A company has an AWS Direct Connect private virtual interface attached to a link aggregation group (LAG) consisting of two 10 Gbps links. A new security requirement mandates layer 2 encryption for external connections, and the network team plans to enable MACsec on Direct Connect to satisfy the requirement. Which set of actions should the network team perform to implement MACsec? (Choose three.)
Choose an answer
Tap an option to check your answer.
Correct answer: Create a new Direct Connect LAG with new circuits and ports that support MACsec., Associate the MACsec Connectivity Association Key (CAK) and the Connection Key Name (CKN) with the new LAG., Configure the MACsec encryption mode on the new LAG..
Why this is the answer
Implementing MACsec on AWS Direct Connect requires new infrastructure because existing Direct Connect connections and LAGs do not support in-place MACsec enablement. Therefore, the network team must create a new Direct Connect LAG with new circuits and ports that are MACsec-capable. Once the new LAG is provisioned, the MACsec Connectivity Association Key (CAK) and Connection Key Name (CKN) must be associated with this new LAG to establish the secure session. Finally, the MACsec encryption mode must be configured on the new LAG itself to activate the Layer 2 encryption. Incorrect options: Associating IKE is for IPsec, not MACsec. Configuring MACsec on the existing LAG or individual connections within it is not possible as they lack MACsec support.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed