The Security department has mandated that all outbound traffic from a VPC toward an on-premises datacenter must go through a security appliance that runs on an Amazon EC2 instance. Which of the following maximizes network performance on AWS? (Choose two.)
Select an option, then click Submit answer.
Reference / correct answer:
Support for the enhanced networking drivers
Most accepted answer: A. Support for the enhanced networking drivers
Community votes: A=1, C=1
A,C. adding ENI won't improve the performance. upvoted 14 times kvirk 4 years, 10 months ago I agree, A,C is correct answer upvoted 3 times ...
I agree, A,C is correct answer upvoted 3 times
A - Enhanced networking should be supported for best performance which ever instance is supported by security appliance. B - Best to have a Dx connection with on-premis. upvoted 5 times jpvdham 4 years, 9 months ago But how would you enable direct connect support on a EC2 instance?: Support for sending traffic over the Direct Connect connection. This is has nothing to do with te EC2 instance (more with routes). So imho AC are correct. upvoted 4 times Ishu_awsguy 4 years, 9 months ago The question is about maximising network performance on AWS. So we must consider DX. the traffic origination from onprem lands to TGW/VGW via DX and then the next hop can be firewall appliances like Checkpoint and Palo Alto. C is very general , it is obvious that we have to do deployment on supported instances , how does it do any value add upvoted 2 times ... ...
But how would you enable direct connect support on a EC2 instance?: Support for sending traffic over the Direct Connect connection. This is has nothing to do with te EC2 instance (more with routes). So imho AC are correct. upvoted 4 times Ishu_awsguy 4 years, 9 months ago The question is about maximising network performance on AWS. So we must consider DX. the traffic origination from onprem lands to TGW/VGW via DX and then the next hop can be firewall appliances like Checkpoint and Palo Alto. C is very general , it is obvious that we have to do deployment on supported instances , how does it do any value add upvoted 2 times ...
The question is about maximising network performance on AWS. So we must consider DX. the traffic origination from onprem lands to TGW/VGW via DX and then the next hop can be firewall appliances like Checkpoint and Palo Alto. C is very general , it is obvious that we have to do deployment on supported instances , how does it do any value add upvoted 2 times