Huawei SD-WAN allows encryption to be controlled by virtual network and by specific device relationships. When encryption is enabled for a VN, the overlay data channels carrying that VN’s traffic use IPsec protection across the relevant WAN links. This provides consistent isolation and confidentiality for the department or service represented by that VN.
Encryption can also be enabled between selected devices or sites. In that case, secure data channels are established for traffic exchanged between those specified endpoints, while other device relationships can continue using GRE without IPsec according to their policies.
Application-specific encryption, as described in option C, is not the supported control granularity. Application identification can influence intelligent traffic steering, QoS, and security-policy selection, but it does not mean that only the payload of a selected application is independently encrypted inside an otherwise unencrypted SD-WAN tunnel.
A transport network is an underlay WAN such as MPLS or the Internet. Enabling encryption is an overlay tunnel policy rather than a mechanism that encrypts all traffic belonging to an entire TN. Huawei distinguishes TNs as underlay networks and GRE or IPsec VPNs as overlay data channels. Therefore, only A and B are correct.