AWS Certified Cloud Practitioner (CLF-C02)Cloud Technology and ServicesMedium
A global enterprise needs to securely connect its on-premises data centers to its Amazon VPCs without sending traffic over the public internet. The solution must support multiple network connections and provide high availability. Which AWS service should the enterprise use?
- AAWS VPN
- BAWS Direct Connect
- CAmazon CloudFront
- DVPC Peering
Show answer & explanationAnswer & explanation
Correct answer: B. AWS Direct Connect
AWS Direct Connect provides a dedicated private network connection from an on-premises data center to AWS, bypassing the public internet. This offers increased bandwidth throughput and a more consistent network experience compared to internet-based VPN connections, while also enhancing security for sensitive traffic.
Why the other options are wrong
- A. AWS VPN (Site-to-Site VPN) uses IPsec tunnels over the public internet, which does not meet the requirement of avoiding the public internet.
- C. Amazon CloudFront is a content delivery network (CDN) service used for caching and delivering content, not for private connectivity between on-premises and VPCs.
- D. VPC Peering connects two VPCs within AWS, not an on-premises data center to a VPC.
AWS Direct Connect
A cloud service solution that links your internal network to AWS Direct Connect locations, bypassing the public internet.
- Establishes a dedicated network connection.
- Reduces network costs, increases bandwidth throughput, and provides a more consistent network experience.
- Supports all AWS services accessible over the public internet.
Memory trick: Direct Connect is the 'private highway' to AWS.