A company is migrating a record-keeping app to AWS. All traffic between on-premises and AWS must be encrypted at every transit device during migration. The app will run across multiple AZs in one Region and use existing 10 Gbps Direct Connect dedicated links with MACsec-capable ports. A network engineer must secure the Direct Connect link at every transit device. They created a Connection Key Name and Connectivity Association Key (CKN/CAK) pair. Which additional steps should the engineer take? (Choose two.)
Choose an answer
Tap an option to check your answer.
Correct answer: Configure the on-premises router with the MACsec secret key., Associate the CKN/CAK pair with the connection, then set the connection's MACsec encryption mode to must_encrypt..
Why this is the answer
To secure the Direct Connect link with MACsec, two primary actions are required. First, the on-premises router must be configured with the MACsec secret key (CAK) and key name (CKN) to establish a secure connection with the Direct Connect device. This ensures that the on-premises side is ready to encrypt and decrypt traffic. Second, on the AWS side, the CKN/CAK pair must be associated with the Direct Connect connection, and the MACsec encryption mode must be set to mustencrypt. The mustencrypt setting enforces encryption for all traffic, fulfilling the requirement that all traffic be encrypted at every transit device. Setting the mode to shouldencrypt would allow unencrypted traffic if MACsec negotiation fails, which doesn't meet the strict encryption requirement. The order of associating the CKN/CAK pair before setting the encryption mode is logical as the key pair must exist before the encryption mode can enforce its use.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed