Palo Alto Networks Certified Cybersecurity Entry-level Technician (PCCET)Cloud SecurityMedium
A cloud security engineer needs to establish a secure, private connection between their on-premises data center and their cloud virtual network to extend their corporate network securely. Which cloud networking component or service is primarily used for this purpose?
- AContent Delivery Network (CDN)
- BLoad Balancer
- CDirect Connect / ExpressRoute (dedicated connection)
- DVirtual Private Cloud (VPC)
Show answer & explanationAnswer & explanation
Correct answer: C. Direct Connect / ExpressRoute (dedicated connection)
Dedicated network connections like AWS Direct Connect or Azure ExpressRoute provide a private, high-bandwidth, and low-latency connection between an on-premises data center and a cloud provider's network, effectively extending the corporate network.
Why the other options are wrong
- A. CDN caches content closer to users to improve delivery speed, not for private data center connectivity.
- B. Load balancers distribute traffic across multiple resources, which is an application-level service, not a direct network extension to on-premises.
- D. VPC is the isolated virtual network within the cloud, but doesn't, by itself, create a private connection to an on-premises data center.
Cloud Dedicated Connection
A dedicated, private network connection established between an organization's on-premises infrastructure and a cloud provider's network, bypassing the public internet.
- Examples: AWS Direct Connect, Azure ExpressRoute, Google Cloud Interconnect.
- Offers higher bandwidth, lower latency, and enhanced security compared to VPN over internet.
- Used for hybrid cloud architectures and large data transfers.
Memory trick: Direct Connect is like building a 'private highway' to the cloud.