Courseiva
TechnologyhardMultiple SelectObjective-mapped

PAS-C01 Technology Practice Question

An SAP administrator is configuring high availability for SAP HANA using HANA system replication (HSR) across multiple Availability Zones. The administrator must ensure that the replication traffic is encrypted and uses the most efficient network path. Which TWO configurations meet these requirements? (Choose TWO.)

⚠ Common exam trap

A common mix-up: candidates assume AWS Direct Connect or VPN are required for encryption and efficient routing between Availability Zones, but SAP HANA's native TLS/SSL encryption and VPC peering (which uses the AWS backbone) already satisfy both requirements without additional services.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Enable SAP HANA system replication with TLS/SSL encryption.

SAP HANA system replication (HSR) supports TLS/SSL encryption natively, which encrypts the replication traffic between the primary and secondary HANA instances. This ensures data confidentiality and integrity without requiring additional network infrastructure, and it uses the most efficient network path because the replication occurs directly over the existing network between the Availability Zones.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Enable SAP HANA system replication with TLS/SSL encryption.

    Why this is correct

    HSR supports TLS encryption for secure replication traffic.

  • Store replication data in Amazon S3 and have the secondary instance pull it.

    Why it's wrong here

    This is not a standard HSR method; it would introduce high latency and complexity.

  • Use AWS Direct Connect to connect the Availability Zones.

    Why it's wrong here

    Direct Connect is for on-premises to AWS connectivity, not between AZs.

  • Use VPC peering between the subnets in different Availability Zones.

    Why this is correct

    VPC peering provides direct network connectivity between AZs with low latency.

  • Configure a VPN connection between the Availability Zones.

    Why it's wrong here

    VPN adds encryption overhead and latency; not the most efficient path.

About these practice questions

Courseiva writes every PAS-C01 question from scratch — 1,616 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PAS-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PAS-C01 exam.