Modernize centralized firewall appliances with a Gateway Load Balancer and Auto Scaling
A company uses AWS Organizations. The company runs two firewall appliances in a centralized networking account. Each firewall appliance runs on a manually configured highly available Amazon EC2 instance. A transit gateway connects the VPC from the centralized networking account to VPCs of member accounts. Each firewall appliance uses a static private IP address that is then used to route traffic from the member accounts to the internet. During a recent incident, a badly configured script initiated the termination of both firewall appliances. During the rebuild of the firewall appliances, the company wrote a new script to configure the firewall appliances at startup. The company wants to modernize the deployment of the firewall appliances. The firewall appliances need the ability to scale horizontally to handle increased traffic when the network expands. The company must continue to use the firewall appliances to comply with company policy. The provider of the firewall appliances has confirmed that the latest version of the firewall code will work with all AWS services. Which combination of steps should the solutions architect recommend to meet these requirements MOST cost-effectively? (Choose three.)
Community Votes
100% of anonymous learners picked answer ACE. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
A Gateway Load Balancer with a PrivateLink endpoint service is the AWS-native pattern for centralized traffic inspection, and it accepts appliances registered by IP address through an Auto Scaling group, so the static private IPs move out of the configuration entirely.
Two statically addressed firewall appliances on manually built EC2 instances must become a horizontally scalable, self-healing deployment, while member accounts keep routing to the internet through them. The vendor has confirmed the appliance code works with AWS services.
Substituting a Network Load Balancer. An NLB cannot distribute traffic to third-party inspection appliances using the GENEVE protocol, so it cannot front a firewall fleet, and an instance-target target group also breaks when the appliance needs a fixed private IP.
Community Discussion (25 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
A Gateway Load Balancer with a PrivateLink endpoint service is the documented pattern for centralized inspection, and member accounts reach the appliances through gateway VPC endpoints with updated route tables. An Auto Scaling group with a launch template that passes the configuration script as user data replaces the manual startup scripting, and an instance-type target group with preserved private addresses lets the appliances keep the static IPs the routing depends on. This is the most cost-effective combination because the same construct replaces both the appliance fleet and the manual rebuild process.Why the Other Options Are Wrong
B: A Network Load Balancer cannot send traffic to third-party inspection appliances, because GWLB uses the GENEVE protocol specifically for this purpose. D: AWS Launch Wizard is a one-time guided deployment tool rather than a repeatable autoscaling mechanism, and the option omits a launch template. E: Endpoints must exist in the member accounts whose route tables are being changed, which is the reason E is correct only when paired with the centralized endpoint service in A.Community Comment Notes
The community vote was 45 to 1 for A, C, E. Commenters cited the AWS centralized inspection architecture blog and confirmed that a Network Load Balancer cannot host inspection appliances, and one commenter confirmed the gateway VPC endpoints are created in the member accounts, which is why E belongs in the answer.Official Reference
Related Analysis
Practice All SAP-C02 Questions
Access 85 questions with complete answers and detailed explanations.
View Full SAP-C02 Practice Test →