A company runs an application on Amazon EC2 instances behind an Application Load Balancer (ALB). The company needs secure, VPN-less access to the application and must allow access only when users meet specific security conditions, including device posture. Which solution meets these requirements?
Choose an answer
Tap an option to check your answer.
Correct answer: Configure AWS Verified Access and onboard the application by creating an endpoint for the ALB..
Why this is the answer
AWS Verified Access provides secure, VPN-less access to applications, allowing access only when users meet specific security conditions, including device posture. By creating an endpoint for the ALB in Verified Access, the application becomes accessible through Verified Access, which then evaluates user and device attributes against defined trust providers (e.g., identity providers, device management solutions) before granting access. AWS WAF is a web application firewall that protects against common web exploits, but it does not inherently provide device posture checks or VPN-less access. Amazon Verified Permissions is a fine-grained authorization service that helps define and enforce permissions for application users, but it doesn't handle the secure, VPN-less access or device posture evaluation at the network edge like Verified Access does. The option of configuring Amazon Verified Permissions and onboarding the application by creating an endpoint for the ALB is incorrect because Verified Permissions is an authorization service, not an access service that provides VPN-less access and device posture checks.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed