A company deployed AWS Cloud WAN with a single edge location in us-east-1. The Cloud WAN configuration includes a production segment and a security segment, plus the default core network policy. The company created a production VPC (attached to the production segment) and an outbound inspection VPC (attached to the security segment). An AWS Network Firewall in the outbound inspection VPC inspects internet-bound traffic. The production VPC route table sends all internet-bound traffic to the Cloud WAN core network, and the outbound inspection VPC route table routes traffic through the Network Firewall. An EC2 instance in the production VPC cannot access the internet. Network Firewall rules are not blocking the traffic. Which combination of actions will resolve the issue? (Choose two.)
Choose an answer
Tap an option to check your answer.
Correct answer: Update the core network policy to configure segment sharing. Share the production segment with the security segment., Update the core network policy to create a static route for the production segment. Specify 0.0.0.0/0 as the destination CIDR block. Specify the outbound inspection VPC as an attachment..
Why this is the answer
The EC2 instance in the production VPC cannot access the internet because the Cloud WAN core network does not know how to route internet-bound traffic from the production segment to the outbound inspection VPC. The first correct action is to update the core network policy to configure segment sharing, specifically sharing the production segment with the security segment. This allows traffic from the production segment to traverse to the security segment where the inspection VPC resides. The second correct action is to update the core network policy to create a static route for the production segment with a destination of 0.0.0.0/0, pointing to the outbound inspection VPC as the attachment. This explicitly directs all internet-bound traffic from the production segment through the inspection VPC. The incorrect option suggesting a static route for the security segment is wrong because the traffic originates from the production segment. The option with a specific CIDR (10.2.0.0/16) is too narrow and won't cover all internet traffic. Creating a new attachment and isolating the production segment would prevent traffic flow.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed