AWS Certified Advanced Networking – Specialty (ANS-C01)Network ImplementationMedium

A company requires a highly available and secure connection between their on-premises data center and their AWS VPC. They have an existing AWS Direct Connect connection. To enhance security and provide an additional layer of encryption for specific sensitive traffic, they want to establish VPN connections over the Direct Connect. Which type of VPN connection should be configured?

  1. ASite-to-Site VPN over Direct Connect (VPN over DX)
  2. BAWS Managed VPN without Direct Connect
  3. CAWS Client VPN
  4. DVPC Endpoint VPN
Show answer & explanation

Correct answer: A. Site-to-Site VPN over Direct Connect (VPN over DX)

A Site-to-Site VPN connection can be established over a Direct Connect private VIF. This configuration provides an additional layer of encryption (IPsec) for data traversing the Direct Connect connection, meeting the security requirement for sensitive traffic.

Why the other options are wrong

  • B. AWS Managed VPN without Direct Connect would use the public internet, which does not leverage the existing DX connection or its benefits.
  • C. AWS Client VPN is for remote users to access VPC resources, not for site-to-site connectivity over DX.
  • D. VPC Endpoint VPN is not a standard AWS service or configuration for this purpose.

VPN over Direct Connect

VPN over Direct Connect combines the dedicated bandwidth and consistent network experience of Direct Connect with the IPsec encryption of a Site-to-Site VPN, adding an extra layer of security.

  • Uses an AWS Site-to-Site VPN connection
  • Traffic travels over a Direct Connect Private VIF
  • Provides IPsec encryption for sensitive data
  • Enhances security beyond just the private DX connection

Memory trick: DX is the private road, VPN over DX is the armored car on that road.

More Network Implementation questions