AWS Certified Advanced Networking – Specialty (ANS-C01)Network Security, Compliance, and GovernanceHard

A research institution is deploying a new application that will process highly confidential data. They need to ensure that all data in transit across public networks is encrypted end-to-end to meet stringent privacy regulations. The application will communicate between different AWS regions and also with on-premises data centers over the internet. Which solution provides the most secure and compliant method for encrypting data in transit in this scenario?

  1. AAWS Direct Connect with MACsec
  2. BSSL/TLS encryption within the application layer
  3. CAWS PrivateLink for inter-region communication
  4. DAWS Site-to-Site VPN and IPsec VPN over the internet
Show answer & explanation

Correct answer: D. AWS Site-to-Site VPN and IPsec VPN over the internet

AWS Site-to-Site VPN (which uses IPsec) provides encrypted tunnels over the public internet, making it suitable for encrypting data in transit between different AWS regions (by routing through the VPN) and between AWS and on-premises data centers. IPsec is a robust, widely accepted protocol for network-layer encryption, ensuring end-to-end security over public networks, which is critical for highly confidential data and stringent privacy regulations.

Why the other options are wrong

  • A. Direct Connect with MACsec provides Layer 2 encryption over a *private* dedicated connection, not over public networks, and is not designed for inter-region communication over the internet.
  • B. SSL/TLS encryption at the application layer protects application data but may not cover all underlying network traffic or management plane communication, and its implementation depends on every application being correctly configured.
  • C. AWS PrivateLink provides private connectivity to services within the AWS network, but it does not encrypt traffic traversing the public internet between regions or to on-premises data centers for general communication.

AWS Site-to-Site VPN

A service that creates an encrypted connection between your on-premises network and your AWS VPCs over the public internet.

  • Uses IPsec for strong encryption.
  • Suitable for connecting on-premises to AWS and inter-region communication.
  • Provides secure tunnels over potentially unsecure public networks.

Memory trick: VPN 'IPsec' secures 'PUBLIC' paths.

More Network Security, Compliance, and Governance questions