exam questions

Exam AWS Certified Advanced Networking - Specialty ANS-C01 All Questions

View all questions & answers for the AWS Certified Advanced Networking - Specialty ANS-C01 exam

Exam AWS Certified Advanced Networking - Specialty ANS-C01 topic 1 question 18 discussion

A company is planning a migration of its critical workloads from an on-premises data center to Amazon EC2 instances. The plan includes a new 10 Gbps AWS Direct Connect dedicated connection from the on-premises data center to a VPC that is attached to a transit gateway. The migration must occur over encrypted paths between the on-premises data center and the AWS Cloud.
Which solution will meet these requirements while providing the HIGHEST throughput?

  • A. Configure a public VIF on the Direct Connect connection. Configure an AWS Site-to-Site VPN connection to the transit gateway as a VPN attachment.
  • B. Configure a transit VIF on the Direct Connect connection. Configure an IPsec VPN connection to an EC2 instance that is running third-party VPN software.
  • C. Configure MACsec for the Direct Connect connection. Configure a transit VIF to a Direct Connect gateway that is associated with the transit gateway.
  • D. Configure a public VIF on the Direct Connect connection. Configure two AWS Site-to-Site VPN connections to the transit gateway. Enable equal-cost multi-path (ECMP) routing.
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Untamables
Highly Voted 1 year, 8 months ago
Selected Answer: C
C https://docs.aws.amazon.com/directconnect/latest/UserGuide/MACsec.html
upvoted 11 times
...
silviahdz
Highly Voted 1 year, 8 months ago
Selected Answer: C
C is correct, highest bps plus encryption
upvoted 6 times
...
ForDummies
Most Recent 4 months ago
I really hope not find some question like that, because I only can see mistakes. Macsec is used on L2L using layer 02 or direct connection (collocation feat AWS), like clear channel circuit, because you can see another mac address. But if you're using MPLS connection by AWS partner, it's not possible to use it. You can use VPN over DX, and you'll not suffer with latency or throughput, but it's necessary to use a virtual private gateway. https://docs.aws.amazon.com/whitepapers/latest/aws-vpc-connectivity-options/aws-direct-connect-site-to-site-vpn.html Related: AWS Direct Connect and AWS Site-to-Site VPN
upvoted 1 times
...
Raphaello
8 months, 3 weeks ago
Selected Answer: C
C is the correct answer here. MACSec at L2 provides highest throughput when compared to IPSEC VPN tunnels.
upvoted 1 times
...
Marfee400704
10 months, 1 week ago
I think that it's correct answer is C according to SPOTO products.
upvoted 1 times
...
Marfee400704
10 months, 1 week ago
I think that it's correct answer is C according to SPOTO products.
upvoted 1 times
...
marfee
10 months, 2 weeks ago
I think that it's correcty answer is C.
upvoted 1 times
...
AmSpOkE
10 months, 2 weeks ago
C as it says "Highest" throughtput, anything with VPN is limited to 1,25Gbps per tunnel
upvoted 2 times
...
Snape
11 months, 1 week ago
Selected Answer: C
Options A and D are wrong because involvement of using VPN which can add admin overhead Option B IPsec VPN connection + third-party VPN software not as performant as MACsec-encrypted connection directly on the Direct Connect link.
upvoted 1 times
...
Arad
1 year, 1 month ago
Selected Answer: C
For sure C
upvoted 1 times
...
WMF0187
1 year, 3 months ago
Option C is the solution that will provide the highest throughput while meeting the requirement for an encrypted path between the on-premises data center and the AWS Cloud. Here's why: MACsec (Media Access Control Security): MACsec provides a layer 2 encryption mechanism, encrypting the entire Ethernet frame between the on-premises data center and the AWS Cloud. It offers high throughput while encrypting the data at the link layer. Transit VIF and Direct Connect Gateway: By configuring a transit VIF on the Direct Connect connection, you can connect it directly to a Direct Connect gateway associated with the transit gateway. This architecture allows you to efficiently route traffic to multiple VPCs attached to the transit gateway. Option D: While using AWS Site-to-Site VPN connections with ECMP routing can provide redundancy, it may not offer the highest throughput compared to MACsec over a dedicated 10 Gbps Direct Connect connection.
upvoted 1 times
...
DPDK
1 year, 5 months ago
C because VPN's throughput is far lower than DX. We should not use VPN to achieve HIGHEST throughput
upvoted 2 times
...
demoras
1 year, 6 months ago
Selected Answer: C
C is correct, highest bps plus encryption
upvoted 2 times
...
dman
1 year, 8 months ago
Macsec does not extend until TGW its point to point, its would be only until the AWS DX router. Tricky one im more inclined to D
upvoted 1 times
albertkr
1 year, 7 months ago
it does not say it has to extend until the VPC. it just says until AWS Cloud for which i assume it is until AWS DX router where it is the boundary to AWS Cloud
upvoted 1 times
...
...
ohcan
1 year, 8 months ago
Selected Answer: C
MacSEC always provide more throughput than two IPsec tunnels that will reach only 1.5Gb each
upvoted 4 times
tcp22
1 year, 6 months ago
it's 1.25 total of 2.5 for 2 tunnels
upvoted 2 times
...
...
ITgeek
1 year, 8 months ago
Selected Answer: C
is Correct
upvoted 2 times
...
study_aws1
1 year, 8 months ago
Does MACSec work with Transit VIF is the key here.
upvoted 1 times
that1guy
1 year, 8 months ago
The only requirements for MACsec are that you have a dedicated Direct Connect connection and that the customer device supports it, see: https://docs.aws.amazon.com/directconnect/latest/UserGuide/MACsec.html
upvoted 1 times
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago