A company has stateful security appliances deployed in multiple AZs inside a centralized shared services VPC. A transit gateway attaches application VPCs and the shared services VPC. Application workloads run in private subnets across multiple AZs. The stateful appliances inspect all east–west VPC-to-VPC traffic. Users report that traffic between workloads in different Availability Zones is being dropped. ICMP pings between workloads across AZs fail. Security groups, appliance configs, and network ACLs are ruled out. What is causing the dropped traffic?
Choose an answer
Tap an option to check your answer.
Correct answer: Appliance mode is not enabled on the transit gateway attachment to the shared services VPC..
Why this is the answer
When stateful appliances inspect east-west traffic between VPCs via a Transit Gateway, traffic must return through the same appliance it initially traversed to maintain state. Without Appliance Mode enabled on the Transit Gateway attachment to the shared services VPC, the Transit Gateway performs equal-cost multi-path (ECMP) routing. This means return traffic from a different Availability Zone might be routed to a different appliance instance, causing the connection to be dropped because the new appliance has no state information for that flow. Enabling Appliance Mode ensures that traffic for a given flow consistently returns to the same appliance instance, preserving state. The other options are incorrect because deploying appliances and TGW attachments in separate subnets or the same subnet doesn't inherently break stateful inspection, and Appliance Mode on application VPC attachments isn't relevant for ensuring return traffic symmetry through the shared services appliances.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed