Which Steps Encrypt AWS Direct Connect Connections with MACsec?

A company is migrating its internet VPN connections to dedicated AWS Direct Connect connections. The company needs to set up the Direct Connect connections so that all network communications are encrypted in transit. Which combination of steps will meet this requirement? (Choose three.)

  1. Create new Direct Connect connections while requesting MACsec ports. Source Reference Answer
  2. Create a MACsec Connectivity Association Key Name (CKN) and Connectivity Association Key (CAK) pair. Associate the pair with each new connection. Source Reference Answer
  3. Update the on-premises routers to use MACsec and the shared Connectivity Association Key Name (CKN) and Connectivity Association Key (CAK) pair. Source Reference Answer
  4. Create a shared key for an IPsec connection.
  5. Configure a new Direct Connect gateway. Associate the shared key with the new Direct Connect gateway.

Community Votes

ABC
100%

100% of anonymous learners picked answer ABC. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

The exam tests your ability to identify MACsec as the layer 2 encryption mechanism for dedicated Direct Connect, and the common trap is choosing IPsec (options D and E) which encrypts traffic over public VPN connections rather than the physical Direct Connect link.

To encrypt AWS Direct Connect connections in transit, you must enable MACsec by requesting MACsec-capable ports, creating a CKN/CAK pair, and configuring the on-premises routers with that pair. The community consensus for the correct combination is A, B, and C, confirming that MACsec is the layer 2 encryption method for dedicated Direct Connect connections.

The most common mistake is selecting options D and E (IPsec with a shared key) because IPsec is also an encryption technology, but it is not used to encrypt the Direct Connect physical connection itself. MACsec is required for layer 2 encryption of dedicated Direct Connect ports, while IPsec is for site-to-site VPN over the public internet or for encrypting traffic through a Direct Connect gateway with a public VIF or transit VIF.

Community Discussion (3 comments)

ashk123456 👍 1 Selected: ABC
ABC is correct
woorkim 👍 1 Selected: ABC
to encrypt network communications over AWS Direct Connect connections are A, B, and C. These steps ensure that MACsec is enabled and properly configured for the Direct Connect connections, providing encryption in transit.
kowal_001 👍 1 Selected: ABC
ABC MACsec combination.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

Option A is correct because you must create new Direct Connect connections requesting MACsec ports, which support the IEEE 802.1AE standard for encryption at layer 2. Option B is correct because you need to create a CKN/CAK pair and associate it with each new connection; this key pair is the shared secret used by MACsec to encrypt data on the link. Option C is correct because the on-premises routers must be configured with the same CKN/CAK pair to establish the MACsec session, enabling encrypted communication between the customer network and AWS.

Why the Other Options Are Wrong

Option D is incorrect because creating a shared key for an IPsec connection is not the right approach for encrypting Direct Connect. IPsec is used for VPN connections over the internet, not for the physical Direct Connect line. Option E is also incorrect because associating a shared key with a Direct Connect gateway does not encrypt the underlying Direct Connect connection; the Direct Connect gateway is a logical construct for routing traffic between VPCs and on-premises networks, and IPsec over a transit VIF would be handled through a VPN appliance, not through the gateway key association.

The question asks for steps to encrypt network communications over dedicated Direct Connect connections, and only A, B, and C fulfill that by implementing MACsec at both ends of the physical link. The other options confuse the encryption layer and the components involved.

Community Comment Notes

The community comments are unanimous in supporting the answer ABC. For example, one comment states, "To encrypt network communications over AWS Direct Connect connections are A, B, and C. These steps ensure that MACsec is enabled and properly configured for the Direct Connect connections, providing encryption in transit." Another comment simply affirms "ABC" and "ABC is correct." These comments reinforce that the correct process involves MACsec port creation, key pair configuration, and on-premises router updates, with no mention of IPsec or Direct Connect gateway shared keys.

Official Reference

Exam Strategy

Remember that encryption for dedicated Direct Connect connections at layer 2 is always MACsec, not IPsec. On the exam, when you see steps involving MACsec ports and a CKN/CAK pair, select those; ignore IPsec-related options unless the scenario explicitly mentions a VPN over the internet or a public VIF with a VPN tunnel.

Related Analysis

Practice All ANS-C01 Questions

Access 137 questions with complete answers and detailed explanations.

View Full ANS-C01 Practice Test →

← Back to ANS-C01 Study Guide