AWS Certified Solutions Architect – ProfessionalDesign for New SolutionsMedium

A financial analytics firm is building a new application that processes highly sensitive client data. The application needs to interact with various AWS services, such as Amazon S3, Amazon EC2, and Amazon Kinesis, without ever exposing network traffic to the public internet. The solution must ensure that all communication remains within the AWS network and is fully private. Which networking solution should the architect implement?

  1. AEstablish an AWS Direct Connect connection to an on-premises data center.
  2. BConfigure security groups and network ACLs to restrict inbound and outbound traffic.
  3. CDeploy a NAT Gateway within the VPC and route all traffic through it.
  4. DUtilize VPC Endpoints (Interface and Gateway) for all AWS service access.
Show answer & explanation

Correct answer: D. Utilize VPC Endpoints (Interface and Gateway) for all AWS service access.

VPC Endpoints (both Interface and Gateway) allow private connectivity from a VPC to supported AWS services, ensuring that traffic does not traverse the public internet. This directly meets the requirement for fully private communication of sensitive data.

Why the other options are wrong

  • A. AWS Direct Connect establishes private connectivity to an on-premises data center, but the question specifies private communication *between* the application *and* AWS services, not to an external network.
  • B. Security groups and network ACLs restrict traffic but do not inherently make communication with AWS services private; they still might use public endpoints.
  • C. A NAT Gateway allows instances in a private subnet to connect to the internet or other AWS services, but it still routes traffic through the public internet unless specific VPC endpoints are also used.

VPC Endpoints

A feature that enables private connectivity to AWS services from within a VPC, without requiring an internet gateway, NAT device, VPN, or AWS Direct Connect.

  • Interface Endpoints (powered by AWS PrivateLink) for most services.
  • Gateway Endpoints for S3 and DynamoDB.
  • Traffic remains entirely within the Amazon network.

Memory trick: Endpoints Keep Traffic Enclosed and Private.

More Design for New Solutions questions