nerdexam
AmazonAmazon

ANS-C01 · Question #128

ANS-C01 Question #128: Real Exam Question with Answer & Explanation

Sign in or unlock ANS-C01 to reveal the answer and full explanation for question #128. The question stem and answer options stay visible for context.

Submitted by ngozi_ng· Mar 6, 2026Design and Implement Network Security

Question

A company's existing AWS environment contains public application servers that run on Amazon EC2 instances. The application servers run in a VPC subnet. Each server is associated with an Elastic IP address. The company has a new requirement for firewall inspection of all traffic from the internet before the traffic reaches any EC2 instances. A security engineer has deployed and configured a Gateway Load Balancer (GLB) in a standalone VPC with a fleet of third-party firewalls. How should a network engineer update the environment to ensure that the traffic travels across the fleet of firewalls?

Options

  • ADeploy a transit gateway. Attach a GLB endpoint to the transit gateway. Attach the application
  • BUpdate the application subnet route table to have a default route to the GLOn the standalone
  • CProvision a GLB endpoint in the application VPC in a new subnet. Create a gateway route table
  • DInstruct the security engineer to move the GLB into the application VPC. Create a gateway route

Unlock ANS-C01 to see the answer

You've previewed enough free ANS-C01 questions. Unlock ANS-C01 for full answers, explanations, the timed quiz mode, progress tracking, and the master PDF. Question stem and options stay visible so you can still see what's on the exam.

Topics

#AWS GLB#VPC routing#Network traffic inspection#Third-party firewalls
Full ANS-C01 PracticeBrowse All ANS-C01 Questions