AWS Certified Security – SpecialtyDomain 3: Infrastructure SecurityHard

A global enterprise is migrating its legacy applications to AWS. These applications frequently exchange sensitive data with on-premises systems and require a highly available, encrypted, and dedicated network connection. The security team mandates that all data in transit between AWS and on-premises must be encrypted end-to-end and use a private connection, not the public internet. Which combination of AWS services should be used to meet these requirements?

  1. AAWS Site-to-Site VPN over the public internet.
  2. BAWS Direct Connect with AWS Site-to-Site VPN over the Direct Connect private connection.
  3. CAWS Direct Connect with a VPN connection over the public internet.
  4. DVPC Peering Connections between on-premises and AWS.
Show answer & explanation

Correct answer: B. AWS Direct Connect with AWS Site-to-Site VPN over the Direct Connect private connection.

AWS Direct Connect provides a dedicated, private connection between on-premises and AWS, fulfilling the 'private connection' and 'high-bandwidth' requirement. To ensure end-to-end encryption over this private connection, an AWS Site-to-Site VPN can be established over the Direct Connect link. This 'Direct Connect + VPN' pattern offers both privacy and encryption, meeting all requirements.

Why the other options are wrong

  • A. AWS Site-to-Site VPN over the public internet provides encryption but does not offer a dedicated private connection or the guaranteed high bandwidth of Direct Connect.
  • C. A VPN over the public internet does not provide a dedicated private connection, and 'Direct Connect with a VPN over the public internet' is a contradictory setup.
  • D. VPC Peering is for connecting VPCs within AWS, not for connecting on-premises data centers to AWS.

Encrypted Hybrid Cloud Connectivity (Direct Connect + VPN)

A robust hybrid cloud connectivity solution that combines the dedicated, private, and high-bandwidth connection of AWS Direct Connect with the end-to-end encryption capabilities of AWS Site-to-Site VPN. The VPN is established over the Direct Connect link.

  • Direct Connect provides a private, dedicated network connection.
  • VPN adds a layer of encryption over the private Direct Connect link.
  • Ensures data in transit is both private and encrypted.
  • Offers high availability and predictable network performance.

Memory trick: Direct Connect is the 'private road', and VPN is the 'armored car' on that road.

More Domain 3: Infrastructure Security questions