ANS-C01 exam dumps

ANS-C01 practice question 487 of 513

AWS Certified Advanced Networking - Specialty. Expert level, Amazon Web Services. Free question with the correct answer and a full explanation.

ANS-C01 Question 487

Select 2

You are managing an AWS network architecture for a financial institution that requires strict compliance with data confidentiality regulations. One of the applications needs to securely transfer sensitive data between an Amazon EC2 instance in a private subnet and an external partner's on-premises server over the internet. Which of the following approaches ensures the confidentiality of data and communications?

  1. A

    Use AWS Site-to-Site VPN to establish a secure connection between the VPC and the on-premises server.

  2. B

    Use an encrypted application-layer protocol such as HTTPS for data transfer over the internet.

  3. C

    Enable VPC Traffic Mirroring on the subnet to inspect traffic for security threats during data transfer.

  4. D

    Use AWS Direct Connect with MACsec encryption to establish a dedicated, secure connection.

  5. E

    Configure a NAT gateway to route outgoing traffic from the private subnet to the on-premises server.

Show answer and explanation

Correct answers: A, B

Explanation

To ensure the confidentiality of data and communications over the internet, it is essential to use encryption mechanisms like AWS Site-to-Site VPN or HTTPS. These methods protect the data in transit from being intercepted or accessed by unauthorized parties. While other options might enhance security or facilitate connectivity, they do not specifically address the requirement of ensuring data confidentiality.

  • A. Correct.

    This is a correct option because AWS Site-to-Site VPN encrypts data in transit between the AWS environment and the on-premises network, ensuring confidentiality.

  • B. Correct.

    This is a correct option because HTTPS encrypts application-layer data, protecting it from eavesdropping during transit over the internet.

  • C. Incorrect.

    This option is incorrect because VPC Traffic Mirroring is used for traffic analysis and monitoring, not for ensuring data confidentiality.

  • D. Incorrect.

    This option is incorrect because AWS Direct Connect with MACsec encryption is used for dedicated private connections, not for internet-based communication.

  • E. Incorrect.

    This option is incorrect because a NAT gateway facilitates outbound internet traffic from private subnets but does not provide encryption or ensure confidentiality.

Timed practice exam

Take a ANS-C01 practice test under exam conditions

65 questions in 170 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam