nerdexam
Amazon

ANS-C01 · Question #169

A company has an AWS environment that includes multiple VPCs that are connected by a transit gateway. The company has decided to use AWS Site-to-Site VPN to establish connectivity between its…

The correct answer is B. Configure the Site-to-Site VPN tunnel options to use Internet Key Exchange version 2 (IKEv2). C. Use a private certificate authority (CA) from AWS Private Certificate Authority to create a F. Create a customer gateway without specifying the IP address of the customer gateway device. An IP address is not required when you are using a private certificate from AWS Private Certificate Authority. https://docs.aws.amazon.com/vpn/latest/s2svpn/cgw-options.html

Submitted by fatema_kw· Mar 6, 2026Design and Implement Hybrid IT Network Architectures

Question

A company has an AWS environment that includes multiple VPCs that are connected by a transit gateway. The company has decided to use AWS Site-to-Site VPN to establish connectivity between its on-premises network and its AWS environment. The company does not have a static public IP address for its on-premises network. A network engineer must implement a solution to initiate the VPN connection on the AWS side of the connection for traffic from the AWS environment to the on-premises network. Which combination of steps should the network engineer take to establish VPN connectivity between the transit gateway and the on-premises network? (Choose three.)

Options

  • AConfigure the Site-to-Site VPN tunnel options to use Internet Key Exchange version 1 (IKEv1).
  • BConfigure the Site-to-Site VPN tunnel options to use Internet Key Exchange version 2 (IKEv2).
  • CUse a private certificate authority (CA) from AWS Private Certificate Authority to create a
  • DUse a public certificate authority (CA) from AWS Private Certificate Authority to create a
  • ECreate a customer gateway. Specify the current dynamic IP address of the customer gateway
  • FCreate a customer gateway without specifying the IP address of the customer gateway device.

How the community answered

(30 responses)
  • A
    20% (6)
  • B
    67% (20)
  • D
    10% (3)
  • E
    3% (1)

Explanation

An IP address is not required when you are using a private certificate from AWS Private Certificate Authority. https://docs.aws.amazon.com/vpn/latest/s2svpn/cgw-options.html

Topics

#AWS Site-to-Site VPN#Dynamic VPN endpoint#IKEv2#VPN certificate authentication

Community Discussion

No community discussion yet for this question.

Full ANS-C01 Practice