nerdexam
Amazon

ANS-C01 · Question #282

A company is migrating its internet VPN connections to dedicated AWS Direct Connect connections. The company needs to set up the Direct Connect connections so that all network communications are…

The correct answer is A. Create new Direct Connect connections while requesting MACsec ports. B. Create a MACsec Connectivity Association Key Name (CKN) and Connectivity Association Key C. Update the on-premises routers to use MACsec and the shared Connectivity Association Key. MACsec (Media Access Control Security) is a Layer 2 encryption standard that can be enabled on AWS Direct Connect dedicated connections. Requesting MACsec ports ensures that the new connections support encryption at the physical MACsec requires a CKN and CAK pair to establish…

Submitted by sofia.br· Mar 6, 2026Network Security, Compliance, and Governance

Question

A company is migrating its internet VPN connections to dedicated AWS Direct Connect connections. The company needs to set up the Direct Connect connections so that all network communications are encrypted in transit. Which combination of steps will meet this requirement? (Choose three.)

Options

  • ACreate new Direct Connect connections while requesting MACsec ports.
  • BCreate a MACsec Connectivity Association Key Name (CKN) and Connectivity Association Key
  • CUpdate the on-premises routers to use MACsec and the shared Connectivity Association Key
  • DCreate a shared key for an IPsec connection.
  • EConfigure a new Direct Connect gateway. Associate the shared key with the new Direct Connect
  • FSet up IPsec on the on-premises router. Associate the shared key with the IPsec configuration.

How the community answered

(42 responses)
  • A
    71% (30)
  • D
    17% (7)
  • E
    5% (2)
  • F
    7% (3)

Explanation

MACsec (Media Access Control Security) is a Layer 2 encryption standard that can be enabled on AWS Direct Connect dedicated connections. Requesting MACsec ports ensures that the new connections support encryption at the physical MACsec requires a CKN and CAK pair to establish encrypted communication between the on- premises routers and the AWS Direct Connect routers. This ensures the encryption keys are securely shared and recognized by both endpoints. To enable MACsec on the Direct Connect link, the on-premises routers must be configured to use the same CKN and CAK. This ensures secure communication and proper encryption over the

Community Discussion

No community discussion yet for this question.

Full ANS-C01 Practice