AWS Certified Security – SpecialtyDomain 3: Infrastructure SecurityHard
A global enterprise is migrating its on-premises data centers to AWS. They have a requirement to establish secure, high-throughput, and redundant network connectivity between their on-premises network and their AWS VPCs across multiple regions. This connectivity must ensure all traffic is encrypted in transit and support dynamic routing. Which solution provides the most appropriate and resilient network architecture?
- AConfigure VPC Peering connections between all AWS VPCs and connect one VPC to on-premises via a single Direct Connect.
- BImplement AWS Direct Connect connections with multiple Direct Connect Gateways and Site-to-Site VPN as a backup.
- CEstablish multiple AWS Site-to-Site VPN connections from each on-premises data center to each AWS VPC.
- DUtilize AWS Transit Gateway to connect all VPCs and establish a single Site-to-Site VPN connection from on-premises.
Show answer & explanationAnswer & explanation
Correct answer: B. Implement AWS Direct Connect connections with multiple Direct Connect Gateways and Site-to-Site VPN as a backup.
AWS Direct Connect provides dedicated, high-throughput network connections. Combining it with multiple Direct Connect Gateways for multi-region connectivity and using Site-to-Site VPN as a redundant failover mechanism ensures both high availability and encryption for all traffic in transit, while supporting dynamic routing.
Why the other options are wrong
- A. VPC Peering connects VPCs but doesn't scale well for many VPCs or provide on-premises connectivity directly. A single Direct Connect lacks redundancy and multi-region reach without additional components.
- C. Site-to-Site VPN is encrypted but may not offer the 'high-throughput' of Direct Connect alone, and managing many VPNs can be complex for multiple regions/VPCs.
- D. Transit Gateway simplifies VPC connectivity but doesn't inherently provide high-throughput dedicated links to on-premises, and a single VPN is not redundant or high-throughput enough.
Hybrid Cloud Connectivity
Designing robust hybrid cloud connectivity involves combining AWS Direct Connect for high-throughput with VPN for encryption and redundancy, often leveraging Transit Gateway for centralized routing.
- Direct Connect: Dedicated, high-bandwidth connection.
- Site-to-Site VPN: Encrypted tunnel over public internet.
- Direct Connect Gateway: Connects DX to multiple VPCs/regions.
- Transit Gateway: Central routing hub for VPCs and on-premises.
Memory trick: Direct Connect for Speed, VPN for Backup, Gateway for Global.