PAS-C01 Operations and Maintenance Practice Question
An SAP system is running on EC2 instances in a VPC. The security team requires that all traffic between the SAP application and database tiers be encrypted in transit. Which solution meets this requirement with minimal latency?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use security groups to allow traffic only between the instances, with IPsec configured
Security groups act as a virtual firewall, and when combined with IPsec configuration on the EC2 instances, they provide end-to-end encryption between the application and database tiers. This method introduces minimal latency because the encryption is handled by the instances themselves without additional network appliances or load balancers. Option A is incorrect because an AWS Site-to-Site VPN is designed for connecting on-premises networks to AWS, not for internal traffic between tiers. Option C is incorrect because an Application Load Balancer with TLS termination adds unnecessary latency and does not encrypt traffic beyond the load balancer. Option D is incorrect because enabling HTTPS alone does not encrypt database traffic, as database protocols typically use different ports and are not HTTP-based.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Use an AWS Site-to-Site VPN connection between the tiers
Why it's wrong here
Incorrect. AWS Site-to-Site VPN is for connecting on-premises networks to AWS, not for traffic between EC2 instances within the same VPC. It adds unnecessary latency and complexity.
- ✓
Use security groups to allow traffic only between the instances, with IPsec configured
Why this is correct
Correct. Configuring IPsec directly on the EC2 instances and using security groups to control traffic provides encryption in transit with minimal latency, as it works at the network layer without additional components.
- ✗
Use an Application Load Balancer with TLS termination in front of the database tier
Why it's wrong here
Incorrect. An Application Load Balancer with TLS termination adds an extra network hop and processing delay, increasing latency. It is not ideal for low-latency internal encryption.
- ✗
Install TLS certificates on each EC2 instance and enable HTTPS
Why it's wrong here
Incorrect. Installing TLS certificates and enabling HTTPS encrypts traffic at the application layer, which adds CPU overhead and latency compared to network-layer encryption like IPsec.
Quick reference
VPN Protocol Comparison
| Protocol | Port | Encryption | Authentication | Use Case |
|---|---|---|---|---|
| IKEv2 / IPsec | UDP 500 / 4500 | AES-256 | Certificates / PSK | Site-to-site & remote access |
| SSL / TLS VPN | TCP 443 | TLS 1.3 | Certificates / MFA | Clientless remote access |
| L2TP / IPsec | UDP 1701 | AES (IPsec) | PSK / Certificates | Legacy remote access |
| WireGuard | UDP 51820 | ChaCha20 | Public keys | Modern high-performance VPN |
| PPTP | TCP 1723 | MPPE (weak) | MS-CHAPv2 | Legacy — avoid in production |
PPTP is considered insecure. IKEv2/IPsec and SSL VPN are the current recommended options.
Go deeper
Related to this question
About these practice questions
Courseiva writes every PAS-C01 question from scratch — 1,616 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PAS-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PAS-C01 exam.