Certified Cloud Security Professional (CCSP)Cloud Platform and Infrastructure SecurityEasy

A cloud security engineer needs to establish a secure, private network connection between an on-premises data center and a Virtual Private Cloud (VPC) in a public cloud environment. The connection must offer high throughput and low latency, bypassing the public internet. Which cloud networking service should the engineer choose?

  1. ANAT Gateway
  2. BInternet Gateway
  3. CDirect Connect / ExpressRoute / Interconnect
  4. DVPN Gateway
Show answer & explanation

Correct answer: C. Direct Connect / ExpressRoute / Interconnect

Direct Connect (AWS), ExpressRoute (Azure), or Cloud Interconnect (GCP) are dedicated, private network connections that bypass the public internet, offering consistent high throughput and low latency, which is ideal for secure hybrid cloud scenarios.

Why the other options are wrong

  • A. NAT Gateway allows instances in a private subnet to initiate outbound connections to the internet, but prevents inbound connections from the internet.
  • B. Internet Gateway allows instances in a public subnet to connect to the internet, not a private connection to an on-premises data center.
  • D. VPN Gateway uses encrypted tunnels over the public internet, which may not guarantee high throughput or low latency.

Cloud Private Connectivity

Dedicated network services (e.g., Direct Connect, ExpressRoute) that establish a private, high-bandwidth, low-latency connection between on-premises environments and cloud VPCs, bypassing the public internet.

  • Bypasses public internet for enhanced security and performance.
  • Provides consistent network performance.
  • Essential for hybrid cloud architectures requiring secure, fast links.

Memory trick: Direct routes are always the fastest routes.

More Cloud Platform and Infrastructure Security questions