exam questions

Exam AWS Certified Advanced Networking - Specialty ANS-C01 All Questions

View all questions & answers for the AWS Certified Advanced Networking - Specialty ANS-C01 exam

Exam AWS Certified Advanced Networking - Specialty ANS-C01 topic 1 question 101 discussion

A company uses an AWS Direct Connect private VIF with a link aggregation group (LAG) that consists of two 10 Gbps connections. The company's security team has implemented a new requirement for external network connections to provide layer 2 encryption. The company's network team plans to use MACsec support for Direct Connect to meet the new requirement.

Which combination of steps should the network team take to implement this functionality? (Choose three.)

  • A. Create a new Direct Connect LAG with new circuits and ports that support MACsec.
  • B. Associate the MACsec Connectivity Association Key (CAK) and the Connection Key Name (CKN) with the new LAG.
  • C. Associate the Internet Key Exchange (IKE) with the existing LAG.
  • D. Configure the MACsec encryption mode on the existing LAG.
  • E. Configure the MACsec encryption mode on the new LAG.
  • F. Configure the MACsec encryption mode on each Direct Connect connection that makes up the existing LAG.
Show Suggested Answer Hide Answer
Suggested Answer: ABE 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
trap
Highly Voted 1 year, 5 months ago
Correct:A,B,E To start using MACsec, you must turn the feature on when you create a dedicated connection https://docs.aws.amazon.com/directconnect/latest/UserGuide/create-lag.html https://docs.aws.amazon.com/directconnect/latest/UserGuide/direct-connect-mac-sec-getting-started.html https://docs.aws.amazon.com/directconnect/latest/UserGuide/associate-key-lag.html
upvoted 14 times
Tofu13
1 year, 3 months ago
Perfect links, thanks.
upvoted 1 times
...
...
woorkim
Most Recent 6 days, 13 hours ago
Selected Answer: ABE
ABE is correct, no need to config old LAG.
upvoted 1 times
...
cas_tori
3 months ago
Selected Answer: ABE
this is ABE
upvoted 1 times
...
Suresh108
11 months, 1 week ago
minus 'existing' keyword
upvoted 2 times
...
passtest100
1 year, 2 months ago
should be C, D,F since LAG can be updated with MacSec mode rather than a new LAG should be created. https://docs.aws.amazon.com/directconnect/latest/APIReference/API_UpdateLag.html
upvoted 1 times
shinzor
1 year ago
While it is true that you can update MacSec mode on an existing LAG. However the MacSec keys in this context are only based on CKN/CAK. So using IKE as an answer is a no and makes all the other "existing" answers invalid.
upvoted 1 times
...
...
JosMo
1 year, 5 months ago
Selected Answer: ABE
abe is correct
upvoted 4 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...