AWS Certified Solutions Architect – Associate (SAA-C03)Design Secure ArchitecturesHard
An organization is migrating sensitive payment processing applications to AWS. These applications require a highly secure, isolated network environment that is logically separated from other corporate networks and the internet. They also need to establish a dedicated, private network connection to AWS from their on-premises data center. Which combination of AWS networking services should a Solutions Architect recommend to meet these requirements?
- AVPC with private subnets only, VPC Endpoints, and AWS Direct Connect.
- BVPC with private subnets only, NAT Gateway, and AWS Direct Connect.
- CVPC with public and private subnets, VPC Peering, and Transit Gateway.
- DVPC with public and private subnets, Internet Gateway, and VPN Connection.
Show answer & explanationAnswer & explanation
Correct answer: A. VPC with private subnets only, VPC Endpoints, and AWS Direct Connect.
A VPC with private subnets ensures logical isolation. AWS Direct Connect provides a dedicated, private network connection to AWS, bypassing the internet. VPC Endpoints allow private access to AWS services (like S3, DynamoDB) from within the VPC without traversing the internet or a NAT Gateway, enhancing security and isolation.
Why the other options are wrong
- B. A NAT Gateway allows instances in private subnets to access the internet, which violates the 'isolated from the internet' requirement for highly sensitive applications. Direct Connect is good, but NAT Gateway is a problem.
- C. VPC Peering and Transit Gateway are for connecting multiple VPCs, not for providing a dedicated on-premises connection or for isolating from the internet. Public subnets are also a problem.
- D. An Internet Gateway and public subnets expose resources to the internet, violating the isolation requirement. VPN connections use the internet, not a dedicated private connection.
Secure Isolated AWS Network
Creating a highly secure and isolated network environment in AWS, often involving private subnets, Direct Connect, and VPC Endpoints.
- Private subnets host resources isolated from public internet.
- AWS Direct Connect provides dedicated, private network link to AWS.
- VPC Endpoints enable private access to AWS services without internet exposure.
Memory trick: VPC's Private Endpoints Directly Connect.