AWS Certified Solutions Architect – Professional (SAP-C02) — Question 250

A solutions architect at a large company needs to set up network security for outbound traffic to the internet from all AWS accounts within an organization in AWS Organizations. The organization has more than 100 AWS accounts, and the accounts route to each other by using a centralized AWS Transit Gateway. Each account has both an internet gateway and a NAT gateway for outbound traffic to the internet. The company deploys resources only into a single AWS Region.

The company needs the ability to add centrally managed rule-based filtering on all outbound traffic to the internet for all AWS accounts in the organization. The peak load of outbound traffic will not exceed 25 Gbps in each Availability Zone.

Which solution meets these requirements?

Answer options

Correct answer: B

Explanation

Option B is correct because it uses AWS Network Firewall, which can centrally manage rule-based filtering for all outbound traffic across multiple accounts. This solution is scalable and integrates well with the existing architecture. The other options either require more management overhead or do not provide the centralized approach needed for an organization with over 100 AWS accounts.