Hard1 markMultiple Choice

AWS SAP-C02 · Question 18 · Domain 1.1: Network Connectivity

An architecture requires connecting a VPC to an on-premises data center via AWS VPN. The on-premises firewall only supports policy-based VPNs. Which TWO limitations must the architect consider? (Select TWO)

Answer options:

A.

Policy-based VPNs limit the connection to a single IPsec security association (SA) pair.

B.

Policy-based VPNs support BGP dynamic routing.

C.

Policy-based VPNs can utilize AWS Transit Gateway ECMP for higher bandwidth.

D.

Only one CIDR block from the VPC can be routed to one CIDR block on-premises over the VPN.

E.

Policy-based VPNs do not support AES-256 encryption.

F.

AWS does not support policy-based VPNs.

How to approach this question

Recall the specific limitations of policy-based vs route-based VPNs in AWS.

Full Answer

A,D
AWS Site-to-Site VPN supports policy-based VPNs, but restricts them to a single Security Association (SA). This means you can only define one pair of local and remote CIDR blocks.

Common mistakes

Assuming policy-based VPNs support dynamic routing or multiple subnets easily.

Practice the full AWS Solutions Architect Professional SAP-C02 Practice Exam 2

75 questions · hints · full answers · grading

More questions from this exam