Courseiva
Infrastructure Security →mediumMultiple Choice

SCS-C02 Infrastructure Security Practice Question

A company uses AWS Transit Gateway to connect multiple VPCs and on-premises networks via AWS Site-to-Site VPN. Security engineers need to ensure that traffic between VPCs is inspected by a third-party firewall appliance deployed in a centralized inspection VPC. Which architecture should be used?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Create a central inspection VPC with the firewall appliance. Configure Transit Gateway route tables to route traffic between VPCs through the inspection VPC.

Transit Gateway route tables can force traffic between VPCs through the inspection VPC by attaching the firewall appliance and using specific routing entries. Option A is incorrect because security groups only control traffic at the instance level and cannot redirect traffic to an inspection appliance. Option B is incorrect because VPC Peering does not support transitive routing, so traffic between two VPCs cannot go through a third VPC. Option C is incorrect because Network ACLs are stateless and can only filter traffic based on IP/port, not route traffic through an inspection appliance.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Use security groups in each VPC to allow only traffic from the firewall appliance's IP.

    Why it's wrong here

    Security groups act as stateful firewalls at the elastic network interface level, so they can only allow or deny traffic directly to or from an instance. They have no ability to alter routing decisions or force traffic to traverse a given path—traffic between VPCs would still follow the transit gateway route tables, bypassing the firewall appliance entirely. Even if you restricted source IPs to the firewall's IP, other VPCs could still communicate directly via the Transit Gateway, as security groups do not inspect or redirect transit traffic. Therefore, this approach fails to provide centralized inspection.

  • ✗

    Establish VPC Peering connections between each VPC and the inspection VPC.

    Why it's wrong here

    VPC peering establishes a direct, one-to-one network connection between exactly two VPCs and does not support transitive routing. Even if every VPC is paired with a central inspection VPC, a packet from VPC A to VPC B would not be forwarded by the inspection VPC to VPC B because peering connections are non-transitive. You would need a separate peering connection between A and B for any direct communication, and routing via the inspection VPC is impossible. Thus, peering cannot implement a hub-and-spoke inspection model.

  • ✗

    Configure Network ACLs in each VPC to deny traffic that does not originate from the inspection VPC.

    Why it's wrong here

    Network ACLs are stateless packet filters applied at the subnet boundary; they can drop traffic based on source IP but cannot influence the routing table to redirect traffic through an appliance. Configuring NACLs to deny traffic not originating from the inspection VPC would simply block legitimate inter-VPC traffic whose source is the original VPC, not steer it into the inspection path. Additionally, because NACLs are stateless, return traffic must also be explicitly allowed, and they do not provide any mechanism for central inspection. This approach breaks connectivity without adding inspection.

  • ✓

    Create a central inspection VPC with the firewall appliance. Configure Transit Gateway route tables to route traffic between VPCs through the inspection VPC.

    Why this is correct

    Create a dedicated inspection VPC that hosts a firewall appliance or a Gateway Load Balancer, and use separate Transit Gateway route tables to force inter-VPC traffic through that VPC. For example, associate each spoke VPC attachment with a route table that has a target route pointing to the inspection VPC attachment for all destination CIDRs, while the inspection VPC uses its own route table to reach the final destination VPCs. This design leverages Transit Gateway's transitive routing and supports high availability through multiple firewall instances behind a Gateway Load Balancer. It is a best practice for centralized east-west traffic inspection in a multi-VPC topology.

Visual reference

Source Router + ACL permit 10.0.0.0/8 deny any Server 10.0.0.5 ✓ 192.168.1.1 ✗ dropped ACLs evaluate top-down; first match wins — implicit deny all at end

About these practice questions

This SCS-C02 question is part of Courseiva's 1,205-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.