nerdexam
Amazon

ANS-C01 · Question #193

A company is migrating critical applications to AWS. The company has multiple accounts and VPCs that are connected by a transit gateway. A network engineer must design a solution that performs deep…

The correct answer is D. Create a central log VPC and an attachment to the transit gateway. Update the VPC and transit. https://aws.amazon.com/blogs/networking-and-content-delivery/using-vpc-traffic-mirroring-to- monitor-and-secure-your-aws-infrastructure/

Submitted by devops_kid· Mar 6, 2026Network Security

Question

A company is migrating critical applications to AWS. The company has multiple accounts and VPCs that are connected by a transit gateway. A network engineer must design a solution that performs deep packet inspection for any traffic that leaves a VPC network boundary. All inspected traffic and the actions that are taken on the traffic must be logged in a central log account. Which solution will meet these requirements with the LEAST administrative overhead?

Options

  • ACreate a central network VPC that includes an attachment to the transit gateway. Update the
  • BCreate a central network VPC that includes an attachment to the transit gateway. Update the
  • CDeploy network ACLs and security groups to each VPAttach the security groups to active network
  • DCreate a central log VPC and an attachment to the transit gateway. Update the VPC and transit

How the community answered

(63 responses)
  • A
    17% (11)
  • B
    6% (4)
  • C
    10% (6)
  • D
    67% (42)

Explanation

https://aws.amazon.com/blogs/networking-and-content-delivery/using-vpc-traffic-mirroring-to- monitor-and-secure-your-aws-infrastructure/

Community Discussion

No community discussion yet for this question.

Full ANS-C01 Practice