AWS Certified Security – SpecialtyDomain 3: Infrastructure SecurityMedium

A company is developing a new application that uses Amazon API Gateway to expose RESTful APIs. These APIs need to be accessible only from specific internal VPCs and not from the public internet. Furthermore, the company requires that all API calls are authenticated using IAM credentials. How should this API Gateway be configured?

  1. AConfigure the API Gateway endpoint type as 'Private' and associate it with a VPC Endpoint, then use an IAM authorizer for authentication.
  2. BConfigure the API Gateway endpoint type as 'Public' and deploy it in a private subnet, then use a custom Lambda authorizer for authentication.
  3. CConfigure the API Gateway endpoint type as 'Edge-optimized' and use a WAF ACL to block public access, then use a Cognito authorizer for authentication.
  4. DConfigure the API Gateway endpoint type as 'Regional' and use a Resource Policy to restrict access to specific VPC CIDR ranges.
Show answer & explanation

Correct answer: A. Configure the API Gateway endpoint type as 'Private' and associate it with a VPC Endpoint, then use an IAM authorizer for authentication.

Setting the API Gateway endpoint type to 'Private' ensures it's only accessible from within a VPC via a VPC Endpoint, preventing public internet exposure. Using an IAM authorizer allows for authentication based on IAM credentials, meeting the authentication requirement.

Why the other options are wrong

  • B. There is no 'Public' endpoint type that can be deployed in a private subnet to make it private; 'Public' implies internet accessibility. A custom Lambda authorizer can work for authentication but doesn't address the private access requirement without a 'Private' endpoint type.
  • C. 'Edge-optimized' endpoints are publicly accessible, leveraging CloudFront, which contradicts the 'not from the public internet' requirement. WAF can filter but doesn't make it truly private. Cognito is for user pools, not typically IAM credentials for internal services.
  • D. 'Regional' endpoints are publicly accessible, and while a Resource Policy can restrict by IP, it's not truly private and still exposed to the internet. IAM authentication would still be needed separately.

Private API Gateway Configuration

Configuring Amazon API Gateway with a 'Private' endpoint type and a VPC Endpoint to restrict access solely to internal VPCs, combined with IAM authorizers for secure authentication.

  • Private endpoint type for internal VPC access.
  • VPC Endpoint for private connectivity.
  • IAM authorizer for IAM credential-based authentication.

Memory trick: API Gateway: Private Endpoints, IAM Authorizers, Internal Access!

More Domain 3: Infrastructure Security questions