Courseiva
Network Security, Compliance and GovernanceeasyMultiple ChoiceObjective-mapped

ANS-C01 Network Security, Compliance and Governance Practice Question

A company wants to allow its employees to securely access internal web applications hosted in a VPC without using a VPN. The solution must authenticate users against the company's Active Directory and apply fine-grained access controls. Which AWS service should be used?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

AWS Verified Access

AWS Verified Access is the correct service because it provides secure access to corporate applications hosted in a VPC without requiring a VPN, and it integrates with identity providers such as Active Directory for authentication and fine-grained access control. Option A (AWS SSO) is designed for federating access to AWS accounts and applications, not for securing access to internal VPC-based applications without a VPN. Option C (AWS Client VPN) requires VPN client software and a VPN connection, which does not meet the requirement of not using a VPN. Option D (Application Load Balancer with OIDC authentication) can authenticate users but typically requires the ALB to be publicly accessible or connected via VPN, and it does not provide the same purpose-built zero-trust access capabilities as Verified Access.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • AWS Single Sign-On (SSO)

    Why it's wrong here

    SSO is for AWS accounts, not applications.

  • AWS Verified Access

    Why this is correct

    Provides secure access without VPN, integrates with AD.

  • AWS Client VPN

    Why it's wrong here

    Requires VPN client; not the goal.

  • Application Load Balancer with OIDC authentication

    Why it's wrong here

    Application Load Balancer with OIDC authentication offloads user authentication from backend applications, integrating with OIDC-compliant identity providers like Microsoft Entra ID. However, it does not provide the direct integration with an on-premises Active Directory for fine-grained authorisation required for internal web applications. This option is tempting as it secures web access and supports modern authentication protocols, making it suitable for scenarios where a cloud-based OIDC provider handles identity and the application itself manages granular access.

About these practice questions

One of 1,621 original ANS-C01 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This ANS-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the ANS-C01 exam.