Courseiva
Data Protection →easyMultiple Choice

SCS-C02 Data Protection Practice Question

A company wants to ensure that all data transferred between its on-premises data center and AWS is encrypted in transit. Which AWS service should be used to meet this requirement?

⚠ Common exam trap

SCS-C02 often tests the misconception that AWS Direct Connect encrypts traffic by default — it does not, and candidates must recognize that Site-to-Site VPN (or MACsec on Direct Connect) is required for encryption in transit.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

AWS Site-to-Site VPN

AWS Site-to-Site VPN encrypts data in transit between an on-premises network and AWS by establishing IPsec tunnels over the public internet, satisfying the requirement for encryption in transit. It uses IKE for key exchange and IPsec ESP for payload encryption, providing confidentiality and integrity for all traffic traversing the VPN connection. This is the standard AWS service for encrypted hybrid connectivity.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Amazon CloudFront

    Why it's wrong here

    Amazon CloudFront is a content delivery network that caches and accelerates content delivery through a global network of edge locations. It does not establish a site-to-site IPsec tunnel between a company's network and AWS, so it cannot provide the encrypted, private connectivity required for all data transferred between the two environments. HTTPS may protect web traffic, but it does not address general network traffic flowing between on-premises infrastructure and AWS.

  • ✗

    AWS Transit Gateway

    Why it's wrong here

    AWS Transit Gateway is a network transit hub that connects VPCs and on-premises networks using attachments and route tables, but it is purely a routing function. It does not apply encryption to the traffic that passes through it; packets traverse in their original, unencrypted form unless you attach a separate encrypted connectivity option like a VPN. Therefore, using Transit Gateway alone would leave data transferred between sites exposed.

  • ✗

    AWS Direct Connect

    Why it's wrong here

    AWS Direct Connect provides a dedicated, private physical link from an on-premises data center to AWS, avoiding the public internet, but it does not encrypt traffic by default. The link is assumed to be physically secure, yet that does not meet a strict 'encrypt all data' requirement. To ensure encryption, you must run an IPsec VPN over the Direct Connect connection (e.g., AWS Site-to-Site VPN on a public VIF) to protect the data payload.

  • ✓

    AWS Site-to-Site VPN

    Why this is correct

    AWS Site-to-Site VPN is the correct service because it builds an encrypted IPsec tunnel between a customer gateway and a virtual private gateway, encrypting all traffic in transit across the public internet. It uses IKE for key exchange and IPsec protocols like ESP to provide confidentiality and integrity for every packet. This directly satisfies the requirement to ensure all data transferred between the company's network and AWS is protected.

Quick reference

VPN Protocol Comparison

ProtocolPortEncryptionAuthenticationUse Case
IKEv2 / IPsecUDP 500 / 4500AES-256Certificates / PSKSite-to-site & remote access
SSL / TLS VPNTCP 443TLS 1.3Certificates / MFAClientless remote access
L2TP / IPsecUDP 1701AES (IPsec)PSK / CertificatesLegacy remote access
WireGuardUDP 51820ChaCha20Public keysModern high-performance VPN
PPTPTCP 1723MPPE (weak)MS-CHAPv2Legacy — avoid in production

PPTP is considered insecure. IKEv2/IPsec and SSL VPN are the current recommended options.

About these practice questions

One of 1,205 original SCS-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.