A company sends application logs to an Amazon OpenSearch Service cluster deployed inside a VPC. All data must remain inside the VPC. Developers need to access OpenSearch from their local developer machines: some work from home, others from three company office locations. Which solution allows secure direct access from developers' local machines to the OpenSearch cluster in the VPC?
Choose an answer
Tap an option to check your answer.
Correct answer: Provision an AWS Client VPN endpoint and associate it with a subnet in the VPC. Configure the Client VPN self-service portal and have developers connect using the Client VPN client..
Why this is the answer
AWS Client VPN provides secure, direct access to resources within a VPC from anywhere. By provisioning a Client VPN endpoint and associating it with a subnet in the VPC, developers can connect from their local machines using the Client VPN client, ensuring all traffic remains within the VPC. The self-service portal simplifies client configuration. Other options are less suitable: Site-to-Site VPN is for connecting entire networks (e.g., an office network to AWS), not individual developer machines. Direct Connect is for dedicated network connections between on-premises data centers and AWS, not for individual remote users. A public VIF would also expose traffic to the public internet, violating the "data must remain inside the VPC" requirement. A bastion host would require developers to SSH into an EC2 instance and then connect to OpenSearch, adding an unnecessary hop and potential bottleneck, and not providing direct access.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed