Answer – D
The AWS Documentation mentions the following.
You can use AWS Direct Connect to establish a dedicated network connection within your network to create a logical connection to public AWS resources, such as an Amazon virtual private gateway IPsec endpoint. This solution combines the AWS managed benefits of the VPN solution with low latency, increased bandwidth, consistency and an end-to-end, secure connection.
Options A and B are incorrect since just having a VIF alone will not work.
Option C is incorrect since accessing on-premises network needs a VPN connection over public VIF.For more information on such a connectivity option, please refer to the below URL
https://docs.aws.amazon.com/aws-technical-content/latest/aws-vpc-connectivity-options/aws-direct-connect-plus-vpn-network-to-amazon.html
Please also refer to page 741 on the below link on the section "Data Protection in DynamoDB" - the first two paragraphs.
https://docs.aws.amazon.com/amazondynamodb/latest/developerguide/dynamodb-dg.pdf