A bank is designing a new payment API that must run in a public cloud. The security team wants the application to run in an isolated, logically separated section of the provider's network where the bank controls inbound and outbound traffic, defines its own IP addressing, and can connect privately to the provider's object storage without traversing the internet. Which cloud architecture construct should the bank use?
A virtual private cloud gives the bank a logically isolated network in which it defines its own address ranges, subnets, route tables, and gateways. Private subnets keep the payment API off the public internet while security groups and network ACLs control traffic. A service endpoint lets the VPC reach the provider's object storage over the provider's private backbone instead of the public internet, satisfying the private-connectivity requirement.
Why this answer
The requirement combines network isolation, customer-defined addressing and traffic control, and private access to a provider service. A virtual private cloud supplies the isolated network and its subnets, route tables, and gateways; security groups and network ACLs provide the traffic control; and a service endpoint keeps storage traffic on the provider backbone. Content delivery, web application firewalls, and hardware security modules address latency, application attacks, and key protection, not network isolation.
Exam trap
The trap here is treating a security appliance such as a web application firewall or hardware security module as if it establishes network isolation, when isolation comes from the virtual network construct itself.