Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.

Exam AWS Certified Solutions Architect - Professional SAP-C02 topic 1 question 375 discussion

A company runs an intranet application on premises. The company wants to configure a cloud backup of the application. The company has selected AWS Elastic Disaster Recovery for this solution.

The company requires that replication traffic does not travel through the public internet. The application also must not be accessible from the internet. The company does not want this solution to consume all available network bandwidth because other applications require bandwidth.

Which combination of steps will meet these requirements? (Choose three.)

  • A. Create a VPC that has at least two private subnets, two NAT gateways, and a virtual private gateway.
  • B. Create a VPC that has at least two public subnets, a virtual private gateway, and an internet gateway.
  • C. Create an AWS Site-to-Site VPN connection between the on-premises network and the target AWS network.
  • D. Create an AWS Direct Connect connection and a Direct Connect gateway between the on-premises network and the target AWS network.
  • E. During configuration of the replication servers, select the option to use private IP addresses for data replication.
  • F. During configuration of the launch settings for the target servers, select the option to ensure that the Recovery instance’s private IP address matches the source server's private IP address.
Show Suggested Answer Hide Answer
Suggested Answer: AEF 🗳️

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
heatblur
Highly Voted 9 months, 4 weeks ago
Selected Answer: ADE
ADE Option D: Create an AWS Direct Connect connection and a Direct Connect gateway between the on-premises network and the target AWS network. Option E: During configuration of the replication servers, select the option to use private IP addresses for data replication. Option A: could be considered if the private subnets are used without the NAT gateways, ensuring internal-only network access
upvoted 8 times
...
MegalodonBolado
Highly Voted 8 months, 2 weeks ago
Selected Answer: DEF
https://docs.aws.amazon.com/drs/latest/userguide/quick-start-guide-gs.html (E) Data routing and throttling controls how data flows from the external server to the replication servers. If you choose not to use a private IP, your replication servers will be automatically assigned a public IP and data will flow over the public internet. Check "Use private IP for data replication". (F) On Default DRS launch settings, check "Copy private IP". This way all other servers can transparently reach the recovered server. (D) Architects could use VPN or AWS DC, but "...The company does not want this solution to consume all available network bandwidth because other applications require bandwidth.", preferably use AWS Direct Connect.
upvoted 5 times
...
ShenYuying
Most Recent 1 week, 5 days ago
Regarding Option A, I'm not sure why there should be at least 2 subnets in the VPC. When configuring the Elastic Disaster Recovery, you only need to choose 1 subnet as target area. Besides, NAT is not needed here. For Option F, you can choose "Copy private IP" to match source server's IP address, but this is not a must, it is an optional choice, you don't need to choose it to meet the question's requirement. I'm really confused
upvoted 1 times
...
asquared16
4 weeks, 1 day ago
Those who picked A, why would you need the NAT gateways?!
upvoted 1 times
...
kgpoj
1 month ago
I am super confused about A A says Virtual Private Gateway, which is for Site-to-Site VPNs. Why do we need this ???
upvoted 1 times
...
vip2
2 months, 1 week ago
Selected Answer: DEF
replication traffic does not travel through the public internet. --> Not A must not be accessible from the internet --> Not B The company does not want this solution to consume all available network bandwidth --> not C, it requires D as dedicated network E and F during the Disaster Recovery step 3 and 4 as described as link below, https://docs.aws.amazon.com/drs/latest/userguide/quick-start-guide-gs.html
upvoted 1 times
...
ftaws
7 months, 3 weeks ago
We don't need to connect internet, why we need NAT gateway in A?
upvoted 3 times
drake2020
5 months, 1 week ago
the question says not accessible from internet NAT gateway is for inbound to internet and not internet -> inbound
upvoted 2 times
...
marszalekm
7 months, 1 week ago
https://docs.aws.amazon.com/drs/latest/userguide/Network-Requirements.html There are two ways to establish direct connectivity to the Internet for the VPC of the staging area, as described in the VPC FAQ 1. Public IP address + Internet gateway 2. Private IP address + NAT instance
upvoted 1 times
marszalekm
7 months, 1 week ago
Thats the only info I found, however this doesn't exactly answer your question.
upvoted 1 times
...
...
...
zhooon
7 months, 4 weeks ago
How about A,C,E? A. Create an intranet application and other application in a private subnet. Intranet applications connect to a private gateway(one). Other applications connect to the NAT gateway(one). Eliminates traffic interference. C. Site-to-Site VPN connect to private gateway. E. Replicates private IP.
upvoted 3 times
zhooon
7 months, 3 weeks ago
Can not backup for other application through Site-to-Site VPN. It is correct Option D. 'Direct Connect gateway' A, D, E
upvoted 1 times
...
zhooon
7 months, 4 weeks ago
Can other applications communicate with the Internet through the NAT gateway?
upvoted 1 times
...
...
career360guru
8 months, 1 week ago
Selected Answer: ADE
A, D and E
upvoted 2 times
...
yuliaqwerty
9 months ago
Answer ADE
upvoted 1 times
...
shaaam80
9 months, 2 weeks ago
Selected Answer: ADE
Answer ADE
upvoted 2 times
...
J0n102
9 months, 2 weeks ago
Selected Answer: ADE
DX is needed as it Provides a dedicated, private network connection that can be managed to avoid consuming all available network bandwidth
upvoted 4 times
...
SHASHANK32
9 months, 3 weeks ago
Selected Answer: BDE
Not Option - A, I don't see the point of creating NAT gateways.
upvoted 1 times
SHASHANK32
9 months, 2 weeks ago
mb, answer should A,D,E
upvoted 1 times
...
...
shaaam80
9 months, 3 weeks ago
Answer - ACE VPC with 2 private subnets and 2 NAT gateways for application and replication traffic which has to be private Site to Site VPN - for secure connection between Onprem and Customer VPC so both replication and application traffic does not flow over public internet Choosing private IP address for replication.
upvoted 1 times
shaaam80
9 months, 2 weeks ago
Correction - ADE Direct Connect needed for this solution. VPN is not needed
upvoted 1 times
...
shaaam80
9 months, 3 weeks ago
Direct connect not needed as there is no ask for a dedicated connection or high speed.
upvoted 1 times
heatblur
9 months, 3 weeks ago
Question states: "The company does not want this solution to consume all available network bandwidth because other applications require bandwidth." Usage of a VPN relies on the companies bandwidth and could very easily consume most of it. They'd need a dedicated connection (aka Direct Connect) to meet this requirement.
upvoted 3 times
...
...
...
HunkyBunky
9 months, 3 weeks ago
Selected Answer: ADE
I guess ADE
upvoted 1 times
...
devalenzuela86
9 months, 4 weeks ago
Selected Answer: AEF
Creating a VPC with at least two public subnets and an internet gateway (Option B) would allow the application to be accessible from the internet, which is not a requirement. Creating an AWS Site-to-Site VPN connection (Option C) or an AWS Direct Connect connection (Option D) would allow the replication traffic to be routed through a private network, but these options are not required since Option A already provides a private network 1. answer AEF
upvoted 1 times
...
devalenzuela86
10 months ago
Selected Answer: ACE
ACE for sure
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...