Courseiva
Infrastructure Security →easyMultiple Choice

SCS-C02 Infrastructure Security Practice Question

A security engineer needs to ensure that all traffic to an EC2 instance in a VPC is inspected by a network firewall appliance. The firewall is deployed in a separate subnet. What is the MOST secure and scalable way to route traffic through the firewall?

⚠ Common exam trap

It's easy for candidates to confuse Gateway Load Balancer with a traditional load balancer (ALB/NLB) or assume a NAT gateway can inspect inbound traffic, but GWLB is the only AWS service designed specifically for transparent, scalable, and highly available traffic inspection at the network layer.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use a Gateway Load Balancer with a Gateway Load Balancer endpoint in each subnet.

A Gateway Load Balancer (GWLB) with a Gateway Load Balancer endpoint in each subnet provides transparent, scalable, and highly available traffic inspection. GWLB operates at Layer 3 (IP packets) and uses GENEVE encapsulation to forward traffic to the firewall appliance without modifying the source/destination IP addresses, ensuring all traffic to the EC2 instance is inspected. This architecture scales horizontally by adding more firewall instances behind the GWLB and avoids single points of failure.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Configure a NAT gateway in the firewall subnet and route all traffic through it.

    Why it's wrong here

    A NAT gateway only supports outbound-initiated traffic from private subnets by translating source IP addresses; it cannot receive or inspect unsolicited inbound traffic, and it provides no firewall or filtering functionality. Even if placed in a firewall subnet, route tables cannot force transparent bidirectional inspection through it, so return traffic and inbound connections would bypass the control point. This approach therefore does not satisfy a requirement to inspect all traffic to the application.

  • ✓

    Use a Gateway Load Balancer with a Gateway Load Balancer endpoint in each subnet.

    Why this is correct

    Gateway Load Balancer sits inline at Layers 3 and 4 by encapsulating traffic in GENEVE tunnels, forwarding packets to a fleet of firewall appliances while preserving flow symmetry. A Gateway Load Balancer endpoint is created in each subnet and becomes the next-hop target in VPC route tables, so all traffic entering or leaving those subnets is transparently steered through the firewall fleet. This design also provides health checks and autoscaling for the security appliances.

  • ✗

    Use an Application Load Balancer in front of the firewall.

    Why it's wrong here

    An Application Load Balancer operates at Layer 7 and terminates HTTP/HTTPS client connections, then initiates new connections to targets; it is not a transparent next-hop in route tables and cannot intercept arbitrary IP traffic such as raw TCP or UDP. Because the ALB is an endpoint service rather than an inline appliance, traffic flowing between subnets or from the internet cannot be forced through it without breaking the original layer-3 path. It therefore cannot provide transparent security inspection for all traffic before it reaches the application.

  • ✗

    Create a transit gateway and route traffic through the firewall subnet.

    Why it's wrong here

    A transit gateway connects separate VPCs, VPNs, and Direct Connect attachments and uses its own route tables to control inter-VPC routing; it cannot be deployed inside a single VPC to intercept east-west or internet-bound traffic between subnets. Traffic within a VPC does not traverse a transit gateway unless it is explicitly routed to another attachment, and it offers no packet inspection or firewall capabilities. Thus a transit gateway is a connectivity hub, not an inline inspection device for this requirement.

Visual reference

192.168.1.0 /24 256 addresses (254 usable) 192.168.1.0 /25 Subnet A 128 addr (126 usable) 192.168.1.128 /25 Subnet B 128 addr (126 usable) Borrowing 1 bit from host portion creates 2 subnets (/25)

About these practice questions

One of 1,205 original SCS-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.