A software company has remote engineers. Active Directory Domain Services (AD DS) runs on an EC2 instance. Company policy requires that all internal, nonpublic services in the VPC be accessible only via a VPN and that VPN access require multi‑factor authentication (MFA). What should a solutions architect implement to satisfy these requirements?
Choose an answer
Tap an option to check your answer.
Correct answer: Deploy an AWS Client VPN endpoint. Configure an AD Connector directory that integrates with the existing AD DS and enable MFA for AD Connector. Use AWS Client VPN for user connections..
Why this is the answer
The correct solution is to deploy an AWS Client VPN endpoint. This service is designed for remote access to AWS resources and on-premises networks. Integrating it with an AD Connector directory allows the existing AD DS to authenticate users, and enabling MFA on the AD Connector satisfies the multi-factor authentication requirement for VPN access. Users then connect using the AWS Client VPN. Incorrect options: AWS Site-to-Site VPN is primarily for connecting entire networks (e.g., on-premises data centers to AWS VPCs), not individual remote users. Using an Amazon WorkSpaces client for VPN connection is not standard practice for general remote access. AWS VPN CloudHub is for connecting multiple on-premises sites to AWS, not for individual remote user access. AWS Copilot is a tool for deploying containerized applications, not for establishing VPN connections. Amazon WorkLink provides secure access to internal websites and web applications, not general network access to internal services. While it supports MFA, it doesn't fulfill the requirement for VPN access to all internal nonpublic services.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed