A company needs to archive financial data from an on-premises data center to Amazon S3. The company connects on-premises to AWS using Direct Connect with a Direct Connect gateway and a transit gateway. The data must not traverse the public internet and must be encrypted in transit. Which solution satisfies these constraints?
Choose an answer
Tap an option to check your answer.
Correct answer: Establish an IPsec VPN over the transit VIF. Create a VPC attached to the transit gateway and provision an interface VPC endpoint for Amazon S3 in that VPC. Use HTTPS for communication..
Why this is the answer
The correct solution ensures data privacy and encryption. An IPsec VPN over the transit VIF provides an encrypted tunnel from on-premises to the AWS Transit Gateway, preventing data from traversing the public internet. Attaching a VPC to the Transit Gateway and provisioning an interface VPC endpoint for Amazon S3 within that VPC allows private access to S3 without using public IP addresses. HTTPS further encrypts data in transit. Incorrect options: A Direct Connect public VIF routes traffic over the public AWS network, which doesn't guarantee data isolation from the public internet, even with an IPsec VPN on top. Creating a VPC and S3 endpoint without an IPsec VPN over the transit VIF would still send unencrypted data over the Direct Connect connection, not meeting the "encrypted in transit" requirement for the entire path from on-premises. An IPsec VPN over a public VIF to the Transit Gateway still involves the public AWS network. Additionally, S3 access is typically via an endpoint, not directly to a Transit Gateway attachment for S3.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed