AWS Certified Advanced Networking – Specialty (ANS-C01)Network ImplementationHard

A financial institution requires a highly secure and compliant network architecture in AWS. They need to ensure that all traffic between their on-premises data center and their AWS VPCs is encrypted end-to-end and traverses a private, dedicated connection. Furthermore, they must have a backup connectivity solution that also meets the encryption requirements. Which combination of AWS networking services should be implemented?

  1. AAWS Transit Gateway with VPC peering connections to on-premises.
  2. BAWS Direct Connect Gateway with a transit VIF and AWS Client VPN for remote access.
  3. CAWS Direct Connect with a public VIF and AWS Site-to-Site VPN over the internet as a backup.
  4. DAWS Direct Connect with a private VIF and AWS Site-to-Site VPN over the Direct Connect connection.
Show answer & explanation

Correct answer: D. AWS Direct Connect with a private VIF and AWS Site-to-Site VPN over the Direct Connect connection.

AWS Direct Connect provides a private, dedicated connection, which is crucial for compliance. Using a private VIF ensures traffic stays on the AWS network. Encrypting traffic over Direct Connect is achieved by establishing an AWS Site-to-Site VPN over the Direct Connect connection itself, providing end-to-end encryption. This setup also inherently provides a highly available and encrypted backup path over the same private connection, or if the VPN tunnel fails, traffic still traverses the private Direct Connect link (though unencrypted). For a truly separate encrypted backup, a second Direct Connect with VPN or a VPN over internet could be considered, but the question implies encryption *over* the private connection. The most secure and compliant approach for encryption over a private link, with a backup, is VPN over DX.

Why the other options are wrong

  • A. Transit Gateway connects VPCs and on-premises networks but does not inherently provide the dedicated private connection of Direct Connect, nor does VPC peering connect directly to on-premises.
  • B. A transit VIF is used to connect to a Direct Connect Gateway for Transit Gateway associations, and Client VPN is for remote user access, not site-to-site connectivity.
  • C. A public VIF sends traffic over the public internet before reaching the AWS network and doesn't meet the 'private, dedicated connection' requirement for all traffic. VPN over internet is not a private dedicated connection.

Direct Connect with VPN (DX+VPN)

Direct Connect with VPN combines the dedicated, private connectivity of AWS Direct Connect with the encryption capabilities of AWS Site-to-Site VPN, offering a highly secure and compliant hybrid network solution.

  • Direct Connect provides dedicated private link, bypassing the internet.
  • Site-to-Site VPN encrypts traffic end-to-end over the DX connection.
  • Often used for sensitive data transfers and regulatory compliance, offering both privacy and encryption.

Memory trick: DX+VPN: The armored truck on a private highway, ensuring data's safe journey.

More Network Implementation questions