For IndividualsFor Educators
ExpertMinds LogoExpertMinds
ExpertMinds

Ace your certifications with Practice Exams and AI assistance.

  • Browse Exams
  • For Educators
  • Blog
  • Privacy Policy
  • Terms of Service
  • Cookie Policy
  • Support
  • AWS SAA Exam Prep
  • PMI PMP Exam Prep
  • CPA Exam Prep
  • GCP PCA Exam Prep

© 2026 TinyHive Labs. Company number 16262776.

    PracticeAWS Solutions Architect Professional (SAP-C02)AWS Solutions Architect Professional SAP-C02 Practice Exam 6Question 01
    Hard1 markMultiple Choice
    Domain 1.1: Network ConnectivityNetworkingDirect ConnectSecurity

    AWS SAP-C02 · Question 01 · Domain 1.1: Network Connectivity

    A global enterprise requires highly available hybrid connectivity between its on-premises data centers in New York and London to AWS VPCs in us-east-1 and eu-west-2. The solution must provide line-rate encryption and protect against a single AWS Direct Connect location failure. Which architecture meets these requirements with the LEAST operational overhead?

    Answer options:

    A.

    Provision one DX connection per region. Establish IPsec VPNs over the DX connections to Transit Gateways.

    B.

    Provision two DX connections in each region at different DX locations. Enable MACsec on the connections. Use Direct Connect gateways associated with Transit Gateways in each region.

    C.

    Provision two DX connections per region. Use AWS VPN CloudHub for encryption and routing between regions.

    D.

    Provision one DX connection and one Site-to-Site VPN per region. Enable MACsec on the VPN.

    How to approach this question

    Identify the requirement for line-rate encryption (MACsec) and location resiliency (two DX locations).

    Full Answer

    B.Provision two DX connections in each region at different DX locations. Enable MACsec on the connections. Use Direct Connect gateways associated with Transit Gateways in each region.✓ Correct
    MACsec (IEEE 802.1AE) provides hardware-based, line-rate encryption over Direct Connect. Using two connections at different locations ensures high availability.

    Common mistakes

    Selecting IPsec VPN over DX, which limits throughput.
    All questionsQuestion 02

    Practice the full AWS Solutions Architect Professional SAP-C02 Practice Exam 6

    75 questions · hints · full answers · grading

    Sign up freeTake the exam

    More questions from this exam

    Q02An organization has 50 VPCs across two AWS Regions connected via Transit Gateways (TGW). The TGWs...HardQ03A company uses AWS Organizations. The network team wants to share a central Transit Gateway (TGW)...MediumQ04An enterprise has on-premises data centers in the US and Europe. They want to use the AWS global ...HardQ05A company requires that all API calls to Amazon S3 from their VPC must not traverse the public in...MediumQ06An enterprise uses AWS Organizations with all features enabled. The CISO mandates that no AWS acc...Hard
    View all 75 questions →