A network engineer must add an AWS Network Firewall to control internet-bound traffic in an existing environment that contains five VPCs. Each VPC has an internet gateway, NAT gateways, public ALBs, and EC2 instances in private subnets across two Availability Zones. The engineer must be able to write rules that consider the environment’s public IP addresses regardless of traffic direction, minimize changes to production, and ensure high availability. Which combination of steps should the engineer take? (Choose two.)
Choose an answer
Tap an option to check your answer.
Correct answer: Create new subnets in two Availability Zones in each VPC and deploy Network Firewall in each VPC with an endpoint in each Availability Zone., Update the route tables for the public subnets that host the NAT gateways and the ALBs to add routes to the Network Firewall endpoints..
Why this is the answer
The correct approach involves deploying Network Firewall endpoints within each VPC, rather than a centralized inspection VPC, to avoid hairpinning traffic and simplify routing for existing resources. Creating new subnets for the Network Firewall endpoints ensures dedicated resources and avoids conflicts with existing infrastructure. Updating the route tables for public subnets (where NAT Gateways and ALBs reside) is crucial because these are the egress points for internet-bound traffic. This ensures all outbound traffic from private subnets (via NAT Gateways) and inbound traffic to ALBs is inspected by the Network Firewall. Updating private subnet route tables directly would not capture all internet-bound traffic, as NAT Gateways are the primary egress for those instances.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed