Add a static Site-to-Site VPN as the resilient backup path to a 1 Gbps Direct Connect link
A company is designing an AWS environment for a manufacturing application. The application has been successful with customers, and the application's user base has increased. The company has connected the AWS environment to the company's on-premises data center through a 1 Gbps AWS Direct Connect connection. The company has configured BGP for the connection. The company must update the existing network connectivity solution to ensure that the solution is highly available, fault tolerant, and secure. Which solution will meet these requirements MOST cost-effectively?
Community Votes
79% of anonymous learners picked answer D. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
MACsec encryption on Direct Connect is only supported at 10 Gbps and 100 Gbps, so it cannot secure a 1 Gbps link, which leaves a VPN as the only low-cost way to add an encrypted secondary path.
An existing 1 Gbps Direct Connect connection with BGP carries on-premises to AWS traffic. The network must become highly available, fault tolerant, and secure, and the change must be the most cost-effective option available.
Choosing a dynamic Site-to-Site VPN with MACsec because dynamic routing looks more resilient. MACsec is unsupported at 1 Gbps, and a static VPN over the redundant path already satisfies the cost and resilience requirement.
Community Discussion (15 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
A static AWS Site-to-Site VPN gives the Direct Connect connection a second, encrypted path with no additional physical circuit to pay for, and Site-to-Site VPN is the standard, lowest-cost way to add resilience and encryption in transit to an AWS environment. If the Direct Connect connection fails, traffic fails over to the VPN.Why the Other Options Are Wrong
A and B: MACsec on Direct Connect is supported only on 10 Gbps and 100 Gbps links, so it cannot be used with this 1 Gbps connection, and it adds cost without satisfying the security requirement. B also doubles the circuit bill. C: Multiple private VIFs on the same physical connection do not add physical path diversity, so a single circuit or location failure still takes the link down, and load balancing across VIFs raises cost without improving fault tolerance.Community Comment Notes
The community split 79 to 21 for D over A, and the deciding evidence was the AWS Direct Connect MACsec documentation showing MACsec requires a 10 Gbps or 100 Gbps connection, which excludes the dynamic VPN plus MACsec combination in A.Official Reference
Related Analysis
Practice All SAP-C02 Questions
Access 85 questions with complete answers and detailed explanations.
View Full SAP-C02 Practice Test →