Site-to-Site VPN creates an encrypted tunnel over the public internet between your on-premises network and your VPC — a fast-to-set-up way to connect a data center to AWS.

VPN vs Direct Connect

Site-to-Site VPN is quick and cheap but runs over the internet, so performance varies. Direct Connect is a dedicated private line — consistent and high-bandwidth but slower to provision and pricier. Need connectivity today over the internet? VPN. Need consistent high performance? Direct Connect (often with a VPN backup).

Test yourself

Practice question

A company needs an encrypted connection between its data center and AWS set up quickly, and can tolerate variable internet performance. What fits best?

  1. AWS Direct Connect
  2. AWS Site-to-Site VPN
  3. A NAT gateway
  4. VPC peering
👉 Click to reveal the answer & explanation

Correct answer: B. Site-to-Site VPN provides an encrypted tunnel over the internet that’s fast to set up — ideal when performance variance is acceptable. Direct Connect (A) is a dedicated line that takes time to provision; NAT (C) is outbound internet; peering (D) connects VPCs.

Related topics

Direct Connect · Amazon VPC · Transit Gateway

CloudExamPro Premium

Ready to pass the AWS Solutions Architect Associate (SAA-C03)?

Stop guessing whether you’re ready. Our full-length, exam-realistic practice exams put you through the exact question style you’ll face — with a detailed explanation behind every answer, so you learn why, not just what.

  • ✓  6 full-length practice exams
  • ✓  A detailed explanation for every single question
  • ✓  Realistic, scenario-based questions — not memory dumps
  • ✓  Lifetime access, kept current for 2026

Get the SAA-C03 Practice Exams →or try 25 free questions first

Limited-time offer · ends in --Days:--Hrs:--Min:--Sec
Get Instant Access