For IndividualsFor Educators
ExpertMinds LogoExpertMinds
ExpertMinds

Ace your certifications with Practice Exams and AI assistance.

  • Browse Exams
  • For Educators
  • Blog
  • Privacy Policy
  • Terms of Service
  • Cookie Policy
  • Support
  • AWS SAA Exam Prep
  • PMI PMP Exam Prep
  • CPA Exam Prep
  • GCP PCA Exam Prep

© 2026 TinyHive Labs. Company number 16262776.

    PracticeAWS Solutions Architect Professional (SAP-C02)AWS Solutions Architect Professional SAP-C02 Practice Exam 2Question 07
    Medium1 markMultiple Choice
    Domain 1.1: Network ConnectivityDirect ConnectEncryptionMACsec

    AWS SAP-C02 · Question 07 · Domain 1.1: Network Connectivity

    A company has a hybrid architecture with a 10 Gbps AWS Direct Connect connection. They need to encrypt all traffic in transit over the Direct Connect link between their on-premises routers and AWS. Which solution meets this requirement with the LEAST operational overhead?

    Answer options:

    A.

    Establish an AWS Site-to-Site VPN over the Direct Connect connection.

    B.

    Enable MACsec on the Direct Connect connection.

    C.

    Deploy third-party virtual firewall appliances in AWS to terminate IPsec tunnels.

    D.

    Use AWS PrivateLink for all traffic.

    How to approach this question

    Identify the native layer 2 encryption option for Direct Connect.

    Full Answer

    B.Enable MACsec on the Direct Connect connection.✓ Correct
    Enable MACsec on the Direct Connect connection.
    MACsec (IEEE 802.1AE) provides point-to-point Layer 2 encryption over Direct Connect, supporting full line rate (10 Gbps or 100 Gbps) without the IPsec tunnel overhead.

    Common mistakes

    Choosing VPN, which limits bandwidth per tunnel and requires complex ECMP setups for 10 Gbps.
    Question 06All questionsQuestion 08

    Practice the full AWS Solutions Architect Professional SAP-C02 Practice Exam 2

    75 questions · hints · full answers · grading

    Sign up freeTake the exam

    More questions from this exam

    Q01A company is setting up a multi-account AWS environment using AWS Organizations. They need to ens...EasyQ02An enterprise needs to connect its on-premises data center to AWS. They require a dedicated, priv...EasyQ03A company wants to share a single AWS Transit Gateway across multiple AWS accounts within their A...EasyQ04An architect needs to design a highly available database architecture that spans multiple AWS Reg...EasyQ05A global financial institution is migrating its core banking application to AWS. The application ...Medium
    View all 75 questions →