Courseiva
Data Protection →easyMultiple Choice

SCS-C02 Data Protection Practice Question

A company needs to ensure that data in transit between an on-premises data center and Amazon S3 is encrypted. Which AWS service should be used to establish a dedicated encrypted connection?

⚠ Common exam trap

Watch out — candidates often assume Direct Connect alone provides encryption, but it does not—it only provides a private, dedicated physical link; encryption must be added via a VPN overlay, which is why the combination is the correct answer.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

AWS Direct Connect with VPN

AWS Direct Connect provides a dedicated, private network connection from an on-premises data center to AWS, but it does not inherently encrypt data in transit. By combining Direct Connect with a VPN (IPsec tunnel), you get both a dedicated connection and encryption of all traffic between the on-premises network and Amazon S3. This ensures data in transit is protected while avoiding the public internet.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    AWS Transit Gateway

    Why it's wrong here

    AWS Transit Gateway is a central hub that interconnects VPCs, VPNs, and Direct Connect attachments, but it is not a connection type that by itself carries traffic from your on-premises environment. To use Transit Gateway, you must first attach a separate underlying connectivity service such as a Site-to-Site VPN or Direct Connect. It provides routing and traffic management, not the physical or encrypted data path, so it cannot be the direct answer for ensuring secure in-transit data between on-premises and AWS.

  • ✗

    AWS Site-to-Site VPN

    Why it's wrong here

    AWS Site-to-Site VPN creates an encrypted IPsec tunnel between your on-premises router and an AWS VPN endpoint, so it does protect data in transit. However, those tunnels traverse the public internet, meaning the connection is not dedicated and is subject to internet-based variability, latency, and potential congestion. If the company's requirement includes a private, dedicated link between the data center and AWS, Site-to-Site VPN alone falls short because it lacks the dedicated physical infrastructure that Direct Connect provides.

  • ✓

    AWS Direct Connect with VPN

    Why this is correct

    AWS Direct Connect with VPN is the correct combination because Direct Connect gives you a dedicated, private network connection that bypasses the public internet, offering consistent latency and bandwidth. Since Direct Connect alone does not encrypt your traffic, the VPN overlay (typically IPsec) is added to encrypt data in transit over that private connection. This pairing satisfies both explicit requirements: a dedicated transport path and encryption for all data between the on-premises environment and AWS.

  • ✗

    AWS Client VPN

    Why it's wrong here

    AWS Client VPN is a managed, OpenVPN-based remote access service that enables individual users to securely connect from their local devices to AWS or on-premises networks. It is not designed for persistent site-to-site connectivity between an on-premises data center and AWS, which would require a network-to-network tunnel. The scenario involves interconnecting corporate networks, not remote user clients, so Client VPN is architecturally inappropriate for this requirement.

Quick reference

VPN Protocol Comparison

ProtocolPortEncryptionAuthenticationUse Case
IKEv2 / IPsecUDP 500 / 4500AES-256Certificates / PSKSite-to-site & remote access
SSL / TLS VPNTCP 443TLS 1.3Certificates / MFAClientless remote access
L2TP / IPsecUDP 1701AES (IPsec)PSK / CertificatesLegacy remote access
WireGuardUDP 51820ChaCha20Public keysModern high-performance VPN
PPTPTCP 1723MPPE (weak)MS-CHAPv2Legacy — avoid in production

PPTP is considered insecure. IKEv2/IPsec and SSL VPN are the current recommended options.

About these practice questions

This SCS-C02 question is part of Courseiva's 1,205-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.