AWS Certified Cloud Practitioner (CLF-C02)Cloud Technology and ServicesMedium
A company is designing a new application that will process sensitive customer data. They need to ensure that all network traffic between their EC2 instances and an Amazon S3 bucket remains entirely within the AWS network and does not traverse the public internet. This connection must be private and secure. Which AWS service or feature enables this?
- AInternet Gateway
- BVPC Peering
- CVPC Endpoints
- DNAT Gateway
Show answer & explanationAnswer & explanation
Correct answer: C. VPC Endpoints
VPC Endpoints enable you to privately connect your VPC to supported AWS services and VPC endpoint services powered by PrivateLink without requiring an internet gateway, NAT device, VPN connection, or AWS Direct Connect connection. For S3, you would use a Gateway Endpoint, which allows instances in your VPC to access S3 directly and privately within the AWS network.
Why the other options are wrong
- A. An Internet Gateway allows communication between instances in a public subnet and the public internet, which explicitly violates the 'does not traverse the public internet' requirement.
- B. VPC Peering connects two VPCs privately, but not a VPC to an AWS service like S3.
- D. A NAT Gateway allows instances in private subnets to initiate outbound connections to the internet, also violating the 'does not traverse the public internet' requirement for S3 access.
VPC Endpoints
A feature that enables you to privately connect your VPC to supported AWS services and VPC endpoint services powered by AWS PrivateLink without requiring an internet gateway, NAT device, VPN connection, or AWS Direct Connect connection.
- Keeps traffic entirely within the AWS network.
- Enhances security by eliminating exposure to the public internet.
- Two types: Interface Endpoints (powered by PrivateLink) and Gateway Endpoints (for S3 and DynamoDB).
Memory trick: Endpoint: End the public path, point to private.