SCS-C02 exam dumps

SCS-C02 practice question 224 of 504

AWS Certified Security - Specialty. Expert level, Amazon Web Services. Free question with the correct answer and a full explanation.

SCS-C02 Question 224

Select 3

A company has deployed a VPN connection between their on-premises data center and their VPC in AWS using a Virtual Private Gateway. The security team has noticed intermittent connectivity issues and wants to ensure that the VPN tunnel remains highly available. Which of the following steps should they take to improve the reliability of the VPN connection?

  1. A

    Configure multiple Customer Gateway devices in the on-premises environment.

  2. B

    Enable static routing instead of dynamic routing for the VPN connection.

  3. C

    Use both tunnels provided by the VPN connection for redundancy.

  4. D

    Deploy an additional VPN connection with a new Virtual Private Gateway.

  5. E

    Enable Perfect Forward Secrecy (PFS) in the VPN configuration.

Show answer and explanation

Correct answers: A, C, D

Explanation

To ensure high availability of a VPN connection, it is critical to implement redundancy at multiple levels. Configuring multiple Customer Gateway devices provides redundancy on the on-premises side. Using both tunnels of the VPN connection ensures AWS-side redundancy for the existing connection. Deploying an additional VPN connection with a new Virtual Private Gateway adds even more redundancy, protecting against the failure of a single VPN connection. These measures collectively improve the overall reliability and availability of the VPN connection.

  • A. Correct.

    Configuring multiple Customer Gateway devices ensures redundancy on the on-premises side. If one gateway fails, the other can take over, improving overall reliability.

  • B. Incorrect.

    Static routing is less flexible and does not dynamically adapt to network changes, making it less reliable than dynamic routing with BGP. This does not address the intermittent connectivity issue.

  • C. Correct.

    Using both tunnels provided by the VPN connection ensures redundancy. AWS always provides two tunnels for each VPN connection, and using both increases availability.

  • D. Correct.

    Deploying an additional VPN connection with a new Virtual Private Gateway adds another layer of redundancy. If the primary VPN fails, the secondary VPN can take over.

  • E. Incorrect.

    While enabling Perfect Forward Secrecy improves the security of the VPN connection by ensuring that session keys are not reused, it does not directly address availability or reliability issues.

Timed practice exam

Take a SCS-C02 practice test under exam conditions

65 questions in 170 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam