SCS-C02 Data Protection Practice Question
A company wants to protect data in transit between an EC2 instance and an S3 bucket. Which method should be used?
⚠ Common exam trap
SCS-C02 often tests the confusion between network-layer encryption (VPN/IPsec) and application-layer TLS, leading candidates to choose VPN when the question specifically asks about protecting S3 API traffic.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use HTTPS endpoints for S3 API calls
To protect data in transit between an EC2 instance and an S3 bucket, you must use HTTPS endpoints for S3 API calls, which encrypts traffic using TLS. S3 supports HTTPS natively via its REST API endpoints, and this is the standard method to ensure encryption in transit for S3 access from EC2.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Use a VPN connection with IPsec
Why it's wrong here
An IPsec VPN establishes an encrypted tunnel between a customer gateway and the AWS side, but it typically protects traffic between on-premises networks and a VPC. It does not natively encrypt the application-layer S3 API requests originating from an EC2 instance; those requests are JSON/XML over HTTP(S) and would still need TLS to be protected end-to-end. Even if EC2 traffic were forced through a VPN, S3 would still require HTTPS for secure API access, so IPsec alone does not satisfy the requirement.
- ✗
Install an SSL certificate on the EC2 instance
Why it's wrong here
A TLS/SSL certificate on the EC2 instance is used to prove the server's identity when clients connect to it over HTTPS, commonly for a web application. When an EC2 instance initiates requests to S3, it is the TLS client and must validate S3's certificate; presenting its own certificate does nothing to protect the outbound request payload. Simply having a certificate installed does not encrypt traffic to S3 because S3's HTTPS endpoint is already secured by AWS-managed certificates.
- ✗
Use SSH to transfer files
Why it's wrong here
SSH is designed for secure command-line access and file transfer (SCP/SFTP) to a host running an SSH daemon, such as an EC2 instance. Amazon S3 does not offer an SSH service or endpoint, so SSH cannot be used to authenticate or transfer objects directly with S3. Even if you SSH into an EC2 instance, the S3 API calls executed from that instance are separate HTTPS requests and are not protected by the SSH session; you would need to use HTTPS or configure an SSH tunnel, which still ultimately requires HTTPS for the S3 API.
- ✓
Use HTTPS endpoints for S3 API calls
Why this is correct
Using HTTPS endpoints for S3 API calls means every request and response is encrypted with TLS, preventing attackers from reading or tampering with data in transit between an EC2 instance and S3. All AWS SDKs and the AWS CLI are configured to use HTTPS by default when sending S3 operations, and S3's TLS endpoints provide server authentication via AWS-managed certificates. This is the correct, native mechanism to meet the data-in-transit protection requirement for EC2-to-S3 communication.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
One of 1,205 original SCS-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.