AWS Certified Security – SpecialtyDomain 3: Infrastructure SecurityMedium
A client is deploying a new internal API using Amazon API Gateway. This API will be consumed exclusively by other services running within their AWS VPC and must not be accessible from the public internet. The security team requires that all traffic to this API remains entirely within the AWS network and is not exposed to the internet at any point. Which type of API Gateway endpoint should be configured to meet these security requirements?
- APrivate endpoint
- BEdge-optimized endpoint
- CPublic endpoint
- DRegional endpoint
Show answer & explanationAnswer & explanation
Correct answer: A. Private endpoint
A Private endpoint for API Gateway creates an interface VPC endpoint (powered by AWS PrivateLink) that allows clients in your VPC to securely access the API Gateway API without traversing the public internet. This ensures all traffic remains within the AWS network, meeting the strict security requirement.
Why the other options are wrong
- B. Edge-optimized endpoints are deployed using CloudFront and are publicly accessible, designed for global access over the internet.
- C. There is no 'Public endpoint' type distinct from Edge-optimized or Regional; both are public by nature.
- D. Regional endpoints are publicly accessible within a single AWS region over the internet.
API Gateway Private Endpoints
An Amazon API Gateway endpoint type that uses AWS PrivateLink to expose an API exclusively to clients within a specified Amazon Virtual Private Cloud (VPC) through an interface VPC endpoint, ensuring that traffic does not traverse the public internet.
- Ensures API access remains entirely within the AWS network (VPC).
- Uses AWS PrivateLink and interface VPC endpoints.
- Not accessible from the public internet.
- Ideal for internal-facing APIs and microservices.
Memory trick: A 'Private Endpoint' for API Gateway is like a 'secret back door' only for your VPC.