AWS Certified Solutions Architect – ProfessionalDesign for New SolutionsMedium

A financial analytics firm is building a new application that processes highly sensitive customer data. The application needs to connect to various AWS services (e.g., Amazon S3, Amazon DynamoDB, Amazon SQS) without routing traffic over the public internet, ensuring maximum security and compliance. The firm also requires that all traffic to these services remains within the AWS network. Which networking solution should the firm implement?

  1. ASet up a VPN connection from the application's VPC to each AWS service endpoint.
  2. BDeploy an EC2 instance as a NAT Gateway to route private traffic to AWS services.
  3. CConfigure VPC Endpoints (Interface Endpoints and Gateway Endpoints) for the required AWS services.
  4. DUse AWS Direct Connect to establish private connectivity to AWS services.
Show answer & explanation

Correct answer: C. Configure VPC Endpoints (Interface Endpoints and Gateway Endpoints) for the required AWS services.

VPC Endpoints allow private connections from a VPC to supported AWS services without requiring traffic to traverse the public internet. Interface Endpoints (powered by AWS PrivateLink) are used for most AWS services (DynamoDB, SQS), providing private IP addresses for service access. Gateway Endpoints are specifically used for Amazon S3 and DynamoDB (though Interface Endpoints for DynamoDB are also available and often preferred for PrivateLink features). This solution ensures all traffic remains within the AWS network, meeting the security and compliance requirements.

Why the other options are wrong

  • A. VPN connections are typically used for connecting an on-premises network to a VPC, not for connecting within AWS between a VPC and AWS services.
  • B. NAT Gateways allow instances in a private subnet to connect to the internet or other AWS services over the internet, which violates the requirement to keep traffic off the public internet.
  • D. AWS Direct Connect establishes a dedicated network connection from an on-premises data center to AWS, but it's not the primary solution for connecting applications within a VPC to AWS services privately.

Private Connectivity to AWS Services

Methods to access AWS services from within a VPC without traversing the public internet, enhancing security and compliance.

  • VPC Endpoints enable private access to AWS services.
  • Interface Endpoints (PrivateLink) provide private IPs.
  • Gateway Endpoints are for S3 and DynamoDB (legacy for DynamoDB).

Memory trick: VPC Endpoints create a private tunnel, keeping sensitive data off the public road.

More Design for New Solutions questions