Question 1
Q1A security architect is designing a multi-account AWS environment using FortiGate CNF for centralized egress filtering. The design includes a central networking account with a transit gateway and multiple spoke VPCs in different member accounts. To inspect traffic from the spoke VPCs, the architect has created a GWLB endpoint in each spoke. What is the final critical step required in the spoke VPC route tables to direct egress traffic through the FortiGate CNF for inspection?
Show answer & explanation
Correct answer: B
To enforce inspection, all egress traffic (0.0.0.0/0) from the spoke VPC subnets must be routed to the Gateway Load Balancer Endpoint (GWLBe). The GWLBe then forwards the traffic to the FortiGate CNF instance via the GWLB in the central security VPC for inspection before it proceeds to the internet.