AWS Certified Advanced Networking – Specialty (ANS-C01) — Question 105

A company has users who work from home. The company wants to move these users to Amazon WorkSpaces for additional security visibility.

The company has deployed WorkSpaces in its own AWS account in VPC A. A network engineer decides to provide the security visibility by using two firewall appliances behind a Gateway Load Balancer (GWLB). The network engineer provisions another VPC, VPC B, in a separate account and deploys the two firewall appliances in separate Availability Zones.

What should the network engineer do to configure the network connectivity for this solution?

Answer options

Correct answer: B

Explanation

The correct answer is B because the GWLB needs to be created in VPC B, where the firewall appliances are deployed, to manage traffic effectively. Options A, C, and D either incorrectly place the GWLB in VPC A or misconfigure the principal allow list for the GWLB endpoint, which would prevent proper communication between the WorkSpaces and the firewall appliances.