Courseiva
Network Security, Compliance and GovernanceeasyMultiple SelectObjective-mapped

ANS-C01 Network Security, Compliance and Governance Practice Question

A company wants to encrypt all data in transit between its on-premises data center and AWS. Which two services or features can provide encryption for data in transit?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

AWS Site-to-Site VPN

AWS Site-to-Site VPN uses IPsec to encrypt traffic between on-premises and AWS, providing encryption in transit. AWS Direct Connect with MACsec provides encryption at Layer 2. Options C and E are correct. Option A is wrong because AWS PrivateLink does not encrypt traffic between on-premises and AWS; it only provides private connectivity within AWS. Option B is wrong because VPC peering does not inherently encrypt traffic. Option D is wrong because AWS Transit Gateway is a network transit hub and does not provide encryption by itself.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • AWS PrivateLink

    Why it's wrong here

    Encrypts traffic within AWS, not for on-premises connectivity.

  • VPC peering

    Why it's wrong here

    No encryption.

  • AWS Site-to-Site VPN

    Why this is correct

    IPsec encryption.

  • AWS Transit Gateway

    Why it's wrong here

    Transit Gateway does not provide encryption.

  • AWS Direct Connect with MACsec

    Why this is correct

    MACsec provides encryption.

Quick reference

VPN Protocol Comparison

ProtocolPortEncryptionAuthenticationUse Case
IKEv2 / IPsecUDP 500 / 4500AES-256Certificates / PSKSite-to-site & remote access
SSL / TLS VPNTCP 443TLS 1.3Certificates / MFAClientless remote access
L2TP / IPsecUDP 1701AES (IPsec)PSK / CertificatesLegacy remote access
WireGuardUDP 51820ChaCha20Public keysModern high-performance VPN
PPTPTCP 1723MPPE (weak)MS-CHAPv2Legacy — avoid in production

PPTP is considered insecure. IKEv2/IPsec and SSL VPN are the current recommended options.

About these practice questions

This ANS-C01 question is part of Courseiva's 1,621-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

3 more ways this is tested on ANS-C01

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. A company wants to encrypt data in transit between an on-premises data center and AWS. Which service provides a dedicated encrypted connection?

easy
  • A.AWS Transit Gateway
  • B.AWS Direct Connect with MACsec
  • C.AWS Site-to-Site VPN
  • D.AWS Client VPN

Why B: AWS Direct Connect with MACsec provides a dedicated encrypted connection. Option A is wrong because AWS Transit Gateway is a network transit hub, not a connection type. Option C is wrong because AWS Site-to-Site VPN operates over the internet and is not dedicated. Option D is wrong because AWS Client VPN is for individual users and not a dedicated connection.

Variation 2. A company wants to encrypt all data in transit between its on-premises data center and AWS. They are using AWS Direct Connect for connectivity. Which additional configuration is required to ensure encryption?

easy
  • A.Use MACsec to encrypt the Direct Connect connection
  • B.Configure TLS on all applications
  • C.No additional configuration is needed; Direct Connect encrypts traffic automatically
  • D.Set up an IPsec VPN over the Direct Connect connection

Why D: Direct Connect does not provide encryption by default. To encrypt data in transit over Direct Connect, you need to set up an IPsec VPN over the Direct Connect connection. Option A is incorrect because MACsec encrypts at Layer 2, but it is not available on all Direct Connect connections and is different from IPsec. Option B is incorrect because TLS is for application-level encryption, which may not cover all traffic. Option C is incorrect because Direct Connect does not encrypt traffic automatically. Therefore, option D is correct.

Variation 3. A company has a requirement to encrypt all data in transit between its on-premises network and AWS over a VPN connection. Which solution provides encryption in transit?

easy
  • A.AWS Site-to-Site VPN
  • B.AWS Transit Gateway
  • C.VPC Peering
  • D.AWS Direct Connect

Why A: AWS Site-to-Site VPN uses IPsec tunnels to encrypt data in transit. Option B is wrong because Transit Gateway alone does not provide encryption. Option C is wrong because VPC Peering does not encrypt traffic. Option D is wrong because Direct Connect does not natively encrypt traffic; encryption must be added at the application layer.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This ANS-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the ANS-C01 exam.