AWS Certified Advanced Networking – Specialty (ANS-C01)Network Security, Compliance, and GovernanceMedium

A global enterprise needs to ensure all data transferred between their on-premises data centers and AWS VPCs is encrypted in transit using FIPS 140-2 validated cryptography. They are currently using AWS Direct Connect for connectivity. Which solution provides the required encryption and compliance?

  1. AEstablish an IPsec VPN tunnel over the Direct Connect connection.
  2. BUse AWS PrivateLink for all traffic between on-premises and AWS.
  3. CConfigure TLS/SSL on all applications to encrypt data at the application layer.
  4. DEnable encryption on the Direct Connect connection itself.
Show answer & explanation

Correct answer: A. Establish an IPsec VPN tunnel over the Direct Connect connection.

Direct Connect provides a private, dedicated connection but does not encrypt data in transit by default. To meet FIPS 140-2 compliance for data in transit over Direct Connect, an IPsec VPN tunnel must be established over the Direct Connect connection, providing the necessary encryption.

Why the other options are wrong

  • B. AWS PrivateLink enables private connectivity to services within AWS, not direct encryption for on-premises to VPC traffic.
  • C. Application-layer encryption is good practice but doesn't guarantee FIPS 140-2 compliance for all network traffic or protect against lower-layer eavesdropping without additional network encryption.
  • D. Direct Connect itself does not offer native encryption; it's a private connection.

IPsec VPN over Direct Connect

Combines the dedicated bandwidth of Direct Connect with the encryption and FIPS 140-2 compliance of an IPsec VPN tunnel.

  • Direct Connect provides private connectivity, not encryption.
  • IPsec VPN adds encryption, often FIPS 140-2 compliant.
  • Traffic travels encrypted over the dedicated Direct Connect link.
  • Common for highly regulated industries.

Memory trick: Direct Connect is the road, IPsec VPN is the armored car for FIPS data.

More Network Security, Compliance, and Governance questions