SAP-C02 exam dumps

SAP-C02 practice question 215 of 678

AWS Certified Solutions Architect - Professional. Professional level, Amazon Web Services. Free question with the correct answer and a full explanation.

SAP-C02 Question 215

Select 3

A financial services company is running a web application on Amazon EC2 instances behind an Application Load Balancer (ALB). The application stores sensitive customer data in an Amazon RDS database. Due to regulatory requirements, the company must ensure that all data in transit is encrypted and that only specific internal IP ranges can access the application. Additionally, the company must ensure that database credentials are not hardcoded into the application code. Which combination of security controls should you implement to meet these requirements?

  1. A

    Configure the ALB to use an HTTPS listener with a valid SSL/TLS certificate.

  2. B

    Use AWS Secrets Manager to securely store and retrieve database credentials.

  3. C

    Create a security group rule to allow access to the EC2 instances only from the specified internal IP ranges.

  4. D

    Enable Amazon RDS encryption at rest using AWS Key Management Service (KMS).

  5. E

    Enable AWS WAF on the ALB to block unauthorized IP ranges.

Show answer and explanation

Correct answers: A, B, C

Explanation

The requirements in the scenario focus on encrypting data in transit, controlling access to the application based on IP ranges, and securely managing database credentials. HTTPS on the ALB ensures encryption in transit, AWS Secrets Manager securely handles database credentials, and security group rules control access based on IP ranges. While other options like enabling RDS encryption at rest or using AWS WAF are good security practices, they are not directly relevant to the given requirements.

  • A. Correct.

    Correct. Configuring the ALB with an HTTPS listener ensures encryption for data in transit between the client and the ALB, which satisfies the encryption requirements.

  • B. Correct.

    Correct. Using AWS Secrets Manager ensures that database credentials are securely stored and not hardcoded into the application, meeting the security requirement.

  • C. Correct.

    Correct. Creating a security group rule that restricts access to the EC2 instances ensures that only the specified internal IP ranges can access the application, meeting the requirement for IP-based access control.

  • D. Incorrect.

    Incorrect. While enabling encryption at rest for RDS is a good security practice, this does not address the specific requirements in the scenario, which focus on data in transit encryption and access control.

  • E. Incorrect.

    Incorrect. AWS WAF can block unauthorized traffic, but it is not specifically required here as the security group rule already restricts access based on IP ranges.

Timed practice exam

Take a SAP-C02 practice test under exam conditions

75 questions in 180 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam