Modernize centralized firewall appliances with a Gateway Load Balancer and Auto Scaling

Answer Correct answers: A, C, E — Use a Gateway Load Balancer with a PrivateLink endpoint service, an Auto Scaling group with a launch template, and VPC endpoints in each member account.

A company uses AWS Organizations. The company runs two firewall appliances in a centralized networking account. Each firewall appliance runs on a manually configured highly available Amazon EC2 instance. A transit gateway connects the VPC from the centralized networking account to VPCs of member accounts. Each firewall appliance uses a static private IP address that is then used to route traffic from the member accounts to the internet. During a recent incident, a badly configured script initiated the termination of both firewall appliances. During the rebuild of the firewall appliances, the company wrote a new script to configure the firewall appliances at startup. The company wants to modernize the deployment of the firewall appliances. The firewall appliances need the ability to scale horizontally to handle increased traffic when the network expands. The company must continue to use the firewall appliances to comply with company policy. The provider of the firewall appliances has confirmed that the latest version of the firewall code will work with all AWS services. Which combination of steps should the solutions architect recommend to meet these requirements MOST cost-effectively? (Choose three.)

  1. Deploy a Gateway Load Balancer in the centralized networking account. Set up an endpoint service that uses AWS PrivateLink. Correct Answer
  2. Deploy a Network Load Balancer in the centralized networking account. Set up an endpoint service that uses AWS PrivateLink.
  3. Create an Auto Scaling group and a launch template that uses the new script as user data to configure the firewall appliances. Create a target group that uses the instance target type. Correct Answer
  4. Create an Auto Scaling group. Configure an AWS Launch Wizard deployment that uses the new script as user data to configure the firewall appliances. Create a target group that uses the IP target type.
  5. Create VPC endpoints in each member account. Update the route tables to point to the VPC endpoints. Correct Answer

Community Votes

ACE
100%

100% of anonymous learners picked answer ACE. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

A Gateway Load Balancer with a PrivateLink endpoint service is the AWS-native pattern for centralized traffic inspection, and it accepts appliances registered by IP address through an Auto Scaling group, so the static private IPs move out of the configuration entirely.

Two statically addressed firewall appliances on manually built EC2 instances must become a horizontally scalable, self-healing deployment, while member accounts keep routing to the internet through them. The vendor has confirmed the appliance code works with AWS services.

Substituting a Network Load Balancer. An NLB cannot distribute traffic to third-party inspection appliances using the GENEVE protocol, so it cannot front a firewall fleet, and an instance-target target group also breaks when the appliance needs a fixed private IP.

Community Discussion (25 comments)

yog927 👍 13 Selected: AC
Refer this https://aws.amazon.com/blogs/networking-and-content-delivery/centralized-inspection-architecture-with-aws-gateway-load-balancer-and-aws-transit-gateway/ The endpoint is created in the centralized account only.
blackname 👍 7 Selected: AC
A - Gateway Load Balancer is LB type used to redirect traffic to traffic inspection devices like firewalls, this is done via GENEVE network protocol. (correct) B - NLB could not be used, NLB does not support GENEVE protocol. (incorrect) C - ASG is the way to go for this scenario, in addition could be add Autoscaling policies to add more instances during traffic spikes and reduce when no traffic spikes (correct) D - Launch wizard work directly with resource EC2 and EBS, I didn't see any integration with ASG (incorrect) E - Works but it's not cost effective, VPCE have a price of 0.01$/hour/az each, so if you have GWLB in multi-az you would pay (1VPCE number of AZs number of member account) (incorrect - not cost effective) F - Since transit gateway is used, all traffic could be routed to the centralized networking account, and in there 0.0.0.0/0 traffic would go to the GWLB endpoints, so instead of multiple vpc endpoints you would only have 1VPCE * number of AZs (correct)
zhen234 👍 1 Selected: ACE
VPC endpoints need to be created in member accounts, not the centralized account.
TomTom 👍 1 Selected: ACE
ACE Can meet the requirement with most cost-effective
0b43291 👍 1 Selected: AC
Gateway Load Balancer (Step A): The Gateway Load Balancer (GWLB) is designed specifically for centralized inspection architectures, where traffic needs to be inspected or processed by third-party virtual appliances, such as the firewall appliances in this scenario. GWLB provides a cost-effective and scalable solution for distributing traffic across the firewall appliances. Auto Scaling Group and Launch Template (Step C): As mentioned in my previous response, creating an Auto Scaling group and a launch template that uses the new script as user data allows for automated and consistent deployment of the firewall appliances, as well as horizontal scaling to handle increased traffic. VPC Endpoints in the Centralized Networking Account (Step F): Creating VPC endpoints in the centralized networking account and updating the route tables in each member account to point to these VPC endpoints enables secure and private communication between the member accounts and the firewall appliances, without the need for an internet gateway or NAT gateway.
milesToGo 👍 2
Guys, The answer is ACE. AWS PrivateLink — A technology that provides private connectivity between VPCs and services. VPC endpoint — The entry point in your VPC that enables you to connect privately to a service. So Got to choose E - Create VPC endpoints in each member account. Update the route tables to point to the VPC endpoints. Check ChatGPT, Check Google Gemini (Do you create a VPC endpoint in centralized account or each member account if Gateway Load Balancer in the centralized networking account is set up as endpoint service using AWS PrivateLink) Go to Concepts and read under service name https://docs.aws.amazon.com/vpc/latest/privatelink/concepts.html
AzureDP900 👍 1
The correct answers are A, C, and E. Option A: Deploying a Gateway Load Balancer allows for efficient routing and scaling, while setting up an endpoint service using AWS PrivateLink enables secure and private connectivity between the load balancer and member accounts. Option C: Creating an Auto Scaling group with a launch template that uses the new script as user data ensures consistent configuration of firewall appliances. Additionally, creating a target group with the instance target type allows for efficient routing of traffic to the scaled instances. Option E: Creating VPC endpoints in each member account enables direct access to the centralized networking account's resources without the need for public IP addresses or NAT devices. This is particularly beneficial when deploying highly available and scalable firewall appliances.
Danm86 👍 1
Between E and F, I vote for option E, because already there is transit gateway for communication from centrailzed account to member accounts.
kgpoj 👍 1 Selected: ACE
A has VPC Endpoint Service in central VPC Then we should have VPC endpoints in member accounts
testo001 👍 1 Selected: ACE
Main discussion about E and F
vip2 👍 3 Selected: ACE
Main discussion about E and F it combine Member VPC, Centralize networking, Endpoint Service, VPC Endpoint Accoring to statement and answer A and C, that mean Transit-GW is in memeber VPC Firewall in Centralize VPC which alread has Endpoint Service in PrivateLink, So, MUST have VPC Endpoint in Memeber account, not Centralized Another important is 'Each firewall appliance uses a static private IP address that is then used to route traffic from the member accounts to the internet ', which prevent use one IP from transit-GW as endpoint.
vip2 👍 1
Main discussion about E and F it combine Member VPC, Centralize networking, Endpoint Service, VPC Endpoint Accoring to statement and answer A and C, that mean Transit-GW is in memeber VPC Firewall in Centralize VPC which alread has Endpoint Service in PrivateLink, So, MUST have VPC Endpoint in Memeber account, not Centralized Another important is 'Each firewall appliance uses a static private IP address that is then used to route traffic from the member accounts to the internet ', which prevent use one IP from transit-GW as endpoint.
grandcanyon 👍 5 Selected: ACE
https://docs.aws.amazon.com/vpc/latest/privatelink/vpce-gateway-load-balancer.html
trungtd 👍 3 Selected: AC
Having multiple VPC endpoints will make connection unscalable
Zas1 👍 3 Selected: ACE
F discard because update route. Explain "titi_r"
2aa610e 👍 3 Selected: ACE
gateway loadbalancer endpoint needs to be in the spoke VPC. https://aws.amazon.com/blogs/networking-and-content-delivery/scaling-network-traffic-inspection-using-aws-gateway-load-balancer/
7f6aef3 👍 4 Selected: ACE
VPC endpoint service in central account VPC endpoint in memeber account F is wrong
Spavanko 👍 1 Selected: BCE
More logical
leliodesouza 👍 2 Selected: BCE
Why B might also be considered: B. Deploy a Network Load Balancer in the centralized networking account: This would distribute incoming traffic across multiple instances of the firewall appliances deployed in the centralized networking account, providing scalability and high availability. Using AWS PrivateLink for endpoint services ensures that communication between member accounts and the centralized networking account remains within the AWS network, enhancing security and performance. However, this option may not be as cost-effective as option C alone because it involves additional costs associated with deploying and managing a Network Load Balancer. But it could be considered if high availability and scalability are prioritized over cost-effectiveness.
adelynllllllllll 👍 2
ACE E pairs up with end point service in A.
pangchn 👍 3 Selected: ACE
ACE VPC endpoint service in central account VPC endpoint in memeber account
AWSPro1234 👍 3 Selected: AC
I am thinking between E and F , E is not cost efficient but F is.
djangoUnchained 👍 4 Selected: ACE
Why would you create the VPC endpoint in the centralized account? The goal is to connect the member accounts to the centralized accounts. F is wrong. https://docs.aws.amazon.com/elasticloadbalancing/latest/gateway/getting-started.html
Dgix 👍 3 Selected: AC
For cost efficiency, ACF.
CMMC 👍 3 Selected: AC
aligned

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

A Gateway Load Balancer with a PrivateLink endpoint service is the documented pattern for centralized inspection, and member accounts reach the appliances through gateway VPC endpoints with updated route tables. An Auto Scaling group with a launch template that passes the configuration script as user data replaces the manual startup scripting, and an instance-type target group with preserved private addresses lets the appliances keep the static IPs the routing depends on. This is the most cost-effective combination because the same construct replaces both the appliance fleet and the manual rebuild process.

Why the Other Options Are Wrong

B: A Network Load Balancer cannot send traffic to third-party inspection appliances, because GWLB uses the GENEVE protocol specifically for this purpose. D: AWS Launch Wizard is a one-time guided deployment tool rather than a repeatable autoscaling mechanism, and the option omits a launch template. E: Endpoints must exist in the member accounts whose route tables are being changed, which is the reason E is correct only when paired with the centralized endpoint service in A.

Community Comment Notes

The community vote was 45 to 1 for A, C, E. Commenters cited the AWS centralized inspection architecture blog and confirmed that a Network Load Balancer cannot host inspection appliances, and one commenter confirmed the gateway VPC endpoints are created in the member accounts, which is why E belongs in the answer.

Official Reference

Related Analysis

Practice All SAP-C02 Questions

Access 85 questions with complete answers and detailed explanations.

View Full SAP-C02 Practice Test →

← Back to SAP-C02 Study Guide