Virtual Private Cloud (VPC)

A logically isolated network inside a public cloud, whose address ranges, subnets, routing and filtering rules are defined and configured by the customer.

A Virtual Private Cloud is a logically isolated network carved out of a public cloud provider’s shared infrastructure. The customer chooses its private address ranges, subnets, routing and filtering rules. Filtering may be offered at more than one level, for example per instance and per subnet. The ISC2 exam outline names the VPC as its own item in Domain 4.

The name misleads. A VPC is not a private cloud, which in NIST SP 800-145 is a deployment model where the infrastructure serves one organisation alone; a VPC runs on hardware other customers share. Under shared responsibility the provider supplies and maintains the isolation, and the customer owns the configuration inside it. That is where failures tend to arise: one misconfigured route or rule can expose whatever it reaches. Connections out of a VPC commonly use a site-to-site VPN back to the organisation or peering with another VPC, and each connection extends the trust boundary. Inside it, subnetting and filtering provide network segmentation in the usual way.

Exam relevance: questions in this area tend to turn on who is responsible for what. Candidates are expected to keep the provider’s isolation apart from the customer’s configuration, and to recognise a misconfigured route or rule, not the cloud itself, as the likely cause of an exposure in a scenario.