Courseiva
Infrastructure Security →mediumMultiple Select

SCS-C02 Infrastructure Security Practice Question

Which TWO of the following are valid methods to protect sensitive data in transit between an on-premises data center and AWS? (Select TWO.)

⚠ Common exam trap

It's easy for candidates to assume AWS Transit Gateway or VPC Peering inherently encrypt traffic, but they do not; encryption must be explicitly added via VPN or Direct Connect with IPSec, and the exam tests this distinction between connectivity and encryption.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

AWS Site-to-Site VPN

AWS Site-to-Site VPN (Option B) creates an encrypted tunnel between an on-premises VPN device and a Virtual Private Gateway in AWS, using IPSec to protect data in transit. This ensures confidentiality and integrity of data crossing the public internet, making it a valid method for securing sensitive data between an on-premises data center and AWS.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    AWS Transit Gateway

    Why it's wrong here

    AWS Transit Gateway is a central hub that interconnects VPCs and on-premises networks via VPC attachments and VPN/Direct Connect attachments. It operates at Layer 3 and forwards packets between attachments, but it does not perform any encryption of the data payload; encryption only occurs if you attach an encrypted tunnel like an AWS Site-to-Site VPN. Since Transit Gateway alone provides no confidentiality or integrity protection for traffic, it is not a valid method for protecting sensitive data.

  • ✓

    AWS Site-to-Site VPN

    Why this is correct

    AWS Site-to-Site VPN creates an encrypted IPsec tunnel between your on-premises VPN device and the AWS VPN endpoint, using protocols like IKE and ESP to authenticate and encrypt all traffic traversing the public internet. The VPN tunnels support AES-128 or AES-256 encryption, along with perfect forward secrecy, ensuring confidentiality and data integrity. This native AWS service directly provides secure encryption of data in transit between your network and the VPC, making it a valid method to protect sensitive data.

  • ✗

    Internet Gateway

    Why it's wrong here

    An Internet Gateway is a horizontally scaled, redundant component that allows communication between a VPC and the internet. It performs network address translation (for IPv6) and routes traffic, but it is purely a Layer 3 forwarding device with no encryption capabilities. Traffic passing through an Internet Gateway is sent in cleartext unless the application itself handles encryption, so relying on it alone cannot protect sensitive data.

  • ✗

    VPC Peering

    Why it's wrong here

    VPC Peering connects two VPCs using the AWS private backbone, providing low-latency, private connectivity without traversing the public internet. Although the traffic is isolated from other AWS customers and is not exposed to the internet, it is not encrypted; AWS does not encrypt the data payload for VPC peering connections. Therefore, VPC peering alone does not meet the requirement for encrypting sensitive data in transit.

  • ✓

    AWS Direct Connect with IPSec VPN

    Why this is correct

    AWS Direct Connect establishes a private physical network connection from your data center to AWS, bypassing the public internet for lower latency and higher security. By layering an IPSec VPN over a Direct Connect virtual interface, you combine the private, dedicated circuit with encryption, ensuring that all traffic is both off the public internet and cryptographically protected. This hybrid approach is considered a valid method for protecting sensitive data, as it provides encryption while leveraging the reliability of Direct Connect.

Quick reference

VPN Protocol Comparison

ProtocolPortEncryptionAuthenticationUse Case
IKEv2 / IPsecUDP 500 / 4500AES-256Certificates / PSKSite-to-site & remote access
SSL / TLS VPNTCP 443TLS 1.3Certificates / MFAClientless remote access
L2TP / IPsecUDP 1701AES (IPsec)PSK / CertificatesLegacy remote access
WireGuardUDP 51820ChaCha20Public keysModern high-performance VPN
PPTPTCP 1723MPPE (weak)MS-CHAPv2Legacy — avoid in production

PPTP is considered insecure. IKEv2/IPsec and SSL VPN are the current recommended options.

About these practice questions

One of 1,205 original SCS-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.