A software engineering team at a global enterprise uses a dedicated AWS account that is connected to the company's on-premises data center via two AWS Direct Connect connections. The account is configured so that all non-VPC-bound traffic routes through a virtual private gateway. A developer has recently deployed a new AWS Lambda function using the AWS Management Console. This function must securely access a database hosted in the private subnet of the on-premises data center. What is the most appropriate configuration to enable this access?