Your question is Secure Cross-Network DB Access in AWS. Take a moment with it on the right.
Talk me through your thinking if you like. When you're confident, submit your answer and I'll grade it like a real screen (7/10 or better passes).
In an AWS architecture where a database instance is placed within a private subnet and protected by a security group, how can a developer securely connect to it from outside the VPC or from a different network segment?