Courseiva
Security →easyMultiple Choice

DVA-C02 Security Practice Question

A company wants to encrypt data in transit between an EC2 instance and an S3 bucket. What should they do?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use the S3 HTTPS endpoint for all API calls.

Data in transit between EC2 and S3 is encrypted by using the S3 HTTPS endpoint for all API calls, which uses TLS/SSL to encrypt the connection. Option A is incorrect because S3 does not support SSH transfers; SSH is used for secure shell access, not for S3 API calls. Option B is incorrect because S3 does not support VPN connections; VPN is used for network-level encryption between on-premises networks and AWS, not directly between EC2 and S3. Option C is incorrect because client-side encryption encrypts data before sending, but it does not address encryption in transit; HTTPS is the standard for in-transit encryption, and client-side encryption is for data at rest on the client side.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Use SSH to transfer files to S3.

    Why it's wrong here

    Amazon S3 does not expose an SSH or SFTP interface for object storage operations; all S3 access is performed over HTTP/HTTPS through its REST API, so SSH is not a valid transport mechanism between EC2 and S3.

  • ✗

    Establish a VPN connection between the instance and S3.

    Why it's wrong here

    S3 has no VPN endpoint or gateway to terminate a VPN tunnel against; encrypting traffic to S3 in transit is achieved through TLS on the HTTPS API calls, or through a VPC endpoint for private routing, not through a customer VPN connection.

  • ✗

    Enable client-side encryption using the AWS SDK.

    Why it's wrong here

    Client-side encryption using the AWS Encryption SDK encrypts the object's content before it ever leaves the instance, which protects data confidentiality at rest and even against a compromised transport, but it does not by itself address the requirement of encrypting the transport channel — that still requires HTTPS.

  • ✓

    Use the S3 HTTPS endpoint for all API calls.

    Why this is correct

    S3's HTTPS endpoints wrap every API call in TLS, encrypting the request and response payloads end-to-end between the EC2 instance and S3, which directly and completely satisfies the requirement to encrypt data in transit with no additional configuration needed.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

This DVA-C02 question is part of Courseiva's 1,135-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This DVA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DVA-C02 exam.