AWS Certified Security – SpecialtyDomain 3: Infrastructure SecurityMedium

A client is deploying a new internal API using Amazon API Gateway. This API will be consumed by applications running on EC2 instances within a private subnet of their VPC. For security and compliance, the API must not be accessible from the public internet, and all traffic between the EC2 instances and the API Gateway must remain within the AWS network. How should the API Gateway be configured to meet these requirements?

  1. AConfigure the API Gateway as a Regional API endpoint.
  2. BConfigure the API Gateway as an Edge-optimized API endpoint.
  3. CConfigure the API Gateway as a Public API endpoint and restrict access using a resource policy based on source IP.
  4. DConfigure the API Gateway as a Private API endpoint with a VPC Endpoint.
Show answer & explanation

Correct answer: D. Configure the API Gateway as a Private API endpoint with a VPC Endpoint.

A Private API endpoint for API Gateway, combined with a VPC Endpoint (interface endpoint), ensures that the API is only accessible from within your VPC (or connected networks) and that all traffic remains entirely within the AWS network, never traversing the public internet.

Why the other options are wrong

  • A. Regional API endpoints are public and accessible from the internet, though not globally optimized like Edge-optimized.
  • B. Edge-optimized API endpoints are public and use CloudFront for improved performance, not private access.
  • C. A Public API endpoint, even with a resource policy, is still publicly accessible and relies on IP filtering, which is less secure and doesn't guarantee traffic stays off the public internet.

API Gateway Private Endpoints

Amazon API Gateway Private API endpoints are accessible only from within your Amazon VPC by using an interface VPC endpoint.

  • API is not exposed to the public internet.
  • Access controlled via VPC Endpoint policies and resource policies.
  • Traffic remains within the AWS network.
  • Ideal for internal applications and microservices.

Memory trick: Private Endpoint Protects API Privately.

More Domain 3: Infrastructure Security questions