SCS-C02 exam dumps

SCS-C02 practice question 337 of 504

AWS Certified Security - Specialty. Expert level, Amazon Web Services. Free question with the correct answer and a full explanation.

SCS-C02 Question 337

Select 3

Your organization has recently established a hybrid cloud environment using AWS. To securely connect your on-premises data center to your VPC, you have set up a Site-to-Site VPN using AWS VPN services. However, your security team raises a concern that data in transit between the on-premises data center and AWS is not encrypted as expected. Which of the following steps should you take to ensure that the VPN connection is encrypted?

  1. A

    Ensure that the VPN connection is configured to use IPsec with strong encryption algorithms such as AES-256.

  2. B

    Verify that the customer gateway device on the on-premises side supports IPsec and is configured properly.

  3. C

    Enable Perfect Forward Secrecy (PFS) for the VPN connection to enhance encryption security.

  4. D

    Modify the VPC route table to include a route to the on-premises data center.

  5. E

    Ensure the security group attached to the VPC allows traffic over the VPN tunnel.

Show answer and explanation

Correct answers: A, B, C

Explanation

To ensure a secure Site-to-Site VPN connection, it is essential to configure IPsec with strong encryption algorithms, verify that the customer gateway device supports IPsec, and enable Perfect Forward Secrecy (PFS). These steps ensure that data in transit is encrypted and protected from unauthorized access. Modifying the VPC route table and configuring security groups are necessary for connectivity and access control but do not address encryption directly.

  • A. Correct.

    This is correct. IPsec is crucial for encrypting data in transit over a VPN. Using strong encryption algorithms such as AES-256 ensures that data remains confidential.

  • B. Correct.

    This is correct. The customer gateway device must support IPsec and be properly configured to establish a secure, encrypted connection.

  • C. Correct.

    This is correct. Enabling Perfect Forward Secrecy (PFS) ensures session keys are not reused, which enhances the security of the encrypted VPN connection.

  • D. Incorrect.

    This is incorrect. Modifying the VPC route table helps route traffic through the VPN but does not directly address encryption concerns.

  • E. Incorrect.

    This is incorrect. Security groups are used to control inbound and outbound traffic but do not affect encryption of the VPN connection.

Timed practice exam

Take a SCS-C02 practice test under exam conditions

65 questions in 170 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam