Add a static Site-to-Site VPN as the resilient backup path to a 1 Gbps Direct Connect link

Answer Correct answer: D — Add a static Site-to-Site VPN as an encrypted secondary path, because MACsec is unsupported on a 1 Gbps Direct Connect connection.

A company is designing an AWS environment for a manufacturing application. The application has been successful with customers, and the application's user base has increased. The company has connected the AWS environment to the company's on-premises data center through a 1 Gbps AWS Direct Connect connection. The company has configured BGP for the connection. The company must update the existing network connectivity solution to ensure that the solution is highly available, fault tolerant, and secure. Which solution will meet these requirements MOST cost-effectively?

  1. Add a dynamic private IP AWS Site-to-Site VPN as a secondary path to secure data in transit and provide resilience for the Direct Connect connection. Configure MACsec to encrypt traffic inside the Direct Connect connection.
  2. Provision another Direct Connect connection between the company's on-premises data center and AWS to increase the transfer speed and provide resilience. Configure MACsec to encrypt traffic inside the Direct Connect connection.
  3. Configure multiple private VIFs. Load balance data across the VIFs between the on-premises data center and AWS to provide resilience.
  4. Add a static AWS Site-to-Site VPN as a secondary path to secure data in transit and to provide resilience for the Direct Connect connection. Correct Answer

Community Votes

D
79%
A
21%

79% of anonymous learners picked answer D. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

MACsec encryption on Direct Connect is only supported at 10 Gbps and 100 Gbps, so it cannot secure a 1 Gbps link, which leaves a VPN as the only low-cost way to add an encrypted secondary path.

An existing 1 Gbps Direct Connect connection with BGP carries on-premises to AWS traffic. The network must become highly available, fault tolerant, and secure, and the change must be the most cost-effective option available.

Choosing a dynamic Site-to-Site VPN with MACsec because dynamic routing looks more resilient. MACsec is unsupported at 1 Gbps, and a static VPN over the redundant path already satisfies the cost and resilience requirement.

Community Discussion (15 comments)

oayoade 👍 12 Selected: D
MACsec is only supported on 10gbps and 100gbps Direct Connect https://docs.aws.amazon.com/directconnect/latest/UserGuide/direct-connect-mac-sec-getting-started.html
TomTom 👍 1
Why not C? Adding multiple VIFs to your Direct Connect connection is a cost-effective way to increase redundancy and improve performance. https://docs.aws.amazon.com/whitepapers/latest/building-scalable-secure-multi-vpc-network-infrastructure/direct-connect.html#:~:text=Option%201%3A%20Create%20a%20private,allowing%20you%20to%20connect%20to
trungtd 👍 1 Selected: D
mentioned by oayoade.
titi_r 👍 1 Selected: D
Answer: D To encrypt data over DX, you use MACsec for 10 Gbps and 100 Gbps links, and S2S VPN for slower links (e.g. 1 Gbps). https://docs.aws.amazon.com/whitepapers/latest/aws-vpc-connectivity-options/aws-direct-connect-site-to-site-vpn.html https://repost.aws/knowledge-center/create-vpn-direct-connect https://aws.amazon.com/blogs/networking-and-content-delivery/adding-macsec-security-to-aws-direct-connect-connections/
pangchn 👍 1 Selected: D
vote for D too
ArunRav 👍 1 Selected: D
D as mentioned by oayoade.
zawminhtay.it.ucsm 👍 1 Selected: D
same as oayosde mentioned,
joseribas89 👍 2 Selected: D
as oayoade says we need at least 10gbps to use MACsec, so option D
pangchn 👍 1 Selected: D
D as mentioned by oayoade.
k23319 👍 2 Selected: A
MACSec is the difference here for the additional security for Direct Connect.
ahmadraufsyahputra 👍 1
A because dynamic IP is more resilence than static IP
Dgix 👍 1 Selected: A
A is the correct answer. D uses static routing which is less suitable.
djangoUnchained 👍 2 Selected: D
With A the VPN is dependent on the DX connection, so not adding any resilience. VPN is encrypted by default, D.
ovladan 👍 1
Solution: A If we look at the request "MOST cost-effectively" we can eliminate the answer under B. If we look at this part of the requirement "the solution is highly available, fault tolerant" we can eliminate C. If we look at this part "The company has configured BGP for the connection" and "the solution is ... secure" we can eliminate D, because the current Direct Connect connection is not encrypted and answer under D does not offer a solution to encrypt the traffic. Base on this answer under A is right choice.
CMMC 👍 3 Selected: A
Provide resilience for the Direct Connect connection. Configure MACsec to encrypt traffic inside the Direct Connect connection. More cost effective than the static Site-to-Site VPN in Option D (which does not have the MACsec encryption for additional security).

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

A static AWS Site-to-Site VPN gives the Direct Connect connection a second, encrypted path with no additional physical circuit to pay for, and Site-to-Site VPN is the standard, lowest-cost way to add resilience and encryption in transit to an AWS environment. If the Direct Connect connection fails, traffic fails over to the VPN.

Why the Other Options Are Wrong

A and B: MACsec on Direct Connect is supported only on 10 Gbps and 100 Gbps links, so it cannot be used with this 1 Gbps connection, and it adds cost without satisfying the security requirement. B also doubles the circuit bill. C: Multiple private VIFs on the same physical connection do not add physical path diversity, so a single circuit or location failure still takes the link down, and load balancing across VIFs raises cost without improving fault tolerance.

Community Comment Notes

The community split 79 to 21 for D over A, and the deciding evidence was the AWS Direct Connect MACsec documentation showing MACsec requires a 10 Gbps or 100 Gbps connection, which excludes the dynamic VPN plus MACsec combination in A.

Official Reference

Related Analysis

Practice All SAP-C02 Questions

Access 85 questions with complete answers and detailed explanations.

View Full SAP-C02 Practice Test →

← Back to SAP-C02 Study Guide