Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Amazon ANS-C01 Exam - Topic 2 Question 69 Discussion

A company is using AWS Cloud WAN with one edge location in the us-east-1 Region and one edge location in the us-west-1 Region. A shared services segment exists at both edge locations. Each shared services segment has a VPC attachment to each inspection VPC in each Region. The inspection VPCs inspect traffic from a WAN by using AWS Network Firewall.The company creates a new segment for a new business unit (BU) in the us-east-1 edge location. The new BU has three VPCs that are attached to the new BU segment. To comply with regulations, the BU VPCs must not communicate with each other. All internet-bound traffic must be inspected in the inspection VPC.The company updates VPC route tables so any traffic that is bound for internet goes to the AWS Cloud WAN core network.The company plans to add more VPCs for the new BU in the future. All future VPCs must comply with regulations.Which solution will meet these requirements in the MOST operationally efficient way? (Choose two.)
B) Create a network policy to share the inspection service segment with the BU segment. and C) Set the isolate-attachments field to True for the BU segment.
A) Update the network policy to share the shared services segment with the BU segment.
D) Set the isolate-attachments field to False for the BU segment.
E) Update the network policy to add static routes for the BU segment. Configure the shared services segment to route traffic related to VPC CIDR blocks to each respective VPC attachment.

Amazon ANS-C01 Exam - Topic 2 Question 69 Discussion

Actual exam question for Amazon's ANS-C01 exam
Question #: 69
Topic #: 2
[All ANS-C01 Questions]

A company is using AWS Cloud WAN with one edge location in the us-east-1 Region and one edge location in the us-west-1 Region. A shared services segment exists at both edge locations. Each shared services segment has a VPC attachment to each inspection VPC in each Region. The inspection VPCs inspect traffic from a WAN by using AWS Network Firewall.

The company creates a new segment for a new business unit (BU) in the us-east-1 edge location. The new BU has three VPCs that are attached to the new BU segment. To comply with regulations, the BU VPCs must not communicate with each other. All internet-bound traffic must be inspected in the inspection VPC.

The company updates VPC route tables so any traffic that is bound for internet goes to the AWS Cloud WAN core network.

The company plans to add more VPCs for the new BU in the future. All future VPCs must comply with regulations.

Which solution will meet these requirements in the MOST operationally efficient way? (Choose two.)

Show Suggested Answer Hide Answer
Suggested Answer: B, C

Contribute your Thoughts:

0/2000 characters
Jin
3 days ago
E could complicate things with static routes, not sure it's worth it.
upvoted 0 times
...
Cordelia
8 days ago
A is a solid choice too, but C might be better for compliance.
upvoted 0 times
...
Quentin
13 days ago
Wait, can they really isolate VPCs like that? Sounds tricky.
upvoted 0 times
...
Ozell
19 days ago
I disagree, B seems more efficient for sharing services.
upvoted 0 times
...
Tula
24 days ago
Option C is the way to go for isolation!
upvoted 0 times
...
Ceola
29 days ago
I vaguely recall that setting isolate-attachments to True would help with compliance, but I’m not sure if we need to consider the inspection traffic too.
upvoted 0 times
...
Lorean
1 month ago
I think we had a practice question about route tables and shared services. Maybe option A could work, but I’m not confident it meets the isolation requirement.
upvoted 0 times
...
Mary
1 month ago
I'm not entirely sure, but I feel like we discussed the importance of not allowing communication between the BU VPCs. That makes me lean towards option C as well.
upvoted 0 times
...
Broderick
1 month ago
I remember something about isolating VPCs for compliance, so I think option C might be the right choice.
upvoted 0 times
...

Save Cancel