AWS Certified Advanced Networking – Specialty (ANS-C01)Network Security, Compliance, and GovernanceHard

A global e-commerce company uses AWS for its payment processing systems. Due to PCI DSS compliance requirements, all data in transit for these systems must be encrypted. The company heavily relies on AWS Direct Connect for connectivity between its on-premises data centers and AWS VPCs. Which solution provides the strongest encryption and meets the compliance requirements for data in transit over Direct Connect connections?

  1. AUsing AWS PrivateLink for secure service access
  2. BConfiguring AWS Direct Connect with MACsec (Media Access Control Security)
  3. CEstablishing IPsec VPN tunnels over AWS Direct Connect
  4. DImplementing SSL/TLS encryption at the application layer
Show answer & explanation

Correct answer: C. Establishing IPsec VPN tunnels over AWS Direct Connect

While MACsec provides encryption at Layer 2 over Direct Connect, it's typically for point-to-point connections and might require specific hardware. IPsec VPN tunnels over Direct Connect provide robust, end-to-end encryption at Layer 3, which is generally considered the strongest and most flexible solution for securing data in transit over Direct Connect for compliance standards like PCI DSS, allowing for cryptographic separation of traffic. SSL/TLS is application-layer encryption and doesn't cover all traffic, while PrivateLink secures access to specific services, not all data in transit over Direct Connect.

Why the other options are wrong

  • A. AWS PrivateLink secures access to specific AWS services or your own services within a VPC, but it does not encrypt all data in transit over a Direct Connect connection itself.
  • B. MACsec provides Layer 2 encryption but is less flexible for multi-VPC or complex routing scenarios compared to IPsec and might have hardware prerequisites. It also doesn't provide the same logical separation as an IPsec tunnel.
  • D. SSL/TLS encrypts at the application layer, not all data in transit at the network layer, and would require every application to be configured correctly.

IPsec VPN over Direct Connect

Combining AWS Direct Connect with IPsec VPN tunnels to provide both dedicated network connectivity and strong, end-to-end encryption for data in transit.

  • Provides Layer 3 encryption.
  • Meets high security and compliance standards (e.g., PCI DSS).
  • Offers cryptographic isolation of traffic over the Direct Connect link.

Memory trick: Direct Connect plus 'IPsec' makes data 'SECURE'.

More Network Security, Compliance, and Governance questions