Give remote engineers VPN access with MFA through AWS Client VPN
A software development company has multiple engineers who are working remotely. The company is running Active Directory Domain Services (AD DS) on an Amazon EC2 instance. The company's security policy states that all internal, nonpublic services that are deployed in a VPC must be accessible through a VPN. Multi-factor authentication (MFA) must be used for access to a VPN. What should a solutions architect do to meet these requirements?
Community Votes
100% of anonymous learners picked answer B. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
Client VPN is the AWS service built for individual user access rather than network-to-network connectivity, and it supports MFA natively for users authenticated through AWS Managed Microsoft AD, which is what satisfies both the per-user VPN requirement and the MFA policy in one service.
A software company has engineers working remotely and runs Active Directory Domain Services on an Amazon EC2 instance. Security policy requires all internal nonpublic services deployed in a VPC to be reachable only through a VPN, and MFA must be used for VPN access.
Using a Site-to-Site VPN. A Site-to-Site VPN connects two networks through a virtual private gateway, so individual engineer endpoints cannot terminate a tunnel on it, and it provides no user-level authentication or MFA, which is why the policy about users and MFA cannot be met with it.
Community Discussion (7 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
The requirement is per-user access with MFA, which maps directly to AWS Client VPN. Client VPN authenticates users against AWS Directory Service and, when MFA is enabled, users must supply a second factor in addition to their directory credentials, so the MFA policy is satisfied without building anything custom. Engineers install the Client VPN client on their machines and connect, which gives them a route into the VPC from which the internal nonpublic services are reachable, and the corporate AD DS directory provides the identity source so the engineers use their existing corporate accounts. A Site-to-Site VPN cannot do this because it connects networks rather than users.Why the Other Options Are Wrong
A: A Site-to-Site VPN with a virtual private gateway connects an entire network to the VPC and provides no per-user authentication, so it cannot serve remote engineers individually and it cannot enforce MFA on user access. The WorkSpaces client in the option is also a virtual desktop client rather than a VPN client, so no VPN tunnel is established by the engineer. C: AWS VPN CloudHub combines Site-to-Site VPN connections into a single hub, which serves network-to-network connectivity rather than user access, and AWS Copilot is a tool for deploying containerised applications, not a VPN client, so engineers could not establish a tunnel with it. D: Amazon WorkLink was a managed service for secure browser access to internal web applications and is not a VPN endpoint, so it cannot provide a route to the VPC or integrate AD DS in the way described.Community Comment Notes
The community voted 100 to 0 for B, and the top-voted comment confirmed that Client VPN supports MFA when enabled for AWS Managed Microsoft AD, which is the mechanism the policy requires. Another commenter raised a fair technical nuance that AD Connector is intended for connecting on-premises AD DS to AWS rather than for AD DS already running on EC2, and also noted that a commenter questioned the framing of the requirement while still accepting B as the only viable option.Official Reference
Related Analysis
Practice All SAP-C02 Questions
Access 85 questions with complete answers and detailed explanations.
View Full SAP-C02 Practice Test →