AWS Certified Advanced Networking – Specialty (ANS-C01)Network Security, Compliance, and GovernanceMedium
A global enterprise needs to ensure all data transferred between their on-premises data centers and AWS VPCs is encrypted in transit using FIPS 140-2 validated cryptography. They are currently using AWS Direct Connect for connectivity. Which solution provides the required encryption and compliance?
- AEstablish an IPsec VPN tunnel over the Direct Connect connection.
- BUse AWS PrivateLink for all traffic between on-premises and AWS.
- CConfigure TLS/SSL on all applications to encrypt data at the application layer.
- DEnable encryption on the Direct Connect connection itself.
Show answer & explanationAnswer & explanation
Correct answer: A. Establish an IPsec VPN tunnel over the Direct Connect connection.
Direct Connect provides a private, dedicated connection but does not encrypt data in transit by default. To meet FIPS 140-2 compliance for data in transit over Direct Connect, an IPsec VPN tunnel must be established over the Direct Connect connection, providing the necessary encryption.
Why the other options are wrong
- B. AWS PrivateLink enables private connectivity to services within AWS, not direct encryption for on-premises to VPC traffic.
- C. Application-layer encryption is good practice but doesn't guarantee FIPS 140-2 compliance for all network traffic or protect against lower-layer eavesdropping without additional network encryption.
- D. Direct Connect itself does not offer native encryption; it's a private connection.
IPsec VPN over Direct Connect
Combines the dedicated bandwidth of Direct Connect with the encryption and FIPS 140-2 compliance of an IPsec VPN tunnel.
- Direct Connect provides private connectivity, not encryption.
- IPsec VPN adds encryption, often FIPS 140-2 compliant.
- Traffic travels encrypted over the dedicated Direct Connect link.
- Common for highly regulated industries.
Memory trick: Direct Connect is the road, IPsec VPN is the armored car for FIPS data.