Courseiva

SOA-C02 Networking and Content Delivery Practice Question

A SysOps administrator needs to ensure that all traffic between an on-premises data center and the AWS VPC is encrypted and goes over the internet. Which AWS service should be used?

⚠ Common exam trap

Test-takers frequently confuse AWS Site-to-Site VPN with AWS Direct Connect, assuming Direct Connect provides encryption by default, but Direct Connect is a private connection that does not include encryption unless a VPN is layered on top.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

AWS Site-to-Site VPN

AWS Site-to-Site VPN creates an encrypted tunnel between an on-premises data center and an AWS VPC using IPsec (IKEv1/IKEv2) over the public internet. This meets the requirement for encryption and internet-based connectivity, as the VPN traffic traverses the internet but is secured by IPsec tunnels.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    AWS Site-to-Site VPN

    Why this is correct

    AWS Site-to-Site VPN creates encrypted IPsec tunnels between the customer's on-premises network and AWS virtual private gateways or transit gateways. These tunnels, which leverage the public internet, provide secure and confidential transmission of data by encrypting traffic in transit. The service also automatically provisions two tunnels for high availability, ensuring redundant connectivity.

  • ✗

    VPC Peering

    Why it's wrong here

    VPC Peering is used exclusively to connect two or more VPCs within AWS, allowing private IP address routing between them. It does not support connectivity to on-premises infrastructure, nor does it provide any encryption or VPN capabilities. Since the objective involves connecting an on-premises network, VPC Peering is not a valid solution.

  • ✗

    AWS Transit Gateway

    Why it's wrong here

    AWS Transit Gateway acts as a central hub for interconnecting VPCs and on-premises networks, simplifying network topology. However, Transit Gateway itself does not establish a connection to on-premises; it relies on an attachment such as a Site-to-Site VPN or Direct Connect. Therefore, while it could be part of the architecture, it is not the direct mechanism that secures traffic over the internet.

  • ✗

    AWS Direct Connect

    Why it's wrong here

    AWS Direct Connect provides a private, dedicated physical link between an on-premises data center and AWS, typically through a partner or colocation provider. This connection does not traverse the public internet and thus does not use IPsec encryption as part of its core data transport. While it offers lower latency and consistent bandwidth, it is not a solution for encrypted traffic over the internet, which is the explicit requirement in the question.

Quick reference

VPN Protocol Comparison

ProtocolPortEncryptionAuthenticationUse Case
IKEv2 / IPsecUDP 500 / 4500AES-256Certificates / PSKSite-to-site & remote access
SSL / TLS VPNTCP 443TLS 1.3Certificates / MFAClientless remote access
L2TP / IPsecUDP 1701AES (IPsec)PSK / CertificatesLegacy remote access
WireGuardUDP 51820ChaCha20Public keysModern high-performance VPN
PPTPTCP 1723MPPE (weak)MS-CHAPv2Legacy — avoid in production

PPTP is considered insecure. IKEv2/IPsec and SSL VPN are the current recommended options.

About these practice questions

One of 1,169 original SOA-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SOA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SOA-C02 exam.