nerdexam
AmazonAmazon

ANS-C01 · Question #180

ANS-C01 Question #180: Real Exam Question with Answer & Explanation

Sign in or unlock ANS-C01 to reveal the answer and full explanation for question #180. The question stem and answer options stay visible for context.

Submitted by emma.c· Mar 6, 2026

Question

A network engineer needs to deploy an AWS Network Firewall firewall into an existing AWS environment. The environment consists of the following: - A transit gateway with all VPCs attached to it - Several hundred application VPCs - A centralized egress internet VPC with a NAT gateway and an internet gateway - A centralized ingress internet VPC that hosts public Application Load Balancers - On-premises connectivity through an AWS Direct Connect gateway attachment The application VPCs have workloads deployed across multiple Availability Zones in private subnets with the VPC route table s default route (0.0.0.0/0) pointing to the transit gateway. The Network Firewall firewall needs to inspect east-west (VPC-to-VPC) traffic and north-south (internet-bound and on-premises network) traffic by using Suricata compatible rules. The network engineer must deploy the firewall by using a solution that requires the least possible architectural changes to the existing production environment. Which combination of steps should the network engineer take to meet these requirements? (Choose three.)

Options

  • ADeploy Network Firewall in all Availability Zones in each application VPC.
  • BDeploy Network Firewall in all Availability Zones in a centralized inspection VPC.
  • CUpdate the HOME_NET rule group variable to include all CIDR ranges of the VPCs and on-
  • DUpdate the EXTERNAL_NET rule group variable to include all CIDR ranges of the VPCs and on-
  • EConfigure a single transit gateway route table. Associate all application VPCs and the centralized
  • FConfigure two transit gateway route tables. Associate all application VPCs with one transit

Unlock ANS-C01 to see the answer

You've previewed enough free ANS-C01 questions. Unlock ANS-C01 for full answers, explanations, the timed quiz mode, progress tracking, and the master PDF. Question stem and options stay visible so you can still see what's on the exam.

Topics

#AWS Network Firewall deployment#AWS Transit Gateway routing#Traffic Inspection Architecture#Suricata rule configuration
Full ANS-C01 PracticeBrowse All ANS-C01 Questions