AWS Certified Advanced Networking – Specialty (ANS-C01) — Question 22

A government contractor is designing a multi-account environment with multiple VPCs for a customer. A network security policy requires all traffic between any two VPCs to be transparently inspected by a third-party appliance.
The customer wants a solution that features AWS Transit Gateway. The setup must be highly available across multiple Availability Zones, and the solution needs to support automated failover. Furthermore, asymmetric routing is not supported by the inspection appliances.
Which combination of steps is part of a solution that meets these requirements? (Choose two.)

Answer options

Correct answer: B, C

Explanation

The correct answer is B and C. Option B specifies the use of a Gateway Load Balancer, which is designed for transparent inspection and supports automated failover, while option C outlines the necessary route table configuration that allows for proper traffic routing to the inspection VPC. Options A, D, and E do not meet the requirements for inspection or do not correctly configure the route tables needed for this setup.