ANS-C01 exam dumps

ANS-C01 practice question 506 of 513

AWS Certified Advanced Networking - Specialty. Expert level, Amazon Web Services. Free question with the correct answer and a full explanation.

ANS-C01 Question 506

Select 4

Your company operates a web application hosted on Amazon EC2 instances behind an Application Load Balancer (ALB). To comply with regulatory requirements, you must ensure end-to-end encryption for data in transit between clients and the application. Under the AWS shared responsibility model, which of the following actions are your responsibility?

  1. A

    Configuring SSL/TLS certificates on the Application Load Balancer

  2. B

    Enabling HTTPS listeners on the Application Load Balancer

  3. C

    Encrypting traffic between the ALB and the Amazon EC2 instances using SSL/TLS

  4. D

    Ensuring that AWS manages the ALB's SSL/TLS certificates

  5. E

    Implementing encryption for traffic between clients and the ALB

Show answer and explanation

Correct answers: A, B, C, E

Explanation

Under the AWS shared responsibility model, AWS manages the security of the cloud infrastructure, but customers are responsible for securing their applications and data within the cloud. This includes configuring SSL/TLS certificates, enabling HTTPS listeners, and ensuring encryption between various components, such as clients, load balancers, and backend servers. AWS provides tools like AWS Certificate Manager to facilitate certificate management, but the configuration and enforcement of encryption remain the customer's responsibility.

  • A. Correct.

    Correct. Configuring SSL/TLS certificates on the ALB is the customer's responsibility under the shared responsibility model, as AWS does not configure certificates for your application.

  • B. Correct.

    Correct. Customers are responsible for enabling HTTPS listeners on the ALB to ensure that encrypted traffic is accepted and handled properly.

  • C. Correct.

    Correct. Encryption between the ALB and EC2 instances is the customer's responsibility, as AWS does not automatically manage this aspect of end-to-end encryption.

  • D. Incorrect.

    Incorrect. AWS does not automatically manage SSL/TLS certificates for customers. You must manage certificate configuration yourself unless using AWS Certificate Manager in conjunction with AWS services.

  • E. Correct.

    Correct. Implementing encryption for traffic between clients and the ALB is the customer's responsibility, as you need to configure HTTPS listeners and manage certificates.

Timed practice exam

Take a ANS-C01 practice test under exam conditions

65 questions in 170 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam