A company uses AWS Cloud WAN with edge locations in us-east-1 and us-west-1. A shared services segment exists at both edges, and each shared segment has VPC attachments to each inspection VPC. Inspection VPCs run AWS Network Firewall to inspect WAN traffic. A new business-unit (BU) segment is created at the us-east-1 edge with three BU VPCs attached. Regulations require that BU VPCs must not communicate with one another and that all internet-bound traffic be inspected in the inspection VPC. VPC route tables already send internet-bound traffic to the Cloud WAN core. More BU VPCs will be added later and must follow the same rules. Which actions provide the most operational efficiency? (Choose two.)
Choose an answer
Tap an option to check your answer.
Correct answer: Create a network policy to share the inspection service segment with the BU segment., Set the isolate-attachments field to True for the BU segment..
Why this is the answer
To ensure BU VPCs cannot communicate with each other, setting isolate-attachments to True for the BU segment is crucial. This automatically creates isolation within the segment, preventing direct VPC-to-VPC routing. To route internet-bound traffic through the inspection VPC, the inspection service segment (which contains the Network Firewall) must be shared with the BU segment. This allows the Cloud WAN policy to direct traffic from the BU VPCs to the inspection VPC for filtering. Sharing the shared services segment would not provide the necessary inspection capabilities. Adding static routes is less efficient than leveraging segment sharing and isolation for these requirements.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed