AWS Cloud WAN Segment Isolation and Policy
A company is using AWS Cloud WAN with one edge location in the us-east-1 Region and one edge location in the us-west-1 Region. A shared services segment exists at both edge locations. Each shared services segment has a VPC attachment to each inspection VPC in each Region. The inspection VPCs inspect traffic from a WAN by using AWS Network Firewall. The company creates a new segment for a new business unit (BU) in the us-east-1 edge location. The new BU has three VPCs that are attached to the new BU segment. To comply with regulations, the BU VPCs must not communicate with each other. All internet-bound traffic must be inspected in the inspection VPC. The company updates VPC route tables so any traffic that is bound for internet goes to the AWS Cloud WAN core network. The company plans to add more VPCs for the new BU in the future. All future VPCs must comply with regulations. Which solution will meet these requirements in the MOST operationally efficient way? (Choose two.)
Community Votes
50% of anonymous learners picked answer AC. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
The exam tests the ability to isolate VPCs within a single segment (isolate-attachments=True) while ensuring traffic can still reach inspection services through explicit sharing or routing policies.
This question tests AWS Cloud WAN network policies, specifically using the isolate-attachments field to enforce VPC isolation within a segment. Community consensus favors combining segment isolation with shared service access via network policy for operational efficiency.
Candidates often choose B (Create a network policy to share the inspection service segment) instead of A because they assume 'inspection' implies needing the 'inspection segment'. However, the question specifies traffic goes to 'shared services segment' VPCs, making A the correct sharing target. Others miss that C is required for isolation.
Community Discussion (4 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
Option C (Set isolate-attachments to True) is critical because it prevents VPCs within the same BU segment from communicating with each other, satisfying the regulatory requirement for isolation without manual route table updates. Option A (Update network policy to share shared services segment) allows the BU segment to send traffic to the shared services segment, where the inspection VPCs reside. This combination ensures all internet-bound traffic is inspected while keeping BU VPCs isolated from each other.Why the Other Options Are Wrong
Option B is incorrect because the question states inspection happens in the 'shared services segment', not an 'inspection service segment'. Sharing a non-existent or misnamed segment would fail. Option D disables isolation, violating the compliance rule. Option E requires manual static route updates for every new VPC, which fails the 'MOST operationally efficient' criterion for future scalability.Community Comment Notes
Comments [2] highlight that AC provides a scalable solution requiring no manual route updates for new VPCs. Comment [1] clarifies that since the question mentions 'shared services segment' for inspection, Option A is the correct sharing target, not an inspection-specific segment. Comment [3] argues against A, but this overlooks that the shared services segment contains the inspection VPCs as per the setup description.Related Analysis
Practice All ANS-C01 Questions
Access 137 questions with complete answers and detailed explanations.
View Full ANS-C01 Practice Test →