You are configuring AWS Client VPN so that on-premises users can access resources in a VPC, but compliance requires that only traffic destined for the VPC go across the VPN tunnel. How should the Client VPN endpoint be configured to enforce this?
Choose an answer
Tap an option to check your answer.
Correct answer: Enable split-tunnel mode on the Client VPN endpoint so only VPC-bound traffic is sent through the tunnel..
Why this is the answer
Enabling split-tunnel mode on the Client VPN endpoint ensures that only traffic destined for the VPC's CIDR blocks is routed through the VPN tunnel. All other traffic, such as internet-bound traffic, is routed directly from the client's local network, bypassing the VPN. This meets the compliance requirement of sending only VPC-bound traffic across the VPN. Associating the endpoint with a private subnet with a NAT gateway would allow outbound internet access from resources within the VPC, but doesn't control which client traffic goes through the tunnel. Specifying DNS server IP addresses helps with name resolution but doesn't dictate traffic routing. Choosing a private certificate is for authentication, not traffic routing.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed