Palo Alto Networks Certified Cybersecurity Entry-level Technician (PCCET)Cloud SecurityMedium

A cloud security engineer needs to establish a secure, private connection between their on-premises data center and their cloud virtual network to extend their corporate network securely. Which cloud networking component or service is primarily used for this purpose?

  1. AContent Delivery Network (CDN)
  2. BLoad Balancer
  3. CDirect Connect / ExpressRoute (dedicated connection)
  4. DVirtual Private Cloud (VPC)
Show answer & explanation

Correct answer: C. Direct Connect / ExpressRoute (dedicated connection)

Dedicated network connections like AWS Direct Connect or Azure ExpressRoute provide a private, high-bandwidth, and low-latency connection between an on-premises data center and a cloud provider's network, effectively extending the corporate network.

Why the other options are wrong

  • A. CDN caches content closer to users to improve delivery speed, not for private data center connectivity.
  • B. Load balancers distribute traffic across multiple resources, which is an application-level service, not a direct network extension to on-premises.
  • D. VPC is the isolated virtual network within the cloud, but doesn't, by itself, create a private connection to an on-premises data center.

Cloud Dedicated Connection

A dedicated, private network connection established between an organization's on-premises infrastructure and a cloud provider's network, bypassing the public internet.

  • Examples: AWS Direct Connect, Azure ExpressRoute, Google Cloud Interconnect.
  • Offers higher bandwidth, lower latency, and enhanced security compared to VPN over internet.
  • Used for hybrid cloud architectures and large data transfers.

Memory trick: Direct Connect is like building a 'private highway' to the cloud.

More Cloud Security questions