Courseiva
Infrastructure Security →hardMultiple Choice

SCS-C02 Infrastructure Security Practice Question

A company uses AWS Direct Connect to connect its on-premises data center to AWS. The connection is set up with a private VIF to a VPC using a virtual private gateway. The security team wants to encrypt all traffic between on-premises and the VPC. Which solution should be implemented?

⚠ Common exam trap

Watch out — candidates often assume Direct Connect private VIFs are inherently encrypted because they are 'private,' but AWS explicitly states that Direct Connect does not provide encryption—you must add IPsec yourself.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Set up an IPsec VPN over the Direct Connect private VIF

Direct Connect private VIFs do not natively encrypt traffic; they provide a private, dedicated network connection but the data traverses it in cleartext. By establishing an IPsec VPN tunnel over the private VIF, you encrypt all traffic between the on-premises network and the VPC, meeting the security team's requirement for encryption while still leveraging the low latency and reliability of Direct Connect.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Configure TLS on the applications

    Why it's wrong here

    TLS only encrypts the specific application protocols that implement it, such as HTTPS or LDAPS, and does not protect UDP traffic, syslog, NTP, or other IP-based communications crossing the Direct Connect link. Even if every application were individually enabled with TLS, the underlying network path between on-premises and the VPC would remain unencrypted, leaving metadata and non-application traffic exposed. This approach fails the requirement to secure the connection itself, rather than just the payloads of a few higher-layer protocols.

  • ✓

    Set up an IPsec VPN over the Direct Connect private VIF

    Why this is correct

    Setting up an IPsec VPN over the Direct Connect private VIF encapsulates all IP traffic between your on-premises network and the VPC, providing network-layer confidentiality and integrity while still using the private, low-latency Direct Connect path. IPsec operates at Layer 3, so it secures every protocol and service traversing the link, not just specific applications, and it is the standard way to add encryption because Direct Connect does not encrypt traffic natively. The VPN tunnel rides inside the private VIF, so you retain the dedicated bandwidth and avoid the public internet.

  • ✗

    Use a site-to-site VPN over the internet instead of Direct Connect

    Why it's wrong here

    Replacing Direct Connect with an internet-based site-to-site VPN forfeits the dedicated connection's benefits, including consistent throughput, lower latency, and greater reliability, because traffic now crosses the public internet where performance is variable and packet paths are uncontrolled. Although IPsec does encrypt the traffic, the public path introduces additional attack surface and potential for ISP outages or throttling. This option also sidesteps the requirement to secure the existing Direct Connect link rather than solving it; the goal is to encrypt the private connection, not to abandon it for a less deterministic network.

  • ✗

    Enable encryption on the Direct Connect private VIF

    Why it's wrong here

    AWS Direct Connect private VIFs are carried over an unencrypted physical link and do not have a console or API setting to enable encryption on the VIF itself. Even though MACsec (IEEE 802.1AE) can be enabled on a dedicated Direct Connect connection to encrypt traffic at Layer 2, it applies to the entire physical link and is not a private-VIF feature; it also requires dedicated connections with compatible hardware. Attempting to 'enable encryption on the private VIF' is not a supported operation, so the correct approach is to overlay IPsec over the VIF or use MACsec on the underlying dedicated connection.

Quick reference

VPN Protocol Comparison

ProtocolPortEncryptionAuthenticationUse Case
IKEv2 / IPsecUDP 500 / 4500AES-256Certificates / PSKSite-to-site & remote access
SSL / TLS VPNTCP 443TLS 1.3Certificates / MFAClientless remote access
L2TP / IPsecUDP 1701AES (IPsec)PSK / CertificatesLegacy remote access
WireGuardUDP 51820ChaCha20Public keysModern high-performance VPN
PPTPTCP 1723MPPE (weak)MS-CHAPv2Legacy — avoid in production

PPTP is considered insecure. IKEv2/IPsec and SSL VPN are the current recommended options.

About these practice questions

Courseiva writes every SCS-C02 question from scratch — 1,205 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.