CompTIA Cloud Essentials+ (CLO-002)Business Principles of Cloud EnvironmentsHard
A cloud architect is designing a solution for a client's highly sensitive financial data application. The client requires complete isolation of their network traffic from all other tenants and demands direct, private connectivity from their on-premises data center to the cloud environment. Which cloud networking component should the architect implement?
- AInternet Gateway
- BVirtual Private Cloud (VPC)
- CNetwork Address Translation (NAT) Gateway
- DPublic IP addresses
Show answer & explanationAnswer & explanation
Correct answer: B. Virtual Private Cloud (VPC)
A Virtual Private Cloud (VPC) provides a logically isolated section of a public cloud where users can launch resources in a virtual network they define. This isolation, combined with private connectivity options like Direct Connect or ExpressRoute (implied by 'direct, private connectivity'), ensures that the client's network traffic is completely segregated, meeting the requirement for highly sensitive data.
Why the other options are wrong
- A. Internet Gateway allows resources in a public subnet to connect to the internet, which is contrary to the requirement for private, isolated traffic.
- C. NAT Gateway allows private subnets to connect to the internet while remaining private, but doesn't provide the fundamental isolation or private on-premises connectivity.
- D. Public IP addresses are used for internet-facing resources and do not provide isolation or private connectivity.
Virtual Private Cloud (VPC)
A logically isolated virtual network within a public cloud provider's infrastructure where users can provision and launch cloud resources.
- Provides network isolation and control.
- Allows defining IP address ranges, subnets, route tables, and network gateways.
- Essential for secure, private cloud deployments and hybrid cloud connectivity.
Memory trick: Cloud networks are like 'private roads' on the internet highway.