A company is replacing internet VPN links with dedicated AWS Direct Connect connections and requires that all traffic be encrypted in transit. Which combination of actions will satisfy this requirement? (Choose three.)
Choose an answer
Tap an option to check your answer.
Correct answer: Create new Direct Connect links and request MACsec-capable ports., Generate a MACsec Connectivity Association Key Name (CKN) and Connectivity Association Key (CAK) pair, and associate that pair with each new connection., Update the on-premises routers to support MACsec and configure them with the shared CKN and CAK..
Why this is the answer
To encrypt Direct Connect traffic in transit, MACsec (Media Access Control Security) is the appropriate solution. This requires requesting MACsec-capable ports when creating new Direct Connect links. Next, a MACsec Connectivity Association Key Name (CKN) and Connectivity Association Key (CAK) pair must be generated and associated with each new connection in AWS. Finally, the on-premises routers must be updated to support MACsec and configured with the shared CKN and CAK to establish the secure connection. The options related to IPsec are incorrect because while IPsec provides encryption, it is typically used for VPNs over the internet or as an additional layer over Direct Connect, not as the primary in-transit encryption mechanism for Direct Connect itself when MACsec is available and preferred for layer 2 encryption.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed