AWS Certified Advanced Networking – Specialty (ANS-C01)Network DesignEasy
A healthcare provider is migrating its critical patient data applications to AWS. The applications are hosted in private subnets across multiple VPCs in the `us-east-2` region. Due to strict compliance requirements (HIPAA), all communication between these applications and shared services (e.g., Amazon S3 for data archival, Amazon CloudWatch for logging) must occur privately, without traversing the public internet. Furthermore, the solution must be simple to deploy and manage. Which AWS networking solution should the provider implement?
- AVPC Peering connections between all application VPCs and a shared services VPC.
- BUtilize VPC Endpoints (Gateway and Interface) for S3 and CloudWatch.
- CEstablish Direct Connect links from each application VPC to AWS services.
- DDeploy NAT Gateways in each private subnet for S3 and CloudWatch access.
Show answer & explanationAnswer & explanation
Correct answer: B. Utilize VPC Endpoints (Gateway and Interface) for S3 and CloudWatch.
VPC Endpoints allow private connections from your VPC to supported AWS services and VPC endpoint services powered by PrivateLink. Gateway Endpoints are for S3 and DynamoDB, enabling private access without exposing traffic to the internet. Interface Endpoints (powered by PrivateLink) are for other services like CloudWatch, providing private IP access via ENIs. This ensures compliance and simplifies management.
Why the other options are wrong
- A. VPC peering connects two VPCs, but it's not designed for private access to AWS services, and managing a full mesh for many application VPCs to a shared services VPC can become complex.
- C. Direct Connect is for connecting on-premises networks to AWS. It's not a solution for private communication between VPCs and AWS services within the AWS network.
- D. NAT Gateways allow instances in private subnets to connect to the internet (including AWS public endpoints), but they do not guarantee private-only communication within the AWS network; traffic still goes over the public internet.
VPC Endpoints (Gateway & Interface)
AWS VPC Endpoints enable private connectivity from your VPC to supported AWS services and VPC endpoint services, ensuring traffic does not traverse the public internet.
- Gateway Endpoints: For S3 and DynamoDB (free).
- Interface Endpoints: For most other AWS services (powered by PrivateLink, incur charges).
- Traffic remains within the AWS network.
- Enhances security and compliance.
- Simplifies network architecture for private service access.
Memory trick: Endpoints are the private door, to AWS services, and nothing more!