Ultimate access to all questions.
A solutions architect at a large company is tasked with establishing network security for outbound internet traffic from all AWS accounts within an AWS Organizations setup. The organization comprises over 100 AWS accounts, interconnected via a centralized AWS Transit Gateway. Each account is equipped with both an internet gateway and a NAT gateway for managing outbound internet traffic. The company's operations are confined to a single AWS Region. The requirement is to implement a centralized, rule-based filtering mechanism for all outbound internet traffic across all AWS accounts in the organization, with the constraint that the peak outbound traffic load per Availability Zone does not surpass 25 Gbps. Which solution effectively fulfills these requirements?