An organization's Security team has a requirement that all data leaving its on-premises data center be encrypted at the network layer and use dedicated connectivity. There is also a requirement to centrally log all traffic flow in Amazon VPC environments. An AWS Direct Connect connection has been ordered to build out this design. What steps should be taken to ensure that connectivity to AWS meets these security requirements? (Choose two.)
A) Provision a public virtual interface on AWS Direct Connect and set up a VPN to each VPC.
B) Provision a private virtual interface for each VPC connection.
C) Enable VPC Flow Logs for each VPC.
D) Use AWS KMS to encrypt traffic between on-premises and AWS.
E) Provision a VPN connection to each VPC over the internet.
Correct Answer:
Verified
Q247: You can use the _ command of
Q248: You have several Amazon Glacier vaults you
Q249: DNS name resolution must be provided for
Q250: All IP addresses within a 10.0.0.0/16 VPC
Q251: You can turn on the AWS Config
Q253: A company is using AWS to host
Q254: Your network utilizes jumbo frames on its
Q255: Which AWS service is used within an
Q256: A customer is using ABC Telecom as
Q257: A legacy, on-premises web application cannot be
Unlock this Answer For Free Now!
View this answer and more for free by performing one of the following actions
Scan the QR code to install the App and get 2 free unlocks
Unlock quizzes for free by uploading documents