- To encrypt data in transit
- To provide private access to AWS services within a VPC
- To manage network access control lists
- To monitor API calls