ANS-C01 exam dumps

ANS-C01 practice question 493 of 513

AWS Certified Advanced Networking - Specialty. Expert level, Amazon Web Services. Free question with the correct answer and a full explanation.

ANS-C01 Question 493

Select 1

Your company is running a multi-tier application in AWS, and security is a top priority. You need to enforce encryption for data in transit between the web servers in an Auto Scaling group and the application servers running on EC2 instances. Which of the following AWS-provided network encryption options can you use to secure the communication between these tiers?

  1. A

    Use Transport Layer Security (TLS) with an Application Load Balancer (ALB) to encrypt traffic between the web servers and application servers.

  2. B

    Enable AWS Key Management Service (KMS) to encrypt all network traffic between the web servers and application servers.

  3. C

    Enable TLS encryption between the web servers and application servers by using mutual authentication certificates.

  4. D

    Use Virtual Private Network (VPN) connections to encrypt traffic between the web servers and application servers.

  5. E

    Leverage VPC Traffic Mirroring to encrypt network traffic between the web servers and application servers.

Show answer and explanation

Correct answer: C

Explanation

To secure data in transit between the web servers and application servers, you can use Transport Layer Security (TLS) with mutual authentication certificates. This ensures end-to-end encryption and establishes a trusted connection between the two tiers. Other options, such as KMS, VPN, or Traffic Mirroring, are either not applicable to this use case or do not provide network encryption in transit.

  • A. Incorrect.

    Transport Layer Security (TLS) with an Application Load Balancer (ALB) is used for encrypting traffic between clients and the ALB, not between web servers and application servers. It does not meet the requirement for inter-tier encryption.

  • B. Incorrect.

    AWS Key Management Service (KMS) is used for encrypting data at rest and managing encryption keys, not for encrypting data in transit.

  • C. Correct.

    TLS encryption with mutual authentication certificates is a valid way to encrypt traffic between the web servers and application servers. This ensures data security in transit by using trusted certificates on both ends.

  • D. Incorrect.

    Using a VPN connection is typically for encrypting traffic between on-premises networks and AWS, not for securing communication between resources within the same VPC.

  • E. Incorrect.

    VPC Traffic Mirroring is used to capture and analyze network traffic for troubleshooting or monitoring purposes. It does not provide encryption for network traffic.

Timed practice exam

Take a ANS-C01 practice test under exam conditions

65 questions in 170 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam