Give remote engineers VPN access with MFA through AWS Client VPN

Answer Correct answer: B — Create an AWS Client VPN endpoint with AD integration and MFA enabled so remote engineers connect to the VPC.

A software development company has multiple engineers who are working remotely. The company is running Active Directory Domain Services (AD DS) on an Amazon EC2 instance. The company's security policy states that all internal, nonpublic services that are deployed in a VPC must be accessible through a VPN. Multi-factor authentication (MFA) must be used for access to a VPN. What should a solutions architect do to meet these requirements?

  1. Create an AWS Site-to-Site VPN connection. Configure integration between a VPN and AD DS. Use an Amazon WorkSpaces client with MFA support enabled to establish a VPN connection.
  2. Create an AWS Client VPN endpoint. Create an AD Connector directory for integration with AD DS. Enable MFA for AD Connector. Use AWS Client VPN to establish a VPN connection. Correct Answer
  3. Create multiple AWS Site-to-Site VPN connections by using AWS VPN CloudHub. Configure integration between AWS VPN CloudHub and AD DS. Use AWS Copilot to establish a VPN connection.
  4. Create an Amazon WorkLink endpoint. Configure integration between Amazon WorkLink and AD DS. Enable MFA in Amazon WorkLink. Use AWS Client VPN to establish a VPN connection.

Community Votes

B
100%

100% of anonymous learners picked answer B. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

Client VPN is the AWS service built for individual user access rather than network-to-network connectivity, and it supports MFA natively for users authenticated through AWS Managed Microsoft AD, which is what satisfies both the per-user VPN requirement and the MFA policy in one service.

A software company has engineers working remotely and runs Active Directory Domain Services on an Amazon EC2 instance. Security policy requires all internal nonpublic services deployed in a VPC to be reachable only through a VPN, and MFA must be used for VPN access.

Using a Site-to-Site VPN. A Site-to-Site VPN connects two networks through a virtual private gateway, so individual engineer endpoints cannot terminate a tunnel on it, and it provides no user-level authentication or MFA, which is why the policy about users and MFA cannot be met with it.

Community Discussion (7 comments)

AzureDP900 👍 1
This is no brainer question, B is perfect
kgpoj 👍 1 Selected: B
ACD are wrong. But for B, it is also not perfect. AD Connector is for connecting between ADDS on premises and AWS. In this case, the ADDS is on AWS's EC2. Do you really need AD Connector?
Helpnosense 👍 1
No doubt that answer B will collect all the events from accounts in the organizations. But the requirement is "A solutions architect must design a solution that turns on AWS CloudTrail in all AWS accounts." Can answer B turn on AWS CloudTrail in all AWS accounts.?
Fu7ed 👍 1
Answer is B. Client VPN provides Active Directory support by integrating with AWS Directory Service. Client VPN supports multi-factor authentication (MFA) when it's enabled for AWS Managed Microsoft AD or AD Connector. https://docs.aws.amazon.com/vpn/latest/clientvpn-admin/ad.html C. WHY Copilot? D. Worklink is Provide secure mobile access to your internal websites and web apps.
Dgix 👍 4 Selected: B
A: Site-to-Site VPN is for connecting networks, not giving users access. B is correct. C is rubbish: AWS Copilot is for deploying containers (and it's bloody good!) D is also rubbish: WorkLink is for website and webapp access, not VPN access.
oayoade 👍 2 Selected: B
has to be B
CMMC 👍 4 Selected: B
#A - workspaces client for remote desktop access and not for VPN #C - AWS VPN CloudHub for connecting multiple on-premises or offices, and not for individual VPN connection #D - WorkLink for secure access from mobile devices and not for VPN connection

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

The requirement is per-user access with MFA, which maps directly to AWS Client VPN. Client VPN authenticates users against AWS Directory Service and, when MFA is enabled, users must supply a second factor in addition to their directory credentials, so the MFA policy is satisfied without building anything custom. Engineers install the Client VPN client on their machines and connect, which gives them a route into the VPC from which the internal nonpublic services are reachable, and the corporate AD DS directory provides the identity source so the engineers use their existing corporate accounts. A Site-to-Site VPN cannot do this because it connects networks rather than users.

Why the Other Options Are Wrong

A: A Site-to-Site VPN with a virtual private gateway connects an entire network to the VPC and provides no per-user authentication, so it cannot serve remote engineers individually and it cannot enforce MFA on user access. The WorkSpaces client in the option is also a virtual desktop client rather than a VPN client, so no VPN tunnel is established by the engineer. C: AWS VPN CloudHub combines Site-to-Site VPN connections into a single hub, which serves network-to-network connectivity rather than user access, and AWS Copilot is a tool for deploying containerised applications, not a VPN client, so engineers could not establish a tunnel with it. D: Amazon WorkLink was a managed service for secure browser access to internal web applications and is not a VPN endpoint, so it cannot provide a route to the VPC or integrate AD DS in the way described.

Community Comment Notes

The community voted 100 to 0 for B, and the top-voted comment confirmed that Client VPN supports MFA when enabled for AWS Managed Microsoft AD, which is the mechanism the policy requires. Another commenter raised a fair technical nuance that AD Connector is intended for connecting on-premises AD DS to AWS rather than for AD DS already running on EC2, and also noted that a commenter questioned the framing of the requirement while still accepting B as the only viable option.

Official Reference

Related Analysis

Practice All SAP-C02 Questions

Access 85 questions with complete answers and detailed explanations.

View Full SAP-C02 Practice Test →

← Back to SAP-C02 Study Guide