Hard1 markMultiple Choice
Domain 1.1: Network ConnectivityNetworkingDirect ConnectVPN

AWS SAP-C02 · Question 72 · Domain 1.1: Network Connectivity

An enterprise wants to establish a dedicated, private connection to AWS. They require high availability and encryption in transit. Which THREE components are required to build a highly available, encrypted hybrid network? (Select THREE)

Answer options:

A.

Two AWS Direct Connect connections in different locations.

B.

AWS Site-to-Site VPN configured over the Direct Connect connections.

C.

An AWS Transit Gateway or Virtual Private Gateway.

D.

AWS Client VPN.

E.

A single Direct Connect connection with MACsec.

F.

AWS PrivateLink.

How to approach this question

Combine DX for private connectivity with VPN for encryption.

Full Answer

Two AWS Direct Connect connections in different locations., AWS Site-to-Site VPN configured over the Direct Connect connections., An AWS Transit Gateway or Virtual Private Gateway.
To achieve a highly available, encrypted connection, you provision redundant Direct Connect connections and run IPsec VPNs over them (Public VIF or Transit VIF) terminating at a TGW or VGW.

Common mistakes

Thinking Direct Connect is encrypted by default (it is not, unless MACsec is used).

Practice the full AWS Solutions Architect Professional SAP-C02 Practice Exam 3

75 questions · hints · full answers · grading

More questions from this exam