CompTIA Cloud+ (CV0-004)SecurityEasy

A cloud administrator needs to establish a secure, private connection between a company's on-premises data center and their cloud-based virtual network. This connection must not traverse the public internet and should offer consistent network performance. Which of the following cloud networking services should the administrator implement?

  1. ADirect Connect / ExpressRoute / Interconnect
  2. BVirtual Private Network (VPN) gateway
  3. CNetwork Access Control List (NACL)
  4. DCloud Access Security Broker (CASB)
Show answer & explanation

Correct answer: A. Direct Connect / ExpressRoute / Interconnect

Direct Connect (AWS), ExpressRoute (Azure), and Cloud Interconnect (GCP) are all examples of dedicated, private network connections that bypass the public internet, providing consistent performance and enhanced security for hybrid cloud environments.

Why the other options are wrong

  • B. A VPN gateway uses encrypted tunnels over the public internet, which does not guarantee consistent performance and traverses the public internet.
  • C. NACLs are stateless packet filters used for subnet-level traffic control within a cloud network, not for establishing private connections to on-premises environments.
  • D. A CASB is a security policy enforcement point between cloud users and cloud applications, primarily for data visibility and threat protection, not for establishing direct network connectivity.

Dedicated Cloud Connectivity

Dedicated cloud connectivity services (e.g., AWS Direct Connect, Azure ExpressRoute) establish a private, high-bandwidth network connection between an on-premises data center and a cloud provider's network, bypassing the public internet.

  • Bypasses public internet for enhanced security and performance.
  • Offers consistent network throughput and lower latency.
  • Ideal for hybrid cloud architectures and large data transfers.

Memory trick: Direct routes are Express for Interconnecting your cloud.

More Security questions