Medium1 markMultiple Choice
Domain 3.4: Network PerformanceDomain 3PerformanceDirect ConnectVPN

AWS SAA-C03 · Question 50 · Domain 3.4: Network Performance

A company is migrating a large database from its on-premises data center to AWS. The migration requires a dedicated, high-speed network connection. However, the company's security policy mandates that all data in transit must be encrypted using IPsec. How can a solutions architect meet both requirements?

Answer options:

A.

Use AWS Direct Connect with MACsec encryption.

B.

Configure an AWS Site-to-Site VPN over the public internet.

C.

Configure an AWS Site-to-Site VPN over an AWS Direct Connect connection.

D.

Use AWS DataSync with TLS encryption.

How to approach this question

Combine Direct Connect (dedicated/high-speed) with VPN (IPsec encryption).

Full Answer

C.Configure an AWS Site-to-Site VPN over an AWS Direct Connect connection.✓ Correct
Configure an AWS Site-to-Site VPN over an AWS Direct Connect connection.
AWS Direct Connect provides a dedicated, private network connection with consistent high performance. However, Direct Connect alone does not encrypt data in transit. To meet the IPsec requirement, you can configure an AWS Site-to-Site VPN connection over the Direct Connect link.

Common mistakes

Assuming Direct Connect is encrypted by default, or choosing MACsec when IPsec is explicitly requested.

Practice the full AWS SAA-C03 Practice Exam 1

65 questions · hints · full answers · grading

More questions from this exam