AWS Certified Advanced Networking – Specialty (ANS-C01)Network Security, Compliance, and GovernanceMedium

A global enterprise uses AWS Direct Connect to establish a private connection between their on-premises data centers and their AWS VPCs. They need to ensure that all data transmitted over these Direct Connect connections is encrypted in transit to meet stringent regulatory requirements. Which solution provides the MOST secure and compliant method for encrypting data over AWS Direct Connect?

  1. AUse AWS PrivateLink to connect to services, which encrypts traffic by default.
  2. BEnable MACsec encryption on the Direct Connect connection at the physical layer.
  3. CConfigure a VPN over Direct Connect using AWS Site-to-Site VPN.
  4. DImplement client-side encryption for all data before sending it over Direct Connect.
Show answer & explanation

Correct answer: C. Configure a VPN over Direct Connect using AWS Site-to-Site VPN.

While Direct Connect provides a private connection, it does not encrypt data in transit by default. To add encryption, a VPN over Direct Connect is the recommended and most common solution. AWS Site-to-Site VPN establishes IPsec tunnels over the Direct Connect connection, encrypting all data transmitted.

Why the other options are wrong

  • A. AWS PrivateLink provides private connectivity to AWS services without traversing the public internet, but it doesn't inherently encrypt data transmitted over Direct Connect itself. It secures the path, but not the data in transit over the Direct Connect link in the same way a VPN does.
  • B. MACsec (Media Access Control Security) provides encryption at Layer 2 on supported Direct Connect connections, but it's not universally available and might require specific hardware from the customer and Direct Connect partners. VPN over Direct Connect is a more widely applicable and robust solution for end-to-end encryption.
  • D. Client-side encryption encrypts the data payload, but it doesn't encrypt the network traffic metadata or ensure all data is encrypted if applications don't consistently use it. It's an application-level solution, not a network-level one.

VPN over AWS Direct Connect

A solution that combines the private, dedicated bandwidth of AWS Direct Connect with the in-transit encryption of an IPsec VPN (AWS Site-to-Site VPN) to meet high-security and compliance requirements.

  • Direct Connect is private but not encrypted by default.
  • IPsec VPN adds in-transit encryption (Layer 3).
  • Commonly implemented using AWS Site-to-Site VPN.

Memory trick: Direct Connect is Private, VPN Makes it Secure and Encrypted.

More Network Security, Compliance, and Governance questions