SCS-C02 Infrastructure Security Practice Question
A company uses AWS Direct Connect to connect its on-premises data center to AWS. The connection is set up with a private VIF to a VPC using a virtual private gateway. The security team wants to encrypt all traffic between on-premises and the VPC. Which solution should be implemented?
⚠ Common exam trap
Watch out — candidates often assume Direct Connect private VIFs are inherently encrypted because they are 'private,' but AWS explicitly states that Direct Connect does not provide encryption—you must add IPsec yourself.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Set up an IPsec VPN over the Direct Connect private VIF
Direct Connect private VIFs do not natively encrypt traffic; they provide a private, dedicated network connection but the data traverses it in cleartext. By establishing an IPsec VPN tunnel over the private VIF, you encrypt all traffic between the on-premises network and the VPC, meeting the security team's requirement for encryption while still leveraging the low latency and reliability of Direct Connect.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Configure TLS on the applications
Why it's wrong here
TLS only encrypts the specific application protocols that implement it, such as HTTPS or LDAPS, and does not protect UDP traffic, syslog, NTP, or other IP-based communications crossing the Direct Connect link. Even if every application were individually enabled with TLS, the underlying network path between on-premises and the VPC would remain unencrypted, leaving metadata and non-application traffic exposed. This approach fails the requirement to secure the connection itself, rather than just the payloads of a few higher-layer protocols.
- ✓
Set up an IPsec VPN over the Direct Connect private VIF
Why this is correct
Setting up an IPsec VPN over the Direct Connect private VIF encapsulates all IP traffic between your on-premises network and the VPC, providing network-layer confidentiality and integrity while still using the private, low-latency Direct Connect path. IPsec operates at Layer 3, so it secures every protocol and service traversing the link, not just specific applications, and it is the standard way to add encryption because Direct Connect does not encrypt traffic natively. The VPN tunnel rides inside the private VIF, so you retain the dedicated bandwidth and avoid the public internet.
- ✗
Use a site-to-site VPN over the internet instead of Direct Connect
Why it's wrong here
Replacing Direct Connect with an internet-based site-to-site VPN forfeits the dedicated connection's benefits, including consistent throughput, lower latency, and greater reliability, because traffic now crosses the public internet where performance is variable and packet paths are uncontrolled. Although IPsec does encrypt the traffic, the public path introduces additional attack surface and potential for ISP outages or throttling. This option also sidesteps the requirement to secure the existing Direct Connect link rather than solving it; the goal is to encrypt the private connection, not to abandon it for a less deterministic network.
- ✗
Enable encryption on the Direct Connect private VIF
Why it's wrong here
AWS Direct Connect private VIFs are carried over an unencrypted physical link and do not have a console or API setting to enable encryption on the VIF itself. Even though MACsec (IEEE 802.1AE) can be enabled on a dedicated Direct Connect connection to encrypt traffic at Layer 2, it applies to the entire physical link and is not a private-VIF feature; it also requires dedicated connections with compatible hardware. Attempting to 'enable encryption on the private VIF' is not a supported operation, so the correct approach is to overlay IPsec over the VIF or use MACsec on the underlying dedicated connection.
Quick reference
VPN Protocol Comparison
| Protocol | Port | Encryption | Authentication | Use Case |
|---|---|---|---|---|
| IKEv2 / IPsec | UDP 500 / 4500 | AES-256 | Certificates / PSK | Site-to-site & remote access |
| SSL / TLS VPN | TCP 443 | TLS 1.3 | Certificates / MFA | Clientless remote access |
| L2TP / IPsec | UDP 1701 | AES (IPsec) | PSK / Certificates | Legacy remote access |
| WireGuard | UDP 51820 | ChaCha20 | Public keys | Modern high-performance VPN |
| PPTP | TCP 1723 | MPPE (weak) | MS-CHAPv2 | Legacy — avoid in production |
PPTP is considered insecure. IKEv2/IPsec and SSL VPN are the current recommended options.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SCS-C02 question from scratch — 1,205 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.