passdrill
AWS SAA-C03 · VPC & Networking · Card 035/038 medium

A company sets up a new AWS Direct Connect dedicated connection between its data center and an AWS Region to get consistent, high-bandwidth connectivity for a workload with strict data-in-transit encryption requirements. Without adding anything else, is the traffic on this Direct Connect connection encrypted?

  1. Yes, all traffic sent over any Direct Connect connection is automatically encrypted at the physical layer by AWS with no configuration required
  2. Yes, but only if the connection uses a private virtual interface rather than a public virtual interface
  3. No, Direct Connect does not encrypt traffic in transit by default; the company needs to add a Site-to-Site VPN over the Direct Connect connection, or use a MACsec-capable connection, to get encryption
  4. No, and there is no supported way to encrypt traffic that traverses a Direct Connect connection; encryption must happen entirely at the application layer instead
Next card → Shuffle