A financial analytics firm is building a new application that processes highly sensitive customer financial data. The application will leverage containerized microservices orchestrated by Amazon ECS. The firm has a strict security posture requiring that all data, including temporary processing data, never leaves the firm's private network boundaries, even when interacting with AWS services. Data must be encrypted at rest and in transit, and access to all services must be restricted to specific VPC endpoints. Which networking and security configuration should be implemented?
- ADeploy ECS tasks in public subnets, use service-linked roles for ECS, and rely on AWS Shield for DDoS protection.
- BDeploy ECS tasks in private subnets, use VPC Endpoints for AWS services, enable TLS for inter-service communication, and encrypt EBS volumes.
- CUse NAT Gateway for outbound internet access, Security Groups for ECS tasks, and client-side encryption for S3.
- DUse Internet Gateway for all traffic, Network ACLs for subnets, and AWS WAF for web traffic filtering.
Show answer & explanationAnswer & explanation
Correct answer: B. Deploy ECS tasks in private subnets, use VPC Endpoints for AWS services, enable TLS for inter-service communication, and encrypt EBS volumes.
Deploying ECS tasks in private subnets ensures they are not directly accessible from the internet. VPC Endpoints enable secure, private communication with AWS services without traversing the public internet, satisfying the 'never leaves private network' requirement. Enabling TLS ensures data in transit encryption, and encrypting EBS volumes (or other persistence layers) ensures data at rest encryption.
Why the other options are wrong
- A. Deploying ECS tasks in public subnets exposes them directly to the internet, violating the strict security posture. Service-linked roles are for permissions, and Shield is for DDoS protection, neither addresses the network boundary or data privacy requirements.
- C. NAT Gateway provides outbound internet access, which violates the 'never leaves private network' requirement. Client-side encryption is good but doesn't replace the need for secure private network access to AWS services.
- D. Internet Gateway allows direct internet access, which violates the private network boundary requirement. Network ACLs are good, but WAF is for web traffic and doesn't address the core network isolation or service access requirements.
Private Connectivity to AWS Services
Using AWS networking features like VPC Endpoints to ensure that traffic between resources in a VPC and AWS services (e.g., S3, DynamoDB) remains entirely within the AWS private network, without traversing the public internet.
- VPC Endpoints allow private connections to supported AWS services.
- Eliminates the need for an Internet Gateway, NAT Gateway, or VPN for service access.
- Enhances security by keeping traffic off the public internet.
- Supports both interface endpoints (powered by PrivateLink) and gateway endpoints (S3, DynamoDB).
- Crucial for highly sensitive data and strict compliance requirements.
Memory trick: Keep it private, keep it encrypted, keep it on endpoints.