🔍

AWS Certified Advanced Networking - Specialty ANS-C01 — Question 150

Topic 1 · Question 150 of 292

Topic 1 · Question 150 · Select all that apply

A network engineer needs to deploy an AWS Network Firewall firewall into an existing AWS environment. The environment consists of the following: • A transit gateway with all VPCs attached to it • Several hundred application VPCs • A centralized egress internet VPC with a NAT gateway and an internet gateway • A centralized ingress internet VPC that hosts public Application Load Balancers • On-premises connectivity through an AWS Direct Connect gateway attachment The application VPCs have workloads deployed across multiple Availability Zones in private subnets with the VPC route table s default route (0.0.0.0/0) pointing to the transit gateway. The Network Firewall firewall needs to inspect east-west (VPC-to-VPC) traffic and north-south (internet-bound and on-premises network) traffic by using Suricata compatible rules. The network engineer must deploy the firewall by using a solution that requires the least possible architectural changes to the existing production environment. Which combination of steps should the network engineer take to meet these requirements? (Choose three.)

Select 3 answers to reveal the result.