Correct Answer: Scoping each resource connector to only the specific applications it needs to expose, deploying redundant connector instances, using IPsec with strong encryption and Perfect Forward Secrecy for backhaul tunnels, and monitoring both for availability and anomalous activity
Explanation: Scoped connectors, redundancy, strong-encryption IPsec with PFS, and ongoing monitoring together provide secure, resilient access, unlike unrestricted connector reachability, non-redundant single instances, weak IPsec encryption, disabled post-deployment monitoring, or forcing one architecture onto every environment regardless of fit.
Correct Answer: Scoping each resource connector to only the specific applications it needs to expose, deploying redundant connector instances, using IPsec with strong encryption and Perfect Forward Secrecy for backhaul tunnels, and monitoring both for availability and anomalous activity
Explanation: Scoped connectors, redundancy, strong-encryption IPsec with PFS, and ongoing monitoring together provide secure, resilient access, unlike unrestricted connector reachability, non-redundant single instances, weak IPsec encryption, disabled post-deployment monitoring, or forcing one architecture onto every environment regardless of fit.