A company has a 1 Gbps AWS Direct Connect link between its on-premises data center and AWS and uses BGP. As user demand grows, the company needs a more highly available, fault-tolerant, and secure connectivity solution that is also cost-effective. Which change meets these requirements most cost-effectively?
Choose an answer
Tap an option to check your answer.
Correct answer: Add a static AWS Site-to-Site VPN as a secondary path to secure data in transit and provide resilience for the Direct Connect connection..
Why this is the answer
Adding a static AWS Site-to-Site VPN as a secondary path is the most cost-effective solution. It provides a highly available and fault-tolerant backup for the Direct Connect link at a lower cost than an additional Direct Connect connection. The VPN encrypts data in transit, fulfilling the security requirement. Adding a dynamic private IP Site-to-Site VPN is less cost-effective due to the increased complexity and potential for higher operational overhead compared to a static VPN. MACsec on Direct Connect is expensive and often unnecessary if data is already encrypted at the application layer or via a VPN. Provisioning an additional Direct Connect connection provides redundancy and increased bandwidth but is significantly more expensive than a VPN backup. Configuring multiple private VIFs on a single Direct Connect link does not provide fault tolerance for the physical link itself; if the link fails, all VIFs fail.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed