AWS Certified Solutions Architect – Professional (SAP-C02) — Question 467

A software development company has multiple engineers who are working remotely. The company is running Active Directory Domain Services (AD DS) on an Amazon EC2 instance. The company's security policy states that all internal, nonpublic services that are deployed in a VPC must be accessible through a VPN. Multi-factor authentication (MFA) must be used for access to a VPN.

What should a solutions architect do to meet these requirements?

Answer options

Correct answer: B

Explanation

AWS Client VPN is the appropriate service for enabling remote individual users to securely access VPC resources, and it integrates with AD DS via AD Connector to support multi-factor authentication (MFA). Site-to-Site VPN is intended for connecting entire remote networks rather than individual remote workers, making options A and C incorrect. Amazon WorkLink is designed for secure mobile web access rather than full VPC network access, making option D incorrect.