. Option A is wrong because a NAT gateway only handles outbound traffic, not bidirectional inspection. Option B is wrong because a transit gateway does not force traffic through appliances; additional routing and appliance VPCs are needed. Option D is wrong because a VPN connection does not inherently route through VPC appliances; it would require custom routing.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Place the security appliances in a public subnet and route traffic through a NAT gateway.

    Why it's wrong here

    A NAT gateway is designed for outbound internet connectivity from private subnets; it has no mechanism to receive or forward inbound traffic from a Direct Connect virtual interface to security appliances. When an on-premises host initiates traffic into the VPC, that traffic is routed via the VPC route table, and a NAT gateway cannot be a route-table target for such inbound traffic, nor does it perform traffic inspection. Placing appliances in a public subnet and inserting a NAT gateway would simply drop the flow or send it directly to the appliance's private IP, but it cannot transparently intercept and redirect all traffic to the appliance fleet. Thus, this option fails to create a bump-in-the-wire inspection path and would leave traffic uninspected.

  • ✗

    Create a transit gateway and attach the Direct Connect virtual interface to it. Then route traffic through the appliance subnets.

    Why it's wrong here

    While a transit gateway can connect the Direct Connect virtual interface to a VPC, simply attaching it does not insert the security appliance subnets into the data path. Transit gateway route tables forward traffic based on static routes to targets such as VPC attachments or virtual interfaces; they do not support 'traffic through appliance subnets' as a native interception behavior. To force inspection you would have to manually create precise routes pointing to the elastic network interfaces of the appliances, manage asymmetric routing, and handle failover yourself — none of which is inherent. A TGW alone therefore does not provide the transparent chaining that Gateway Load Balancer endpoints offer, so this answer is incomplete and unreliable.

  • ✓

    Deploy a Gateway Load Balancer and create Gateway Load Balancer endpoints in each subnet. Update the route tables to point to the endpoints.

    Why this is correct

    A Gateway Load Balancer (GWLB) transparently intercepts traffic using Gateway Load Balancer endpoints, which are VPC endpoints that can be designated as route-table targets. After you deploy the GWLB in one VPC and the security appliances in target groups, you create endpoints in each subnet and update those subnets' route tables to point the Direct Connect prefix or default route to the endpoints. The GWLB then encapsulates traffic using the GENEVE protocol and distributes flows across the appliance fleet, enabling scaling, health checks, and automatic failover while keeping the appliances transparent to the source and destination. This is the standard pattern for inserting a horizontal fleet of third-party security appliances inline for inspection of Direct Connect traffic.

  • ✗

    Set up a VPN connection from on-premises to the VPC and route traffic through the appliance subnets.

    Why it's wrong here

    Establishing a VPN connection from on-premises to the VPC merely replaces the connectivity transport — it does nothing to place the security appliances in the traffic path. Even with a VPN, route tables must be manually configured to send traffic through the appliance subnets, and the appliances themselves must be integrated as a transparent service; otherwise traffic flows directly between the VPN endpoint and the application. Adding VPN to a Direct Connect architecture also does not resolve the original requirement, because the question specifically asks how to force on-premises traffic through appliances while continuing to use Direct Connect. This solution changes the network path without providing any mechanism for centralized inspection, so it is not a valid answer.

Visual reference

Inside (Private) PC-A 10.0.0.1 PC-B 10.0.0.2 NAT Router Outside (Public) 203.0.113.1 Inside Global Server PAT: many private IPs share one public IP via unique port numbers

About these practice questions

This SCS-C02 question is part of Courseiva's 1,205-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.