An external consultant needs to use a laptop to access two VPCs that are peered in the same AWS Region. The company wants to grant access only to these VPCs without exposing other network resources. Which solution should be used?
Choose an answer
Tap an option to check your answer.
Correct answer: Create an AWS Client VPN endpoint in the Region. Configure access with the appropriate subnet association and authorization rules..
Why this is the answer
An AWS Client VPN endpoint is the correct solution because it allows remote users to securely access AWS resources from their local machine. It provides a managed VPN service that can be configured to allow access only to specific VPCs and subnets, meeting the requirement to restrict access to only the two peered VPCs. The consultant can connect directly from their laptop. AWS Site-to-Site VPN is for connecting entire networks (e.g., on-premises data centers) to AWS, not individual users. AWS Resource Access Manager (RAM) VPC sharing is for sharing subnets within a VPC across AWS accounts, not for providing remote access to external users. A gateway VPC endpoint provides private connectivity to AWS services from within a VPC, not remote access for external users.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed