A US-based company adds a hub-and-spoke hub in eu-west-1 and connects it to an existing us-east-1 environment with a transit gateway peering connection. Each Region uses an inspection VPC with AWS Network Firewall to centralize inspection. To save cost, the engineer decides that inter-Region traffic should be inspected in the Region where the traffic originates and adjusts transit gateway route tables accordingly. Intra-Region communication works, but inter-Region traffic fails. What change will resolve the inter-Region connectivity issue?
Choose an answer
Tap an option to check your answer.
Correct answer: Enable Appliance mode on both the transit gateway attachments for the inspection VPC..
Why this is the answer
Enabling Appliance Mode on the Transit Gateway attachments for the inspection VPCs is crucial for inter-Region traffic inspection. Appliance Mode ensures that all traffic, including return traffic, for a given flow is sent to the same network appliance (in this case, the Network Firewall). Without Appliance Mode, the Transit Gateway might route return traffic directly to the source VPC, bypassing the inspection VPC in the originating Region, leading to asymmetric routing and dropped connections. OSPF is not applicable here as Transit Gateway peering connections do not support dynamic routing protocols. AWS RAM is used for sharing resources, not for routing traffic or resolving asymmetric routing. Preventing asymmetric routing is the goal, but "ensuring both requests and responses are inspected by the same inspection VPC" is achieved by enabling Appliance Mode, not a separate configuration.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed