exam questions

Exam AWS Certified Solutions Architect - Professional All Questions

View all questions & answers for the AWS Certified Solutions Architect - Professional exam

Exam AWS Certified Solutions Architect - Professional topic 1 question 646 discussion

A company hosts a legacy application that runs on an Amazon EC2 instance inside a VPC without internet access. Users access the application with a desktop program installed on their corporate laptops. Communication between the laptops and the VPC flows through AWS Direct Connect (DX). A new requirement states that all data in transit must be encrypted between users and the VPC.
Which strategy should a solutions architect use to maintain consistent network performance while meeting this new requirement?

  • A. Create a client VPN endpoint and configure the laptops to use an AWS client VPN to connect to the VPC over the internet.
  • B. Create a new public virtual interface for the existing DX connection, and create a new VPN that connects to the VPC over the DX public virtual interface.
  • C. Create a new Site-to-Site VPN that connects to the VPC over the internet.
  • D. Create a new private virtual interface for the existing DX connection, and create a new VPN that connects to the VPC over the DX private virtual interface.
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
liono
Highly Voted 3 years, 8 months ago
B https://aws.amazon.com/premiumsupport/knowledge-center/create-vpn-direct-connect/
upvoted 28 times
DashL
3 years, 7 months ago
To connect to a VPC, it is required to connect to a Private Virtual interface over Direct connect. I guess an AWS document will be more accurate than any blog post: https://docs.aws.amazon.com/whitepapers/latest/aws-vpc-connectivity-options/aws-direct-connect-vpn.html
upvoted 4 times
...
helpaws
2 years, 10 months ago
Private VIFs do not provide encryption.. Public VIFs can via IPSEC. you also cannot establish a VPN connection without a Public VIF.
upvoted 5 times
...
user0001
3 years ago
it is D, there is no requirement to access public services so no need for public VIP
upvoted 2 times
Byrney
2 years, 7 months ago
AWS S2S VPN is a public service, so a public VIF is required
upvoted 2 times
...
...
...
Bulti
Highly Voted 3 years, 7 months ago
Answer is B. https://aws.amazon.com/premiumsupport/knowledge-center/create-vpn-direct-connect/. Remember that to connect to services such as EC2 using just Direct Connect you need to create a private VIF. However if you want to encrypt the traffic flowing through DirectConnect, you will need to use the public VIF of DX to create a VPN connection that will allow access to AWS services such as S3, EC2 etc. The video describes this.
upvoted 13 times
...
nhorcajada
Most Recent 1 year, 8 months ago
Selected Answer: D
Its explained here. Prevously public VIF was needed not now https://docs.aws.amazon.com/vpn/latest/s2svpn/private-ip-dx.html
upvoted 1 times
...
evargasbrz
2 years, 5 months ago
Selected Answer: D
D is the right answer here. As you can check in this document: https://docs.aws.amazon.com/whitepapers/latest/aws-vpc-connectivity-options/aws-direct-connect-vpn.html you really need to use a Public VIFs to access all AWS public services such as Amazon virtual private gateway IPsec endpoint.
upvoted 2 times
evargasbrz
2 years, 5 months ago
Sorry I mean B. B is the right answer here.
upvoted 2 times
evargasbrz
2 years, 5 months ago
Can a moderator change my vote to B, please?
upvoted 2 times
...
...
...
JohnPi
2 years, 7 months ago
Selected Answer: B
you need public VIF. To implement a Private IP VPN with AWS Direct Connect you need a transit virtual interface, DXG, transit gateway
upvoted 3 times
...
Enigmaaaaaa
2 years, 10 months ago
This is clearly stated in AWS documentation https://docs.aws.amazon.com/whitepapers/latest/aws-vpc-connectivity-options/aws-direct-connect-vpn.html The answer must B as IPSec tunnels are always public
upvoted 2 times
...
hilft
2 years, 10 months ago
got the DX. D > B
upvoted 1 times
...
aandc
2 years, 11 months ago
B you need to use the public VIF of DX to create a VPN connection https://docs.aws.amazon.com/whitepapers/latest/aws-vpc-connectivity-options/aws-direct-connect-vpn.html
upvoted 1 times
...
TechX
2 years, 11 months ago
Selected Answer: D
D for me
upvoted 1 times
TechX
2 years, 11 months ago
Just ignore D, after asking my experienced senior SA. It should be B, cause now he is also doing a same solution for a company has the same case in this question
upvoted 2 times
...
...
Ddssssss
2 years, 11 months ago
I don't understand why it cant be D?? Just because 90% of the time you would use the Public interface doesn't mean you cant use the private. Its a valid DX configuration option with IPSEC tunnel. Private virtual interface: A private virtual interface should be used to access an Amazon VPC using private IP addresses. https://docs.aws.amazon.com/directconnect/latest/UserGuide/WorkingWithVirtualInterfaces.html It is also clearly explain in this blog which references all the details in any AWS doc. https://jayendrapatil.com/tag/direct-connect/ This doc is also only 2 days old. but with the use of a transit GW you can use Private IP and IPSEC. https://aws.amazon.com/blogs/networking-and-content-delivery/introducing-aws-site-to-site-vpn-private-ip-vpns/
upvoted 1 times
...
Hasitha99
3 years, 1 month ago
Selected Answer: B
o connect to services such as EC2 using just Direct Connect you need to create a private VIF. However if you want to encrypt the traffic flowing through DirectConnect, you will need to use the public VIF of DX to create a VPN connection that will allow access to AWS services such as S3, EC2.
upvoted 1 times
...
azure_kai
3 years, 2 months ago
Selected Answer: D
I would choose D. There is no internet connection. And the traffic is between corporate network and VPC. Most likely, it only involves private IP addresses, which only requires privhttps://www.examtopics.com/exams/amazon/aws-certified-solutions-architect-professional/view/14/#ate virtual interface over DX.
upvoted 1 times
...
jyrajan69
3 years, 3 months ago
There is no debate, link from liono clearly shows step by step solution. Answer is B
upvoted 1 times
...
lifebegins
3 years, 3 months ago
Answer is D: We shoud go over the With AWS Direct Connect and AWS Site-to-Site VPN, you can combine one or more AWS Direct Connect dedicated network connections with the Amazon VPC VPN https://docs.aws.amazon.com/directconnect/latest/UserGuide/encryption-in-transit.html
upvoted 1 times
...
HellGate
3 years, 4 months ago
My answer is D. Why do we need public virtual interface for communication between laptop and VPC over DX? There are no requirements of accessing from internet. It should be PRIVATE virtual interface.
upvoted 1 times
futen0326
3 years, 3 months ago
Private VIFs do not provide encryption.. Public VIFs can via IPSEC. you also cannot establish a VPN connection without a Public VIF.
upvoted 2 times
Naj_64
2 years, 8 months ago
You can with a Transit VIF "Private IP VPN is deployed on top of Transit VIFs" -- https://aws.amazon.com/blogs/networking-and-content-delivery/introducing-aws-site-to-site-vpn-private-ip-vpns/ Answer is still B though.
upvoted 1 times
...
...
...
GV19
3 years, 4 months ago
Selected Answer: B
to establish VPN over DX, Public VIF is required, Only Option B has this detail;
upvoted 2 times
...
KiraguJohn
3 years, 6 months ago
VPC does not have internet connection. Private virtual interface: used to access an VPC using private IP addresses. Public virtual interface: can access all AWS public services using public IP addresses.
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...