Courseiva
Security and Compliance →hardMultiple Choice

SOA-C02 Security and Compliance Practice Question

A company has an AWS account with multiple VPCs connected via a transit gateway. The SysOps administrator needs to ensure that all traffic between VPCs is encrypted in transit. Which solution should the administrator implement?

⚠ Common exam trap

Watch out — candidates often assume VPC peering provides encryption by default, but AWS does not encrypt traffic over peering connections; encryption must be explicitly added via VPN or other mechanisms.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Set up AWS Site-to-Site VPN connections between the VPCs via the transit gateway.

AWS Site-to-Site VPN connections between VPCs via a transit gateway can enforce IPsec encryption for all inter-VPC traffic. The transit gateway acts as a central hub, and each VPN connection encrypts traffic using IPsec tunnels, ensuring data confidentiality and integrity in transit. This meets the requirement for encrypted transit between VPCs without relying on third-party appliances.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Use VPC peering connections between the VPCs.

    Why it's wrong here

    VPC peering connections simply route private IP traffic between two VPCs over AWS's internal network; they do not provide any encryption of the data plane by default. All traffic shared via a peering connection is unencrypted at the network layer, and the peering relationship is non-transitive, so it does not scale to multiple VPCs without full-mesh peering. Even if you encrypted at the application layer, the question specifically asks for encryption at the network layer, which peering does not deliver.

  • ✗

    Use VPC endpoints to route traffic through AWS PrivateLink.

    Why it's wrong here

    VPC endpoints using AWS PrivateLink provide private, non-internet connectivity to AWS services or your own services via elastic network interfaces and Network Load Balancers, but they operate at the application/transport layer and do not encrypt traffic between VPCs. PrivateLink is designed to expose or consume services, not to create encrypted tunnels. Traffic over PrivateLink still relies on the VPC's network and any application-level TLS, so it cannot fulfill the requirement for an encryption mechanism at the network level.

  • ✓

    Set up AWS Site-to-Site VPN connections between the VPCs via the transit gateway.

    Why this is correct

    AWS Site-to-Site VPN connections establish IPsec tunnels that encrypt all traffic between the connected sites. By attaching these VPN connections to a transit gateway, you can interconnect multiple VPCs and route private traffic through those encrypted tunnels, achieving confidentiality for inter-VPC communication. This is the correct approach because the VPN terminates IPsec encryption at the transit gateway, and the transit gateway handles routing between all attached VPCs and VPN connections.

  • ✗

    Configure network ACLs to deny unencrypted traffic.

    Why it's wrong here

    Network ACLs are stateless, subnet-level firewalls that filter traffic based on source/destination IP addresses, ports, and protocols; they do not inspect payload content and cannot identify whether traffic is encrypted. Configuring NACLs to 'deny unencrypted traffic' is impossible because NACLs have no mechanism to detect encryption status. Even if you could set rules, NACLs are not a substitute for encryption, as they only allow or deny packets, never alter or protect their contents.

Quick reference

VPN Protocol Comparison

ProtocolPortEncryptionAuthenticationUse Case
IKEv2 / IPsecUDP 500 / 4500AES-256Certificates / PSKSite-to-site & remote access
SSL / TLS VPNTCP 443TLS 1.3Certificates / MFAClientless remote access
L2TP / IPsecUDP 1701AES (IPsec)PSK / CertificatesLegacy remote access
WireGuardUDP 51820ChaCha20Public keysModern high-performance VPN
PPTPTCP 1723MPPE (weak)MS-CHAPv2Legacy — avoid in production

PPTP is considered insecure. IKEv2/IPsec and SSL VPN are the current recommended options.

About these practice questions

One of 1,169 original SOA-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SOA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SOA-C02 exam.