ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 15 - ANS-C00 discussion

Report
Export

An organization's Security team has a requirement that all data leaving its on-premises data center be encrypted at the network layer and use dedicated connectivity. There is also a requirement to centrally log all traffic flow in Amazon VPC environments. An AWS Direct Connect connection has been ordered to build out this design.

What steps should be taken to ensure that connectivity to AWS meets these security requirements? (Choose two.)

A.
Provision a public virtual interface on AWS Direct Connect and set up a VPN to each VPC.
Answers
A.
Provision a public virtual interface on AWS Direct Connect and set up a VPN to each VPC.
B.
Provision a private virtual interface for each VPC connection.
Answers
B.
Provision a private virtual interface for each VPC connection.
C.
Enable VPC Flow Logs for each VPC.
Answers
C.
Enable VPC Flow Logs for each VPC.
D.
Use AWS KMS to encrypt traffic between on-premises and AWS.
Answers
D.
Use AWS KMS to encrypt traffic between on-premises and AWS.
E.
Provision a VPN connection to each VPC over the internet.
Answers
E.
Provision a VPN connection to each VPC over the internet.
Suggested answer: B, E

Explanation:

Explanation:

Reference: https://d1.awsstatic.com/whitepapers/building-a-scalable-and-secure-multi-vpc-aws-network-infrastructure.pdf

asked 16/09/2024
Rakesh Sharma
34 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first