AWS Certified Solutions Architect Professional SAP-C02 Practice Question

A financial-services company exchanges personally identifiable information (PII) with an AWS workload that runs in a private VPC. The company currently uses a single 10 Gbps dedicated AWS Direct Connect private virtual interface that terminates on its on-premises core router. New regulatory requirements mandate that all PII in transit across the hybrid link must be encrypted. The solution must preserve at least 8 Gbps of throughput, add as little operational overhead as possible, and avoid any application-level changes.

Which approach meets these requirements?

  • Configure an AWS Site-to-Site VPN connection with two IPsec tunnels over the Direct Connect link and route all traffic through the VPN.

  • Implement TLS encryption at the application layer for every service that exchanges PII over the Direct Connect link.

  • Order a second 10 Gbps dedicated Direct Connect at a different location and enable BGP MD5 authentication on both connections.

  • Enable MAC Security (MACsec) on the existing 10 Gbps dedicated Direct Connect port and configure matching MACsec parameters on the on-premises router.

AWS Certified Solutions Architect Professional SAP-C02
Design Solutions for Organizational Complexity
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot