AWS Certified Advanced Networking – Specialty (ANS-C01)Network DesignEasy

A financial services company needs to establish secure communication between its on-premises data center and a new application hosted in an AWS VPC. The connection must use IPsec VPN, support multiple tunnels for redundancy and increased throughput, and automatically failover between tunnels. Which AWS service provides a fully managed solution for this requirement?

  1. AAWS Direct Connect
  2. BAWS Client VPN
  3. CAWS Site-to-Site VPN
  4. DAWS Transit Gateway VPN attachment
Show answer & explanation

Correct answer: C. AWS Site-to-Site VPN

AWS Site-to-Site VPN provides a secure IPsec connection between your on-premises network and an AWS VPC. It automatically provisions two tunnels for redundancy and increased throughput, and supports active/passive or active/active configurations with automatic failover.

Why the other options are wrong

  • A. AWS Direct Connect provides a dedicated private connection, not an IPsec VPN over the internet.
  • B. AWS Client VPN is for end-user access to AWS resources, not site-to-site connectivity.
  • D. AWS Transit Gateway VPN attachment connects a Site-to-Site VPN to a Transit Gateway, which is part of a larger solution but Site-to-Site VPN is the core service providing the tunnels and failover functionality.

AWS Site-to-Site VPN

A fully managed AWS service that creates a secure IPsec VPN connection between an on-premises data center (or remote network) and an AWS VPC.

  • Uses IPsec protocol for secure communication over the public internet.
  • Automatically provisions two redundant tunnels for high availability and throughput.
  • Supports BGP for dynamic routing or static routing.
  • Managed by AWS, reducing operational overhead.

Memory trick: Site-to-Site VPN connects your home base securely to the cloud.

More Network Design questions