TechKnowSurge
CompTIA Security+ 3.1 CompTIA SecurityX 3.2 ISC2 CISSP 4.3 NIST 800-53 AC-20
VideoSecurityFree

Customer-to-Cloud Connectivity

Cloud connectivity varies by service model, with SaaS platforms typically accessed via HTTPS through a browser or client app, while IaaS, PaaS, and colocation environments often require direct connections or VPNs for backend infrastructure access.

Complete this video to capture a CTF flag worth 1 point.

About this video

Cloud connectivity is not one-size-fits-all — the appropriate method depends on the type of cloud service model being used and the level of infrastructure access required. SaaS platforms such as Office 365 or Dropbox are typically accessed through a web browser or a lightweight client application, with HTTPS serving as the standard protocol for securing that traffic. This approach is straightforward and works well for end-user-facing applications that do not require direct access to underlying systems. IaaS, PaaS, and colocation environments present a more complex picture, often requiring connectivity that goes beyond standard HTTPS to reach backend infrastructure components directly. Organizations with a headquarters or branch campus that needs reliable, high-performance access to cloud resources have several options available. A direct connection can be purchased through a service provider, establishing a dedicated private link to platforms like AWS, Azure, or Google Cloud without routing traffic over the public internet. Alternatively, a VPN can be used to create an encrypted tunnel through the internet, offering a more accessible but still secure path to cloud infrastructure. A third approach involves colocation facilities that maintain pre-established direct connections to multiple cloud providers, allowing an organization to route traffic through its colocation environment as a centralized hub for cloud access.

What you'll learn

What's covered

Connecting to Cloud Services

Aligned to

CompTIA Security+
3.1 Compare and contrast security implications of different architecture models.
CompTIA SecurityX
3.2 Explain the security requirements and considerations of cloud deployment models.
ISC2 CISSP
4.3 Implement secure communication channels according to design
NIST 800-53
AC-20 Use of External Systems

Key terms

Software as a Service
SaaS
A cloud service model that delivers software applications over the internet on a subscription basis.
Infrastructure as a Service
IaaS
A cloud service model that provides virtualized computing infrastructure over the internet.
Platform as a Service
PaaS
A cloud service model that provides a platform for developing, running, and managing applications without managing infrastructure.
Virtual Private Network
VPN
A technology that creates a secure, encrypted tunnel over a public network to protect data in transit.
Transport Layer Security
TLS
A cryptographic protocol that provides secure communication over a network, successor to SSL.
Colocation
A data center model in which an organization rents physical space, power, cooling, and network connectivity from a third-party facility while retaining ownership of its own servers and equipment.
Direct Connect
A dedicated private network connection between an organization's on-premises infrastructure and a cloud provider such as AWS, Azure, or Google Cloud, bypassing the public internet.
Hypertext Transfer Protocol Secure
HTTPS
The encrypted version of HTTP that wraps web traffic in a TLS session, operating on TCP port 443, so that the data exchanged between a browser and a web server is confidential and cannot be read or modified by an eavesdropper. HTTPS is now the standard for all web traffic, indicated by the padlock icon in a browser.

Topics

Cloud Connectivity Vpn Direct Connect Saas Iaas Paas Cloud Computing Https

Transcript

Connecting to Cloud Services

Nowadays we use a lot of applications and a lot of infrastructure that's up in the cloud. But what does that look like, and how do we connect to it?

One thing to realize is there are a lot of different ways we can make this connection, but generally speaking, certain types of cloud structures will have certain types of connectivity. What do I mean by that?

If it's a SaaS setup right here — this would be like Office 365 or Dropbox — we probably have some sort of client on the end machines, or we're connecting directly into a web portal. So we're largely using HTTPS to connect to that type of structure. Versus if it's IaaS or PaaS, or even colocation: many times we are connecting maybe through HTTPS to certain aspects of it, but a lot of times we also want to connect into the back end infrastructure. To do that, we have some other types of connections besides just HTTPS.

Connecting a Site

For connecting from our end devices into some of these services, largely what we're using is HTTPS. But many times we want to set up our main headquarters, or one of our satellite campuses, to access some of these services. So what does that look like, and how do we access these services?

With some of these services like AWS, Azure and Google Cloud, we could go through some sort of service provider and purchase some sort of direct connection, where we actually get a direct connection — not going through the cloud, not going through the internet, but a direct connection to one of these.

We could also use the cloud and go through a VPN to connect in.

There are also third parties that I've seen where you have set up some sort of private cloud, which essentially is like a colocation. So you set up a colocation and they have direct connections in here, so now you're going through your colocation to get to these different cloud services.

About TechKnowSurge

TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.

Explore free tools and programs →