A network engineer must provide additional safeguards to protect encrypted data at Application Load Balancers (ALBs) through the use of a unique random session key.What should the network engineer do to meet this requirement?
Answer(s): D
Forward secrecy (FS) is a security feature that ensures that even if an attacker is able to compromise the session keys for a particular connection, they will not be able to use those keys to decrypt any past or future communications. This is because FS uses a new, unique session key for each connection.To enable FS on an ALB, you can change the ALB security policy to a policy that supports FS. You can do this by following these steps:Go to the ALB console.Select the ALB that you want to change.Click the Configuration tab.Under Security, click Edit.In the Security policy drop-down list, select a policy that supports FS.Click Save.Once you have enabled FS on an ALB, all connections to the ALB will use unique, random session keys. This will help to protect your data from being intercepted and decrypted by attackers.Here are some additional things to keep in mind when using FS on ALBs:FS is only available for connections that use the TLS 1.2 or TLS 1.3 protocols.If you are using a custom security policy, you will need to make sure that it includes a rule that enables FS.You can also use AWS Key Management Service (KMS) to encrypt session keys. This can be useful if you need to rotate session keys or if you want to store them in a secure location.
A company has deployed a software-defined WAN (SD-WAN) solution to interconnect all of its offices. The company is migrating workloads to AWS and needs to extend its SD-WAN solution to support connectivity to these workloads.A network engineer plans to deploy AWS Transit Gateway Connect and two SD-WAN virtual appliances to provide this connectivity. According to company policies, only a single SD-WAN virtual appliance can handle traffic from AWS workloads at a given time.How should the network engineer configure routing to meet these requirements?
Answer(s): C
A company is planning to deploy many software-defined WAN (SD-WAN) sites. The company is using AWS Transit Gateway and has deployed a transit gateway in the required AWS Region. A network engineer needs to deploy the SD-WAN hub virtual appliance into a VPC that is connected to the transit gateway. The solution must support at least 5 Gbps of throughput from the SD-WAN hub virtual appliance to other VPCs that are attached to the transit gateway.Which solution will meet these requirements?
Answer(s): B
A company is deploying a new application on AWS. The application uses dynamic multicasting. The company has five VPCs that are all attached to a transit gateway Amazon EC2 instances in each VPC need to be able to register dynamically to receive a multicast transmission.How should a network engineer configure the AWS resources to meet these requirements?
Post your Comments and Discuss Amazon ANS-C01 exam with other Community members:
sam Commented on March 03, 2025 helpful questions also in other forums Anonymous
Our website is free, but we have to fight against bots and content theft. We're sorry for the inconvenience caused by these security measures. You can access the rest of the ANS-C01 content, but please register or login to continue.