A. Associate the Client VPN endpoint with a private subnet that has an internet route through a NAT gateway.
B. On the Client VPN endpoint, turn on the split-tunnel option.
C. On the Client VPN endpoint, specify DNS server IP addresses.
D. Select a private certificate to use as the identity certificate for the VPN client.

- Awsexamhub website is not related to, affiliated with, endorsed or authorized by Amazon.
- Trademarks, certification & product names are used for reference only and belong to Amazon.