ISC2 Certified Cloud Security Professional (CCSP) Practice Question
A company is building a hybrid architecture where its on-premises edge router will connect to the cloud provider by means of two IPSec VPN tunnels that terminate on different cloud VPN gateways in the same region. Operations wants automatic traffic fail-over if one tunnel goes down and does not want to edit static routes during maintenance. Which customer-side configuration best satisfies these networking requirements?
Create an SSL client VPN connection using IKEv1 and configure static routes to the cloud subnets.
Deploy a VXLAN overlay between on-premises and cloud networks to stretch Layer 2 segments.
Configure two route-based IPSec tunnels and enable BGP peering across each tunnel to exchange routes dynamically.
Build two policy-based IPSec tunnels and use static routes on the router.
Only a route-based IPSec VPN that runs BGP across both tunnels can automatically exchange reachability information and remove or re-add routes when a tunnel state changes. Policy-based VPNs use access-lists tied to crypto-maps, so they need static routes. SSL client VPNs do not support site-to-site dynamic routing. VXLAN extends Layer 2 segments but cannot establish an encrypted WAN overlay with BGP fail-over on its own.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is the difference between policy-based and route-based IPSec VPNs?
Open an interactive chat with Bash
What is BGP peering and why is it important for this hybrid cloud setup?
Open an interactive chat with Bash
Why can't VXLAN or an SSL client VPN be used for dynamic routing or fail-over in this scenario?
Open an interactive chat with Bash
ISC2 Certified Cloud Security Professional (CCSP)
Cloud Platform & Infrastructure Security
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .