Question 270:
A start-up firm is looking to deploy a backup web server in AWS Cloud Infrastructure with primary servers at on-prem Data Centre. Web server will be deployed on EC2 instance in non-default VPC. You have been asked to establish a VPN connectivity between on-prem Cisco Routers & VGW. After initial VPN connection establishment, Security Team has concerns on Crypto parameters used for this connection & asked you to use enhance Crypto parameters. Which of the following can be done to establish VPN connections with new Crypto parameters &meet mandatory security guidelines with the least effort?
Answer options:
A.Create a second VGW with a VPC & create a new VPN connection with Customer Gateway using new Crypto parameters. B.Delete existing VPN connection & create a separate VPN tunnel with new Crypto parameters. C.Change Crypto Configuration on Customer Gateway& open an AWS support ticket to share new Crypto configuration with them to be added at VGW end. D.Change Crypto Configuration on Customer Gateway, VPN Configuration with VGW is negotiated when Tunnel is established.