QuestionQ1
Network DesignAn insurance company plans to migrate workloads from its on-premises data center to the AWS Cloud. The company needs end-to-end domain name resolution, including bi-directional DNS resolution between AWS and the existing on-premises environments. The workloads will be migrated into multiple VPCs, have dependencies on one another, and will not all migrate at the same time.
Which solution fulfills these requirements?
QuestionQ2
Network Management and OperationA company runs an application on Amazon EC2 instances behind an Application Load Balancer (ALB). The company recently had a network security breach. A network engineer needs to collect and analyze logs containing the client IP address, target IP address, target port, and user agent for every user who accesses the application.
What is the MOST operationally efficient solution that fulfills these requirements?
Community Discussion
QuestionQ3
Network Security, Compliance, and GovernanceA company uses AWS Network Firewall to protect outbound traffic for multiple VPCs in the same AWS account. Each VPC contains Amazon EC2 instances that host the company’s applications. Every EC2 instance is tagged with the name of the application that it hosts. The EC2 instances are in Auto Scaling groups.
A Network Firewall stateful rule group must stay current even when an Auto Scaling group launches or terminates EC2 instances.
Which solution meets this requirement with the LEAST implementation and administrative effort?
Community Discussion
QuestionQ4
Network DesignA company is migrating applications from a data center to AWS. Many applications will need to exchange data with the company’s on-premises mainframe.
The company must achieve transfer speeds of 4 Gbps to satisfy peak traffic demands. A network engineer must design a highly available solution that maximizes resiliency. The solution must withstand the loss of circuits or routers.
Which solution satisfies these requirements?
Community Discussion
QuestionQ5
Network ImplementationA company has an AWS environment containing multiple VPCs connected through a transit gateway. The company has chosen AWS Site-to-Site VPN to establish connectivity between its on-premises network and its AWS environment.
The company does not have a static public IP address for its on-premises network. A network engineer must implement a solution that initiates the VPN connection from the AWS side for traffic from the AWS environment to the on-premises network.
Which combination of steps should the network engineer take to establish VPN connectivity between the transit gateway and the on-premises network?
Community Discussion