SCS-C02 Data Protection Practice Question
A company wants to ensure that all data transferred between its on-premises data center and AWS is encrypted in transit. Which AWS service should be used to meet this requirement?
⚠ Common exam trap
SCS-C02 often tests the misconception that AWS Direct Connect encrypts traffic by default — it does not, and candidates must recognize that Site-to-Site VPN (or MACsec on Direct Connect) is required for encryption in transit.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
AWS Site-to-Site VPN
AWS Site-to-Site VPN encrypts data in transit between an on-premises network and AWS by establishing IPsec tunnels over the public internet, satisfying the requirement for encryption in transit. It uses IKE for key exchange and IPsec ESP for payload encryption, providing confidentiality and integrity for all traffic traversing the VPN connection. This is the standard AWS service for encrypted hybrid connectivity.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Amazon CloudFront
Why it's wrong here
Amazon CloudFront is a content delivery network that caches and accelerates content delivery through a global network of edge locations. It does not establish a site-to-site IPsec tunnel between a company's network and AWS, so it cannot provide the encrypted, private connectivity required for all data transferred between the two environments. HTTPS may protect web traffic, but it does not address general network traffic flowing between on-premises infrastructure and AWS.
- ✗
AWS Transit Gateway
Why it's wrong here
AWS Transit Gateway is a network transit hub that connects VPCs and on-premises networks using attachments and route tables, but it is purely a routing function. It does not apply encryption to the traffic that passes through it; packets traverse in their original, unencrypted form unless you attach a separate encrypted connectivity option like a VPN. Therefore, using Transit Gateway alone would leave data transferred between sites exposed.
- ✗
AWS Direct Connect
Why it's wrong here
AWS Direct Connect provides a dedicated, private physical link from an on-premises data center to AWS, avoiding the public internet, but it does not encrypt traffic by default. The link is assumed to be physically secure, yet that does not meet a strict 'encrypt all data' requirement. To ensure encryption, you must run an IPsec VPN over the Direct Connect connection (e.g., AWS Site-to-Site VPN on a public VIF) to protect the data payload.
- ✓
AWS Site-to-Site VPN
Why this is correct
AWS Site-to-Site VPN is the correct service because it builds an encrypted IPsec tunnel between a customer gateway and a virtual private gateway, encrypting all traffic in transit across the public internet. It uses IKE for key exchange and IPsec protocols like ESP to provide confidentiality and integrity for every packet. This directly satisfies the requirement to ensure all data transferred between the company's network and AWS is protected.
Quick reference
VPN Protocol Comparison
| Protocol | Port | Encryption | Authentication | Use Case |
|---|---|---|---|---|
| IKEv2 / IPsec | UDP 500 / 4500 | AES-256 | Certificates / PSK | Site-to-site & remote access |
| SSL / TLS VPN | TCP 443 | TLS 1.3 | Certificates / MFA | Clientless remote access |
| L2TP / IPsec | UDP 1701 | AES (IPsec) | PSK / Certificates | Legacy remote access |
| WireGuard | UDP 51820 | ChaCha20 | Public keys | Modern high-performance VPN |
| PPTP | TCP 1723 | MPPE (weak) | MS-CHAPv2 | Legacy — avoid in production |
PPTP is considered insecure. IKEv2/IPsec and SSL VPN are the current recommended options.
Go deeper
Related to this question
About these practice questions
One of 1,205 original SCS-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.