CompTIA Cloud+ (CV0-004)SecurityMedium

A cloud architect is designing a highly available and secure application that relies on a managed database service. The architect needs to ensure that the database traffic remains private and does not traverse the public internet, even when accessed by other services within the same cloud provider's network. Which networking construct should the architect use to achieve this private connectivity?

  1. AVirtual Private Gateway
  2. BVPC Peering
  3. CInternet Gateway
  4. DPrivate Link / Service Endpoint
Show answer & explanation

Correct answer: D. Private Link / Service Endpoint

Private Link (AWS) or Service Endpoints (Azure/GCP) allow services within a cloud provider's network to connect privately without traversing the public internet, even if they are in different VPCs/VNets or owned by different accounts. This ensures secure and isolated communication.

Why the other options are wrong

  • A. A Virtual Private Gateway is used to connect a VPC to an on-premises network via VPN, not for private connectivity within the cloud provider's network.
  • B. VPC Peering connects two VPCs directly, but it's typically for direct communication between user-owned VPCs, not for privately accessing managed services across the provider's network boundary without public internet exposure.
  • C. An Internet Gateway allows resources in a VPC to connect to the public internet, which is the opposite of the requirement.

Private Link / Service Endpoint

A cloud networking feature that enables private connectivity to services hosted on the same cloud platform, without exposing traffic to the public internet.

  • Connects VPCs/VNets to services privately.
  • Traffic remains within the cloud provider's network.
  • Enhances security and simplifies network architecture.

Memory trick: Private Links Prevent Public Leaks.

More Security questions