SCS-C02 Infrastructure Security Practice Question
Which TWO of the following are valid methods to protect sensitive data in transit between an on-premises data center and AWS? (Select TWO.)
⚠ Common exam trap
It's easy for candidates to assume AWS Transit Gateway or VPC Peering inherently encrypt traffic, but they do not; encryption must be explicitly added via VPN or Direct Connect with IPSec, and the exam tests this distinction between connectivity and encryption.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
AWS Site-to-Site VPN
AWS Site-to-Site VPN (Option B) creates an encrypted tunnel between an on-premises VPN device and a Virtual Private Gateway in AWS, using IPSec to protect data in transit. This ensures confidentiality and integrity of data crossing the public internet, making it a valid method for securing sensitive data between an on-premises data center and AWS.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
AWS Transit Gateway
Why it's wrong here
AWS Transit Gateway is a central hub that interconnects VPCs and on-premises networks via VPC attachments and VPN/Direct Connect attachments. It operates at Layer 3 and forwards packets between attachments, but it does not perform any encryption of the data payload; encryption only occurs if you attach an encrypted tunnel like an AWS Site-to-Site VPN. Since Transit Gateway alone provides no confidentiality or integrity protection for traffic, it is not a valid method for protecting sensitive data.
- ✓
AWS Site-to-Site VPN
Why this is correct
AWS Site-to-Site VPN creates an encrypted IPsec tunnel between your on-premises VPN device and the AWS VPN endpoint, using protocols like IKE and ESP to authenticate and encrypt all traffic traversing the public internet. The VPN tunnels support AES-128 or AES-256 encryption, along with perfect forward secrecy, ensuring confidentiality and data integrity. This native AWS service directly provides secure encryption of data in transit between your network and the VPC, making it a valid method to protect sensitive data.
- ✗
Internet Gateway
Why it's wrong here
An Internet Gateway is a horizontally scaled, redundant component that allows communication between a VPC and the internet. It performs network address translation (for IPv6) and routes traffic, but it is purely a Layer 3 forwarding device with no encryption capabilities. Traffic passing through an Internet Gateway is sent in cleartext unless the application itself handles encryption, so relying on it alone cannot protect sensitive data.
- ✗
VPC Peering
Why it's wrong here
VPC Peering connects two VPCs using the AWS private backbone, providing low-latency, private connectivity without traversing the public internet. Although the traffic is isolated from other AWS customers and is not exposed to the internet, it is not encrypted; AWS does not encrypt the data payload for VPC peering connections. Therefore, VPC peering alone does not meet the requirement for encrypting sensitive data in transit.
- ✓
AWS Direct Connect with IPSec VPN
Why this is correct
AWS Direct Connect establishes a private physical network connection from your data center to AWS, bypassing the public internet for lower latency and higher security. By layering an IPSec VPN over a Direct Connect virtual interface, you combine the private, dedicated circuit with encryption, ensuring that all traffic is both off the public internet and cryptographically protected. This hybrid approach is considered a valid method for protecting sensitive data, as it provides encryption while leveraging the reliability of Direct Connect.
Quick reference
VPN Protocol Comparison
| Protocol | Port | Encryption | Authentication | Use Case |
|---|---|---|---|---|
| IKEv2 / IPsec | UDP 500 / 4500 | AES-256 | Certificates / PSK | Site-to-site & remote access |
| SSL / TLS VPN | TCP 443 | TLS 1.3 | Certificates / MFA | Clientless remote access |
| L2TP / IPsec | UDP 1701 | AES (IPsec) | PSK / Certificates | Legacy remote access |
| WireGuard | UDP 51820 | ChaCha20 | Public keys | Modern high-performance VPN |
| PPTP | TCP 1723 | MPPE (weak) | MS-CHAPv2 | Legacy — avoid in production |
PPTP is considered insecure. IKEv2/IPsec and SSL VPN are the current recommended options.
Go deeper
Related to this question
About these practice questions
One of 1,205 original SCS-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.