AWS Certified Solutions Architect – ProfessionalDesign for New SolutionsEasy

A financial institution is building a new application that processes highly sensitive customer data. The application will interact with several AWS services, including Amazon S3, Amazon SQS, and Amazon DynamoDB. The security team mandates that all traffic between the application and these AWS services must remain entirely within the AWS network and never traverse the public internet. Which solution should an architect recommend to meet this security requirement?

  1. AImplement AWS Client VPN to establish encrypted tunnels.
  2. BUtilize AWS PrivateLink to create VPC Endpoints for each service.
  3. CConfigure Security Groups and Network ACLs to restrict outbound traffic.
  4. DRoute all traffic through an AWS Transit Gateway.
Show answer & explanation

Correct answer: B. Utilize AWS PrivateLink to create VPC Endpoints for each service.

AWS PrivateLink enables you to establish private connectivity between your VPCs and AWS services without exposing your traffic to the public internet. VPC Endpoints, powered by PrivateLink, ensure that all communication with supported AWS services remains within the AWS network.

Why the other options are wrong

  • A. AWS Client VPN allows clients to securely access resources in a VPC, but it doesn't ensure that traffic from applications within the VPC to AWS services bypasses the public internet.
  • C. Security Groups and Network ACLs control traffic flow but do not prevent traffic from traversing the public internet if the destination is a public endpoint.
  • D. AWS Transit Gateway helps centralize network connectivity but does not inherently ensure that traffic to public AWS service endpoints remains private unless combined with VPC Endpoints.

VPC Endpoints (AWS PrivateLink)

VPC Endpoints allow you to privately connect your VPC to supported AWS services and VPC endpoint services powered by AWS PrivateLink, without requiring an internet gateway, NAT device, VPN connection, or AWS Direct Connect connection.

  • Traffic between your VPC and the service stays within the Amazon network.
  • Enhances security by eliminating internet exposure.
  • Supports both interface endpoints (ENIs) and gateway endpoints (for S3 and DynamoDB).

Memory trick: VPC Endpoints Keep Data Inside, Safe and Sound.

More Design for New Solutions questions