ETExamTower
Q28Network ImplementationMultiple answers

A company has an AWS environment containing multiple VPCs connected through a transit gateway. The company wants to use a certificate-based AWS Site-to-Site VPN connection to establish connectivity between an on-premises environment and the AWS environment. The company does not have a static public IP address for its on-premises environment. Which combination of steps should the company perform to establish VPN connectivity between the transit gateway and the on-premises environment? (Choose two.)

Select 2 answers.
← → navigate · a answer
Community votes
B
50% (3)
E
50% (3)
A
0% (0)
C
0% (0)
D
0% (0)
Discussion · 2
B, E 4
Why B (Create a private certificate in ACM) is correct: • AWS requires a private certificate from AWS Certificate Manager (ACM) for certificate-based authentication. • The certificate is used to authenticate the VPN connection instead of a pre-shared key (PSK). Why E (Create a customer gateway without specifying an IP address) is correct: • If the on-premises IP address is dynamic, you must create a customer gateway without an IP address. • This allows the VPN to function with BGP (Border Gateway Protocol), which dynamically updates the connection when the on-premises IP changes.
B, E 1
Answer: B & E