Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Amazon Exam ANS-C01 Topic 5 Question 21 Discussion

Actual exam question for Amazon's ANS-C01 exam
Question #: 21
Topic #: 5
[All ANS-C01 Questions]

A company is deploying third-party firewall appliances for traffic inspection and NAT capabilities in its VPC. The VPC is configured with private subnets and public subnets. The company needs to deploy the firewall appliances behind a load balancer.

Which architecture will meet these requirements MOST cost-effectively?

Show Suggested Answer Hide Answer
Suggested Answer: B

Contribute your Thoughts:

Sylvia
7 days ago
I'm not sure, you guys. I was kind of leaning towards option A, with the Gateway Load Balancer and the NAT gateway. I feel like that might be a bit more scalable and reliable in the long run, even if it's not the absolute cheapest option. But I'm open to being convinced otherwise. What do you all think?
upvoted 0 times
...
Novella
8 days ago
I'm leaning towards option B as well. The only thing I'm wondering about is the performance impact of having the firewall appliances handle the NAT functionality. I wonder if that could potentially become a bottleneck, especially if we're dealing with high traffic volumes. But overall, I think it's the best option presented here.
upvoted 0 times
...
Zachary
9 days ago
I agree with Orville on option B. It seems like the most efficient and cost-effective way to meet the requirements. Plus, I like the idea of using the firewall appliances' own NAT functionality instead of relying on a separate NAT gateway. It streamlines the setup and reduces the number of moving parts.
upvoted 0 times
...
Orville
10 days ago
Hmm, this question seems pretty straightforward. I think option B is the most cost-effective solution here. Using the Gateway Load Balancer and configuring the firewall appliances with two network interfaces, one in a private subnet and another in a public subnet, allows us to leverage the NAT functionality on the firewall appliances to send the traffic to the internet after inspection. This way, we don't need to set up a separate NAT gateway, which would add additional cost.
upvoted 0 times
...

Save Cancel