mediumMultiple Select
CAS-004 Practice Question: A security architect is designing a hybrid cloud…
A security architect is designing a hybrid cloud environment where a web application hosted in AWS needs to securely access an on-premises database. The architect wants to minimize exposure to the internet and ensure encryption in transit. Which TWO techniques should the architect consider? (Choose two.)
⚠ Common exam trap
It's easy for candidates to confuse VPC peering with hybrid connectivity, not realizing it only works between VPCs within the same AWS region, or they assume TLS alone is sufficient for network-level security without addressing the underlying internet exposure.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Establish an IPsec VPN tunnel between the AWS VPC and the on-premises network.
Option A is correct because an IPsec VPN tunnel between the AWS VPC and the on-premises network creates an encrypted, private path over the internet, satisfying both the requirement to minimize public exposure and to ensure encryption in transit. Option B is correct because AWS Direct Connect provides a dedicated private network connection from on-premises to AWS that bypasses the public internet entirely, and it can be combined with encryption (e.g., MACsec or VPN over Direct Connect) to meet the in-transit encryption requirement. Option C is not correct here because Secrets Manager handles credential storage and rotation, not the secure network path or encryption in transit between the web app and the database. Option D is not correct because VPC peering only connects VPCs within AWS (or between AWS VPCs), not an AWS VPC to an on-premises network. Option E is not correct because TLS encrypts the application-to-database session but does not by itself minimize internet exposure, since the traffic could still traverse the public internet.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Establish an IPsec VPN tunnel between the AWS VPC and the on-premises network.
Why this is correct
An IPsec VPN tunnel encrypts traffic in transit between the AWS VPC and on-premises network, satisfying the encryption requirement. Because it runs over the public internet, it does not fully eliminate internet exposure, but it is a valid technique for secure hybrid connectivity.
- ✓
Use AWS Direct Connect to create a dedicated private network connection from on-premises to AWS.
Why this is correct
AWS Direct Connect provides a dedicated private network path from on-premises to AWS, bypassing the public internet entirely. This satisfies the requirement to minimise internet exposure, though encryption in transit must be added separately since Direct Connect is not encrypted by default.
- ✗
Store database credentials in AWS Secrets Manager and retrieve them at runtime.
Why it's wrong here
Secrets Manager protects credential storage, not the network path or transport channel, so it leaves the database reachable over the internet and unencrypted. It is tempting because centralised secret rotation genuinely removes hard-coded credentials; that would be the right control when the requirement is credential lifecycle management rather than private connectivity.
- ✗
Configure VPC peering between the AWS VPC and the on-premises network.
Why it's wrong here
VPC peering connects two AWS VPCs; it cannot extend to an on-premises network, so no private path to the database is created. It is tempting because peering does provide private, non-internet routing, and would be correct if both the application and database were AWS-hosted VPCs.
- ✗
Configure the web application to connect to the database using TLS encryption.
Why it's wrong here
TLS encrypts data in transit but does nothing to reduce internet exposure, since the connection still traverses public networks. It is tempting because encryption in transit is explicitly required, and TLS would be the right answer if the question asked only how to protect confidentiality of the database traffic.
Quick reference
VPN Protocol Comparison
| Protocol | Port | Encryption | Authentication | Use Case |
|---|---|---|---|---|
| IKEv2 / IPsec | UDP 500 / 4500 | AES-256 | Certificates / PSK | Site-to-site & remote access |
| SSL / TLS VPN | TCP 443 | TLS 1.3 | Certificates / MFA | Clientless remote access |
| L2TP / IPsec | UDP 1701 | AES (IPsec) | PSK / Certificates | Legacy remote access |
| WireGuard | UDP 51820 | ChaCha20 | Public keys | Modern high-performance VPN |
| PPTP | TCP 1723 | MPPE (weak) | MS-CHAPv2 | Legacy — avoid in production |
PPTP is considered insecure. IKEv2/IPsec and SSL VPN are the current recommended options.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CAS-005 question from scratch — 973 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.