AWS Certified Security – SpecialtyDomain 3: Infrastructure SecurityMedium

A global enterprise is migrating its legacy applications to AWS. These applications frequently communicate with on-premises systems and other AWS VPCs. The security team requires that all network traffic between these environments must be encrypted and centrally managed. Which AWS networking service should be used to establish secure, encrypted, and centrally managed connectivity?

  1. AInternet Gateway for all traffic.
  2. BVPC Peering Connections.
  3. CAWS Site-to-Site VPN connections managed by a Transit Gateway.
  4. DAWS Direct Connect with public VIFs.
Show answer & explanation

Correct answer: C. AWS Site-to-Site VPN connections managed by a Transit Gateway.

AWS Site-to-Site VPN connections provide encrypted connectivity between on-premises and AWS VPCs. Managing these connections through a Transit Gateway allows for centralized routing and management of traffic between multiple VPCs and on-premises networks, fulfilling the requirement for encryption and centralized management.

Why the other options are wrong

  • A. An Internet Gateway is for connecting VPCs to the public internet, does not provide encryption for private traffic, and is not for secure on-premises connectivity.
  • B. VPC Peering Connections allow direct network routing between VPCs but do not encrypt traffic by default and are not centrally managed for a large number of connections (N*N problem). They also don't connect to on-premises.
  • D. AWS Direct Connect provides dedicated network connections but does not inherently encrypt traffic (unless combined with VPN) and public VIFs are for public AWS services, not private VPC connectivity.

Centralized Encrypted Network Connectivity

Using AWS Transit Gateway with Site-to-Site VPN to achieve encrypted and centrally managed network connectivity between multiple AWS VPCs and on-premises networks.

  • Transit Gateway for hub-and-spoke routing.
  • Site-to-Site VPN for encrypted on-premises connectivity.
  • Scalable and centrally managed.

Memory trick: Transit Gateway + VPN: Centralized, Encrypted, Connected!

More Domain 3: Infrastructure Security questions