AWS Certified Advanced Networking – Specialty (ANS-C01)Network DesignEasy
A company is designing a new application that will process sensitive financial data. The application's backend services need to access Amazon S3 and Amazon DynamoDB without traversing the public internet. The security team mandates that all traffic must remain within the AWS network and be fully private. Which networking construct should be implemented to ensure secure and private access to these AWS services from within the VPC?
- AVPC Endpoints
- BInternet Gateway
- CAWS Direct Connect
- DNAT Gateway
Show answer & explanationAnswer & explanation
Correct answer: A. VPC Endpoints
VPC Endpoints allow private connectivity to supported AWS services without requiring an internet gateway, NAT device, VPN connection, or AWS Direct Connect connection. Traffic between your VPC and the AWS service remains entirely within the Amazon network.
Why the other options are wrong
- B. Internet Gateway enables public internet access for a VPC, directly contradicting the private access requirement.
- C. AWS Direct Connect links on-premises networks to AWS, not directly for private access to AWS services from within a VPC.
- D. NAT Gateway allows instances in a private subnet to connect to the internet, which violates the requirement for no public internet traversal.
VPC Endpoints
A feature that enables private connectivity from your VPC to supported AWS services and VPC endpoint services powered by AWS PrivateLink, without requiring an internet gateway, NAT device, VPN connection, or AWS Direct Connect connection.
- Keeps traffic within the Amazon network.
- Supports two types: Interface Endpoints (powered by PrivateLink) and Gateway Endpoints.
- Gateway Endpoints support S3 and DynamoDB.
- Enhances security by eliminating public internet exposure.
Memory trick: Endpoints keep your data 'inside the fence' of AWS.