A cloud application uses a managed API gateway to expose REST APIs. The security team wants to ensure that clients cannot bypass the gateway and call backend services directly. The backend services run on private subnets and are fronted by an internal load balancer. Which control should be implemented to enforce this requirement?
Restricting backend ingress to the API gateway's identity ensures that only the gateway can forward requests. This can be done with security groups, network ACLs, or IAM-based authentication depending on the cloud provider. It directly prevents clients from bypassing the gateway, because direct calls from other sources are denied at the network or identity layer.
Why this answer
The only way to prevent clients from bypassing the API gateway is to restrict backend ingress to the gateway's identity. This can be enforced through security groups, network policies, or IAM roles. mTLS, WAFs, and gateway-only API key validation add security but do not block direct network access, so they cannot guarantee that all traffic flows through the gateway.
Exam trap
The trap here is assuming that mTLS or API keys at the gateway prevent bypass, when network-level or identity-level restrictions on the backend are required.