Courseiva
Operations and MaintenancehardMultiple ChoiceObjective-mapped

PAS-C01 Operations and Maintenance Practice Question

An SAP system is running on EC2 instances in a VPC. The security team requires that all traffic between the SAP application and database tiers be encrypted in transit. Which solution meets this requirement with minimal latency?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Use security groups to allow traffic only between the instances, with IPsec configured

Security groups act as a virtual firewall, and when combined with IPsec configuration on the EC2 instances, they provide end-to-end encryption between the application and database tiers. This method introduces minimal latency because the encryption is handled by the instances themselves without additional network appliances or load balancers. Option A is incorrect because an AWS Site-to-Site VPN is designed for connecting on-premises networks to AWS, not for internal traffic between tiers. Option C is incorrect because an Application Load Balancer with TLS termination adds unnecessary latency and does not encrypt traffic beyond the load balancer. Option D is incorrect because enabling HTTPS alone does not encrypt database traffic, as database protocols typically use different ports and are not HTTP-based.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Use an AWS Site-to-Site VPN connection between the tiers

    Why it's wrong here

    Incorrect. AWS Site-to-Site VPN is for connecting on-premises networks to AWS, not for traffic between EC2 instances within the same VPC. It adds unnecessary latency and complexity.

  • Use security groups to allow traffic only between the instances, with IPsec configured

    Why this is correct

    Correct. Configuring IPsec directly on the EC2 instances and using security groups to control traffic provides encryption in transit with minimal latency, as it works at the network layer without additional components.

  • Use an Application Load Balancer with TLS termination in front of the database tier

    Why it's wrong here

    Incorrect. An Application Load Balancer with TLS termination adds an extra network hop and processing delay, increasing latency. It is not ideal for low-latency internal encryption.

  • Install TLS certificates on each EC2 instance and enable HTTPS

    Why it's wrong here

    Incorrect. Installing TLS certificates and enabling HTTPS encrypts traffic at the application layer, which adds CPU overhead and latency compared to network-layer encryption like IPsec.

Quick reference

VPN Protocol Comparison

ProtocolPortEncryptionAuthenticationUse Case
IKEv2 / IPsecUDP 500 / 4500AES-256Certificates / PSKSite-to-site & remote access
SSL / TLS VPNTCP 443TLS 1.3Certificates / MFAClientless remote access
L2TP / IPsecUDP 1701AES (IPsec)PSK / CertificatesLegacy remote access
WireGuardUDP 51820ChaCha20Public keysModern high-performance VPN
PPTPTCP 1723MPPE (weak)MS-CHAPv2Legacy — avoid in production

PPTP is considered insecure. IKEv2/IPsec and SSL VPN are the current recommended options.

About these practice questions

Courseiva writes every PAS-C01 question from scratch — 1,616 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PAS-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PAS-C01 exam.