SCS-C02 Data Protection Practice Question
A company needs to ensure that data in transit between an on-premises data center and Amazon S3 is encrypted. Which AWS service should be used to establish a dedicated encrypted connection?
⚠ Common exam trap
Watch out — candidates often assume Direct Connect alone provides encryption, but it does not—it only provides a private, dedicated physical link; encryption must be added via a VPN overlay, which is why the combination is the correct answer.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
AWS Direct Connect with VPN
AWS Direct Connect provides a dedicated, private network connection from an on-premises data center to AWS, but it does not inherently encrypt data in transit. By combining Direct Connect with a VPN (IPsec tunnel), you get both a dedicated connection and encryption of all traffic between the on-premises network and Amazon S3. This ensures data in transit is protected while avoiding the public internet.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
AWS Transit Gateway
Why it's wrong here
AWS Transit Gateway is a central hub that interconnects VPCs, VPNs, and Direct Connect attachments, but it is not a connection type that by itself carries traffic from your on-premises environment. To use Transit Gateway, you must first attach a separate underlying connectivity service such as a Site-to-Site VPN or Direct Connect. It provides routing and traffic management, not the physical or encrypted data path, so it cannot be the direct answer for ensuring secure in-transit data between on-premises and AWS.
- ✗
AWS Site-to-Site VPN
Why it's wrong here
AWS Site-to-Site VPN creates an encrypted IPsec tunnel between your on-premises router and an AWS VPN endpoint, so it does protect data in transit. However, those tunnels traverse the public internet, meaning the connection is not dedicated and is subject to internet-based variability, latency, and potential congestion. If the company's requirement includes a private, dedicated link between the data center and AWS, Site-to-Site VPN alone falls short because it lacks the dedicated physical infrastructure that Direct Connect provides.
- ✓
AWS Direct Connect with VPN
Why this is correct
AWS Direct Connect with VPN is the correct combination because Direct Connect gives you a dedicated, private network connection that bypasses the public internet, offering consistent latency and bandwidth. Since Direct Connect alone does not encrypt your traffic, the VPN overlay (typically IPsec) is added to encrypt data in transit over that private connection. This pairing satisfies both explicit requirements: a dedicated transport path and encryption for all data between the on-premises environment and AWS.
- ✗
AWS Client VPN
Why it's wrong here
AWS Client VPN is a managed, OpenVPN-based remote access service that enables individual users to securely connect from their local devices to AWS or on-premises networks. It is not designed for persistent site-to-site connectivity between an on-premises data center and AWS, which would require a network-to-network tunnel. The scenario involves interconnecting corporate networks, not remote user clients, so Client VPN is architecturally inappropriate for this requirement.
Quick reference
VPN Protocol Comparison
| Protocol | Port | Encryption | Authentication | Use Case |
|---|---|---|---|---|
| IKEv2 / IPsec | UDP 500 / 4500 | AES-256 | Certificates / PSK | Site-to-site & remote access |
| SSL / TLS VPN | TCP 443 | TLS 1.3 | Certificates / MFA | Clientless remote access |
| L2TP / IPsec | UDP 1701 | AES (IPsec) | PSK / Certificates | Legacy remote access |
| WireGuard | UDP 51820 | ChaCha20 | Public keys | Modern high-performance VPN |
| PPTP | TCP 1723 | MPPE (weak) | MS-CHAPv2 | Legacy — avoid in production |
PPTP is considered insecure. IKEv2/IPsec and SSL VPN are the current recommended options.
Go deeper
Related to this question
About these practice questions
This SCS-C02 question is part of Courseiva's 1,205-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.