PAS-C01 Technology Practice Question
An SAP administrator is configuring high availability for SAP HANA using HANA system replication (HSR) across multiple Availability Zones. The administrator must ensure that the replication traffic is encrypted and uses the most efficient network path. Which TWO configurations meet these requirements? (Choose TWO.)
⚠ Common exam trap
A common mix-up: candidates assume AWS Direct Connect or VPN are required for encryption and efficient routing between Availability Zones, but SAP HANA's native TLS/SSL encryption and VPC peering (which uses the AWS backbone) already satisfy both requirements without additional services.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Enable SAP HANA system replication with TLS/SSL encryption.
SAP HANA system replication (HSR) supports TLS/SSL encryption natively, which encrypts the replication traffic between the primary and secondary HANA instances. This ensures data confidentiality and integrity without requiring additional network infrastructure, and it uses the most efficient network path because the replication occurs directly over the existing network between the Availability Zones.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Enable SAP HANA system replication with TLS/SSL encryption.
Why this is correct
HSR supports TLS encryption for secure replication traffic.
- ✗
Store replication data in Amazon S3 and have the secondary instance pull it.
Why it's wrong here
This is not a standard HSR method; it would introduce high latency and complexity.
- ✗
Use AWS Direct Connect to connect the Availability Zones.
Why it's wrong here
Direct Connect is for on-premises to AWS connectivity, not between AZs.
- ✓
Use VPC peering between the subnets in different Availability Zones.
Why this is correct
VPC peering provides direct network connectivity between AZs with low latency.
- ✗
Configure a VPN connection between the Availability Zones.
Why it's wrong here
VPN adds encryption overhead and latency; not the most efficient path.
Go deeper
Related to this question
About these practice questions
Courseiva writes every PAS-C01 question from scratch — 1,616 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PAS-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PAS-C01 exam.