nerdexam
Amazon

ANS-C01 · Question #129

A company has an AWS Site-to-Site VPN connection between its office and its VPC. Users report occasional failure of the connection to the application that is hosted inside the VPC. A network…

The correct answer is B. Set the dead peer detection (DPD) timeout action to Restart. Initiate traffic from on premises to. https://docs.aws.amazon.com/vpn/latest/s2svpn/initiate-vpn-tunnels.html

Submitted by paula_co· Mar 6, 2026Network Management and Operations

Question

A company has an AWS Site-to-Site VPN connection between its office and its VPC. Users report occasional failure of the connection to the application that is hosted inside the VPC. A network engineer discovers in the customer gateway logs that the Internet Key Exchange (IKE) session ends when the connection to the application fails. What should the network engineer do to bring up the IKE session if the IKE session goes down?

Options

  • ASet the dead peer detection (DPD) timeout action to Clear. Initiate traffic from the VPC to on
  • BSet the dead peer detection (DPD) timeout action to Restart. Initiate traffic from on premises to
  • CSet the dead peer detection (DPD) timeout action to None. Initiate traffic from the VPC to on
  • DSet the dead peer detection (DPD) timeout action to Cancel. Initiate traffic from on premises to

How the community answered

(30 responses)
  • A
    7% (2)
  • B
    70% (21)
  • C
    3% (1)
  • D
    20% (6)

Explanation

https://docs.aws.amazon.com/vpn/latest/s2svpn/initiate-vpn-tunnels.html

Topics

#AWS Site-to-Site VPN#IKE session#DPD#VPN troubleshooting

Community Discussion

No community discussion yet for this question.

Full ANS-C01 Practice