SOA-C02 Security and Compliance Practice Question
A company has an AWS account with multiple VPCs connected via a transit gateway. The SysOps administrator needs to ensure that all traffic between VPCs is encrypted in transit. Which solution should the administrator implement?
⚠ Common exam trap
Watch out — candidates often assume VPC peering provides encryption by default, but AWS does not encrypt traffic over peering connections; encryption must be explicitly added via VPN or other mechanisms.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Set up AWS Site-to-Site VPN connections between the VPCs via the transit gateway.
AWS Site-to-Site VPN connections between VPCs via a transit gateway can enforce IPsec encryption for all inter-VPC traffic. The transit gateway acts as a central hub, and each VPN connection encrypts traffic using IPsec tunnels, ensuring data confidentiality and integrity in transit. This meets the requirement for encrypted transit between VPCs without relying on third-party appliances.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Use VPC peering connections between the VPCs.
Why it's wrong here
VPC peering connections simply route private IP traffic between two VPCs over AWS's internal network; they do not provide any encryption of the data plane by default. All traffic shared via a peering connection is unencrypted at the network layer, and the peering relationship is non-transitive, so it does not scale to multiple VPCs without full-mesh peering. Even if you encrypted at the application layer, the question specifically asks for encryption at the network layer, which peering does not deliver.
- ✗
Use VPC endpoints to route traffic through AWS PrivateLink.
Why it's wrong here
VPC endpoints using AWS PrivateLink provide private, non-internet connectivity to AWS services or your own services via elastic network interfaces and Network Load Balancers, but they operate at the application/transport layer and do not encrypt traffic between VPCs. PrivateLink is designed to expose or consume services, not to create encrypted tunnels. Traffic over PrivateLink still relies on the VPC's network and any application-level TLS, so it cannot fulfill the requirement for an encryption mechanism at the network level.
- ✓
Set up AWS Site-to-Site VPN connections between the VPCs via the transit gateway.
Why this is correct
AWS Site-to-Site VPN connections establish IPsec tunnels that encrypt all traffic between the connected sites. By attaching these VPN connections to a transit gateway, you can interconnect multiple VPCs and route private traffic through those encrypted tunnels, achieving confidentiality for inter-VPC communication. This is the correct approach because the VPN terminates IPsec encryption at the transit gateway, and the transit gateway handles routing between all attached VPCs and VPN connections.
- ✗
Configure network ACLs to deny unencrypted traffic.
Why it's wrong here
Network ACLs are stateless, subnet-level firewalls that filter traffic based on source/destination IP addresses, ports, and protocols; they do not inspect payload content and cannot identify whether traffic is encrypted. Configuring NACLs to 'deny unencrypted traffic' is impossible because NACLs have no mechanism to detect encryption status. Even if you could set rules, NACLs are not a substitute for encryption, as they only allow or deny packets, never alter or protect their contents.
Quick reference
VPN Protocol Comparison
| Protocol | Port | Encryption | Authentication | Use Case |
|---|---|---|---|---|
| IKEv2 / IPsec | UDP 500 / 4500 | AES-256 | Certificates / PSK | Site-to-site & remote access |
| SSL / TLS VPN | TCP 443 | TLS 1.3 | Certificates / MFA | Clientless remote access |
| L2TP / IPsec | UDP 1701 | AES (IPsec) | PSK / Certificates | Legacy remote access |
| WireGuard | UDP 51820 | ChaCha20 | Public keys | Modern high-performance VPN |
| PPTP | TCP 1723 | MPPE (weak) | MS-CHAPv2 | Legacy — avoid in production |
PPTP is considered insecure. IKEv2/IPsec and SSL VPN are the current recommended options.
Go deeper
Related to this question
About these practice questions
One of 1,169 original SOA-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SOA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SOA-C02 exam.