AWS Certified Advanced Networking – Specialty (ANS-C01)Network Management and OperationsEasy

A company is migrating its on-premises data center to AWS. They need to establish a highly available and resilient network connection between their on-premises network and their AWS VPCs. The solution must support multiple VPN tunnels and automatically fail over in case of a connection failure. Which AWS service provides this capability?

  1. AAWS Global Accelerator
  2. BAWS Client VPN
  3. CAWS Site-to-Site VPN
  4. DAWS Direct Connect
Show answer & explanation

Correct answer: C. AWS Site-to-Site VPN

AWS Site-to-Site VPN provides a highly available and resilient connection between an on-premises network and AWS. Each VPN connection consists of two tunnels, ensuring automatic failover. It's suitable for secure, encrypted connectivity over the public internet.

Why the other options are wrong

  • A. Global Accelerator improves application availability and performance for internet-facing applications by routing user traffic, not for establishing site-to-site connectivity.
  • B. Client VPN allows individual users to securely access AWS resources from their devices, not for connecting an entire on-premises data center.
  • D. Direct Connect provides a dedicated private connection, offering higher bandwidth and lower latency, but it's not primarily focused on automatic failover between multiple tunnels over the internet like Site-to-Site VPN.

AWS Site-to-Site VPN

A service that creates an encrypted connection between your on-premises network and your Amazon VPCs, typically over the public internet.

  • Each VPN connection has two tunnels for high availability.
  • Supports BGP for dynamic routing and automatic failover.
  • Cost-effective solution for secure connectivity over the internet.

Memory trick: For 'site-to-site' resilience, use 'Site-to-Site VPN'.

More Network Management and Operations questions