Site-to-Site VPN creates an encrypted tunnel over the public internet between your on-premises network and your VPC — a fast-to-set-up way to connect a data center to AWS.
VPN vs Direct Connect
Site-to-Site VPN is quick and cheap but runs over the internet, so performance varies. Direct Connect is a dedicated private line — consistent and high-bandwidth but slower to provision and pricier. Need connectivity today over the internet? VPN. Need consistent high performance? Direct Connect (often with a VPN backup).
Test yourself
A company needs an encrypted connection between its data center and AWS set up quickly, and can tolerate variable internet performance. What fits best?
- AWS Direct Connect
- AWS Site-to-Site VPN
- A NAT gateway
- VPC peering
👉 Click to reveal the answer & explanation
Correct answer: B. Site-to-Site VPN provides an encrypted tunnel over the internet that’s fast to set up — ideal when performance variance is acceptable. Direct Connect (A) is a dedicated line that takes time to provision; NAT (C) is outbound internet; peering (D) connects VPCs.
Related topics
Direct Connect · Amazon VPC · Transit Gateway
Ready to pass the AWS Solutions Architect Associate (SAA-C03)?
Stop guessing whether you’re ready. Our full-length, exam-realistic practice exams put you through the exact question style you’ll face — with a detailed explanation behind every answer, so you learn why, not just what.
- ✓ 6 full-length practice exams
- ✓ A detailed explanation for every single question
- ✓ Realistic, scenario-based questions — not memory dumps
- ✓ Lifetime access, kept current for 2026
Get the SAA-C03 Practice Exams →or try 25 free questions first