← AWS Solutions Architect Professional: complex decisions
17 / 25 · 75 MIN

Transit Gateway and traffic inspection

Trace a packet in both directions and demonstrate segmentation and inspection before handover.

Separate association, propagation, and subnet routing

First draw the attachment through which the packet enters Transit Gateway. The table associated with that attachment determines destination lookup. Propagation has a different role: it installs an attachment’s routes in one or more tables. An attachment associates with one table while it can propagate into several. Do not confuse a route visible in the shared-services table with the table actually used by production traffic. Also confirm the application subnet route to Transit Gateway and the return path. In the fictional exercise, a positions flow enters through PROD, associated with the isolated table. Its destination exists only in the services table; captures and tables should explain failure before permissions are opened. Two Available attachments do not establish that the complete path has been configured.

Read preference without losing the inspection requirement

Lookup selects the most specific route for the destination. For the same prefix, a static route takes precedence over a propagated route. In the original model, 172.22.0.0/16 leads to inspection, but 172.22.44.0/24 leads directly to the destination. A packet for 172.22.44.19 uses the latter and can bypass intended inspection. A successful functional test does not validate the security control. Compare the selected route, inspection-point records, and agreed negative tests. A blackhole route drops traffic matching the selected route; it does not guarantee blocking every more-specific exception. Record prefix, route origin, next hop, and table for every decision. Avoid treating attachment-type preference as overriding the initial most-specific match.

Ensure zone coverage and flow consistency

Resources in a zone need a VPC attachment with a subnet in that zone to reach Transit Gateway. Adding a third application zone without reviewing the attachment can cause failures only on new instances. The subnet route alone does not create that coverage. For stateful inspection in an appliance VPC, appliance mode retains the chosen zone for that attachment during the flow; the design still needs coherent routing both ways and state on the correct appliance. Do not assume enabling an option fills missing routes or fixes every asymmetry. Rehearsal should record source, destination, ports, zone, and forward and return paths. Include cross-zone traffic and the planned failure condition. One healthy connection in one zone does not establish coverage of the full deployment.

Choose the attachment and demonstrate boundaries

Direct peering between Transit Gateways requires acceptance and static routes to send traffic through the peer; do not assume automatic dynamic propagation. Overlapping VPC CIDRs are not solved by adding an attachment either. Identify the collision and review addressing or a compatible integration without claiming nonexistent general connectivity. Current documentation allows integrating AWS Network Firewall through a managed network function attachment, reducing manual inspection-VPC management. This option has its own requirements; do not present it as generic support for any third-party firewall. In either design, confirm effective routes that send traffic to inspection. For the PM, the output should be an allowed-and-denied flow matrix, table owners, per-zone evidence, and a reversible change plan. A centralized design still needs validation for each consumer.

from ipaddress import ip_address, ip_network
routes = [('172.22.0.0/16', 'inspection'), ('172.22.44.0/24', 'direct')]
destination = ip_address('172.22.44.19')
matches = [(ip_network(prefix).prefixlen, target) for prefix, target in routes if destination in ip_network(prefix)]
selected_target = max(matches)[1] # direct
# Teaching model: longest-prefix selection only, not all AWS route priorities.
IN PRACTICE

At a fictional bank, the positions application reaches a central service, but no records appear at the inspection point. The team identifies a /24 route taking precedence over the inspection /16 and reviews the exception with security and networking before retesting.

Common pitfalls

Inspecting the wrong table; confusing propagation with association; omitting return paths or zones; treating connectivity as proof of inspection.

Related topics: Hybrid DNS and authority across accounts

Take this idea with you

Validate the packet’s selected path in both directions against connectivity and segmentation requirements.

Create account

Reference: How Transit Gateway works · SAP-C02

AWS is a trademark of Amazon.com, Inc. or its affiliates. bigsavant.com is an independent preparation platform and is not affiliated with, associated with, sponsored, authorised or endorsed by AWS. Content and questions are original, are not official exam questions, and completing our tests does not award or guarantee any certification. Names are used only to identify the subject. All other trademarks belong to their respective owners.