AWS Certified Advanced Networking – Specialty (ANS-C01)Network DesignMedium

A global enterprise requires a highly secure and private connection between their on-premises network and AWS, specifically for accessing Amazon S3 and DynamoDB without traversing the public internet. They have multiple VPCs in different accounts, and the solution must be cost-effective and scalable. Which approach should the networking team recommend?

  1. ADeploy AWS Global Accelerator to front S3 and DynamoDB, and connect on-premises via Client VPN.
  2. BUse VPC Peering between all VPCs and create a single NAT Gateway to route traffic to S3 and DynamoDB.
  3. CUtilize AWS Direct Connect with a Direct Connect Gateway, and configure Gateway VPC Endpoints for S3 and Interface VPC Endpoints for DynamoDB.
  4. DSet up a Site-to-Site VPN connection to each VPC and configure VPC endpoints.
Show answer & explanation

Correct answer: C. Utilize AWS Direct Connect with a Direct Connect Gateway, and configure Gateway VPC Endpoints for S3 and Interface VPC Endpoints for DynamoDB.

Direct Connect provides a private, dedicated connection. Direct Connect Gateway allows a single DX connection to reach multiple VPCs. Gateway VPC Endpoints for S3 and Interface VPC Endpoints for DynamoDB ensure private access to these AWS services from within the VPCs, bypassing the public internet while leveraging the private Direct Connect link.

Why the other options are wrong

  • A. Global Accelerator improves internet-based access and Client VPN is for remote users, neither provides private data center connectivity to AWS services bypassing the public internet.
  • B. VPC Peering connects VPCs, but doesn't provide private access to S3/DynamoDB from on-premises, and NAT Gateway is for outbound internet access, not private service access.
  • D. Site-to-Site VPN uses the public internet and connecting each VPC individually is not scalable for multiple VPCs.

Direct Connect with VPC Endpoints

An architecture that uses AWS Direct Connect for a private connection from on-premises to AWS, combined with VPC Endpoints (Gateway for S3, Interface for DynamoDB/others) to privately access AWS services without traversing the public internet.

  • Direct Connect establishes a private link from on-premises to AWS.
  • Direct Connect Gateway enables connectivity to VPCs across regions.
  • Gateway VPC Endpoints provide private access to S3 and DynamoDB.
  • Interface VPC Endpoints provide private access to other services (like DynamoDB API) via ENIs.
  • Ensures data privacy and consistent performance for service access.

Memory trick: Directly Connect your private home to the Cloud's private services.

More Network Design questions