A company wants to configure DNS Security Extensions (DNSSEC) for the company's primary domain. The company registers the domain with Amazon Route 53. The company hosts the domain on Amazon EC2 instances by using BIND.
What is the MOST operationally efficient solution that meets this requirement?
In an AWS environment where a VPC has no internet access and requires communication with AWS services such as Secrets Manager, the most secure method is to use an interface VPC endpoint (AWS PrivateLink). This allows private connectivity to services like Secrets Manager, enabling AWS Lambda functions and other resources within the VPC to access Secrets Manager without requiring an internet gateway, NAT gateway, or VPN connection. Interface VPC endpoints are powered by AWS PrivateLink, a technology that enables private connectivity between AWS services using Elastic Network Interfaces (ENI) with private IPs in your VPCs. This option is more secure than creating a NAT gateway because it doesn't expose the resources to the internet and adheres to the principle of least privilege by providing direct access to only the required service.
Adelina
3 months agoJusta
3 months agoMarge
3 months agoTamra
4 months agoFloyd
4 months agoMickie
4 months agoGeorgiann
4 months agoMelissa
4 months agoAaron
5 months agoEdna
5 months agoCorrinne
5 months agoGlory
5 months agoVelda
5 months agoBenton
5 months agoDorsey
5 months agoTy
5 months agoMichel
5 months agoLuisa
10 months agoAmmie
9 months agoSalena
9 months agoGilma
9 months agoEzekiel
10 months agoMalinda
10 months agoSerina
10 months agoLatricia
10 months agoJesusa
9 months agoYuette
9 months agoJospeh
10 months agoOrville
10 months agoSerina
11 months agoDierdre
11 months agoJodi
11 months agoDonte
11 months ago