exam questions

Exam AWS Certified Solutions Architect - Professional All Questions

View all questions & answers for the AWS Certified Solutions Architect - Professional exam

Exam AWS Certified Solutions Architect - Professional topic 1 question 77 discussion

You are designing a connectivity solution between on-premises infrastructure and Amazon VPC. Your servers on-premises will be communicating with your VPC instances. You will be establishing IPSec tunnels over the Internet You will be using VPN gateways, and terminating the IPSec tunnels on AWS supported customer gateways.
Which of the following objectives would you achieve by implementing an IPSec tunnel as outlined above? (Choose four.)

  • A. End-to-end protection of data in transit
  • B. End-to-end Identity authentication
  • C. Data encryption across the Internet
  • D. Protection of data in transit over the Internet
  • E. Peer identity authentication between VPN gateway and customer gateway
  • F. Data integrity protection across the Internet
Show Suggested Answer Hide Answer
Suggested Answer: CDEF 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
01037
Highly Voted 3 years, 7 months ago
My answer would be C,D,E,F. For A, End to end protection means the secure tunnel has to be established between your EC2 instance and the on-perm machine. By establishing a VPN tunnel between VPC and your on-perm gateway does not achieve that, the traffic before entering and after exiting the VPN tunnel will not be encrypted. For B, Same as A For C, As explained in A, this is what you can achieve by established a VPN tunnel between the two gateway. (encryption only happen between the two VPN end point which protect the data when it travel on the internet) For D, same as C For E, When establishing the VPN tunnel, the two gateway will authenticate each other prior to form the VPN tunnel. For F, same as C
upvoted 10 times
...
amministrazione
Most Recent 8 months, 3 weeks ago
A. End-to-end protection of data in transit C. Data encryption across the Internet D. Protection of data in transit over the Internet F. Data integrity protection across the Internet
upvoted 1 times
...
JPA210
1 year, 2 months ago
Selected Answer: ACDF
I will use the same explanation given by someone else: 'E is the request of building the VPN not the achievement of the VPN.'
upvoted 1 times
...
hobokabobo
2 years, 4 months ago
Selected Answer: CDEF
The security is not end to end. Eliminates A+B. E has different character than CDF but it is still achieved.
upvoted 1 times
...
TigerInTheCloud
2 years, 4 months ago
Selected Answer: ACDF
VPN is about encrypting data in transit. There is nothing about the identity autheication/
upvoted 1 times
hobokabobo
2 years, 4 months ago
The IPSEC is not established end to end. Its only over the internet to the gateway.
upvoted 1 times
...
TigerInTheCloud
2 years, 4 months ago
E is the request of building the VPN not the achievement of the VPN. A is not a good answer. If choose three, I will remove this one.
upvoted 1 times
...
...
CloudHandsOn
2 years, 9 months ago
C,D,E,F were the first choices
upvoted 1 times
...
challenger1
3 years, 4 months ago
My answer: C, D, E, F C. Data encryption across the Internet D. Protection of data in transit over the Internet E. Peer identity authentication between VPN gateway and customer gateway F. Data integrity protection across the Internet
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago