AWS Certified Advanced Networking – Specialty (ANS-C01) — Question 27

A software company offers a software-as-a-service (SaaS) accounting application that is hosted in the AWS Cloud The application requires connectivity to the company's on-premises network. The company has two redundant 10 GB AWS Direct Connect connections between AWS and its on-premises network to accommodate the growing demand for the application.
The company already has encryption between its on-premises network and the colocation. The company needs to encrypt traffic between AWS and the edge routers in the colocation within the next few months. The company must maintain its current bandwidth.
What should a network engineer do to meet these requirements with the LEAST operational overhead?

Answer options

Correct answer: C

Explanation

Option C is the best choice as it directly addresses the need for encryption with the least complexity by utilizing MACsec on new Direct Connect connections. Options A and B introduce additional infrastructure and VPN configurations, which increase operational overhead. Option D, while also valid, adds unnecessary complexity by creating both a public VIF and additional VPN connections.