exam questions

Exam AWS Certified Advanced Networking - Specialty ANS-C01 All Questions

View all questions & answers for the AWS Certified Advanced Networking - Specialty ANS-C01 exam

Exam AWS Certified Advanced Networking - Specialty ANS-C01 topic 1 question 265 discussion

A company has an AWS environment that includes multiple VPCs that are connected by a transit gateway. The company wants to use a certificate-based AWS Site-to-Site VPN connection to establish connectivity between an on-premises environment and the AWS environment. The company does not have a static public IP address for the on-premises environment.

Which combination of steps should the company take to establish VPN connectivity between the transit gateway and the on-premises environment? (Choose two.)

  • A. Create a public certificate in AWS Certificate Manager (ACM).
  • B. Create a private certificate in AWS Certificate Manager (ACM).
  • C. Configure the Site-to-Site VPN tunnels to use the pre-shared key (PSK).
  • D. Create a customer gateway. Specify the current dynamic IP address of the customer gateway device's external interface.
  • E. Create a customer gateway. Do not specify the IP address of the customer gateway device.
Show Suggested Answer Hide Answer
Suggested Answer: BE 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
AWSLoverLoverLoverLoverLover
3 weeks, 4 days ago
Selected Answer: BE
Answer: B & E
upvoted 1 times
...
ashk123456
1 month ago
Selected Answer: BE
Why B (Create a private certificate in ACM) is correct: • AWS requires a private certificate from AWS Certificate Manager (ACM) for certificate-based authentication. • The certificate is used to authenticate the VPN connection instead of a pre-shared key (PSK). Why E (Create a customer gateway without specifying an IP address) is correct: • If the on-premises IP address is dynamic, you must create a customer gateway without an IP address. • This allows the VPN to function with BGP (Border Gateway Protocol), which dynamically updates the connection when the on-premises IP changes.
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago