AWS Certified Cloud Practitioner (CLF-C02)Cloud Technology and ServicesMedium
A company is designing a new application that will process sensitive customer data. They need to ensure that their EC2 instances can securely access Amazon S3 buckets without traversing the public internet. Which AWS networking component should they use to achieve this?
- AInternet Gateway
- BVPC Endpoint
- CDirect Connect
- DNAT Gateway
Show answer & explanationAnswer & explanation
Correct answer: B. VPC Endpoint
VPC Endpoints allow private connections from your VPC to supported AWS services and VPC endpoint services powered by PrivateLink, ensuring that traffic to these services does not leave the Amazon network.
Why the other options are wrong
- A. An Internet Gateway allows resources in a public subnet to connect to the internet, which would expose traffic to the public internet.
- C. AWS Direct Connect provides a dedicated private connection from an on-premises data center to AWS, which is not relevant for EC2 instances within a VPC accessing S3 privately.
- D. A NAT Gateway allows instances in a private subnet to initiate outbound connections to the internet but prevents inbound connections, still involving the public internet.
VPC Endpoint
A feature that enables you to privately connect your VPC to supported AWS services and VPC endpoint services without requiring an internet gateway, NAT device, VPN connection, or AWS Direct Connect connection.
- Private connection to AWS services (e.g., S3, DynamoDB)
- Traffic stays within the Amazon network
- Enhances security by avoiding the public internet
- Two types: Interface Endpoints and Gateway Endpoints
Memory trick: VPC Endpoint, a private gate, connects services, seals your fate (securely).