Soru

Zorluk: KolayAWS Network Services

An enterprise wants to interconnect 50 Amazon VPCs and their on-premises network in a hub-and-spoke topology to simplify routing management. Additionally, they need to implement a stateless security control at the subnet level to block traffic from specific IP addresses. Which of the following AWS features or services should the enterprise configure to meet these requirements? (Select TWO.)

  1. AWS Transit GatewayCevap
  2. Network Access Control Lists (Network ACLs)Cevap
  3. C
    VPC Peering
  4. D
    Security Groups
  5. E
    NAT Gateway

Cevap

AWS Transit Gateway and Network Access Control Lists (Network ACLs)
AWS Transit Gateway is the correct service for connecting a large number of VPCs and on-premises networks in a simplified hub-and-spoke design. Network Access Control Lists (Network ACLs) are correct because they operate statelessly at the subnet level, which allows configuring explicit rules to deny and block specific IP addresses.

Adım Adım Çözüm

1
Identify the routing solution for scaling multi-VPC connectivity.
AWS Transit Gateway is identified as the central hub to connect 50 VPCs and on-premises networks, avoiding the mesh complexity of VPC Peering.
It acts as a cloud router, simplifying connectivity management and reducing configuration overhead.
2
Identify the network security mechanism that operates at the subnet level and supports stateless deny rules.
Network Access Control Lists (Network ACLs) are selected over Security Groups because they are stateless, apply at the subnet level, and can block specific IP addresses.
Security Groups are stateful, operate at the instance level, and only support allow rules.

Anahtar Kavram

AWS Transit Gateway simplifies multi-VPC and hybrid network routing using a hub-and-spoke model, while Network ACLs provide stateless, subnet-level security filtering including explicit IP blocking.
Bu soruyu puanla