AWS Certified Solutions Architect Professional SAP-C02 Practice Question

A financial services company uses a 10 Gbps AWS Direct Connect connection for hybrid connectivity between its on-premises data center and a central networking VPC. A new compliance requirement mandates encryption for all data in transit traversing this link. The solution must provide line-rate encryption with minimal performance overhead and integrate natively with the existing high-speed connection. Which approach should a solutions architect recommend?

  • Establish an AWS Site-to-Site VPN connection over a public virtual interface (VIF) on the Direct Connect connection. Route traffic from on-premises to the VPC over the encrypted IPsec tunnel.

  • Enforce application-level encryption using TLS for all communication. Use AWS Certificate Manager (ACM) Private Certificate Authority to issue and manage certificates for all internal clients and servers.

  • Deploy an AWS Network Firewall into the path of the Direct Connect traffic flow and configure stateful rules to only allow encrypted protocols like SSH and HTTPS.

  • Configure the Direct Connect connection to use MACsec (IEEE 802.1AE) security. Work with the network provider to enable MACsec on the on-premises and AWS-side equipment to encrypt traffic at Layer 2.

AWS Certified Solutions Architect Professional SAP-C02
Design for New Solutions
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot