SCS-C02 exam dumps

SCS-C02 practice question 128 of 504

AWS Certified Security - Specialty. Expert level, Amazon Web Services. Free question with the correct answer and a full explanation.

SCS-C02 Question 128

Select 2

Your company is hosting an application on Amazon EC2 instances behind an Application Load Balancer (ALB). The application stores sensitive user data in an RDS database. A recent security review identified that the application is not encrypting sensitive data in transit. To address this finding, you need to ensure that all communication between users and the application, as well as between the application and the database, is encrypted without making significant changes to the existing infrastructure. Which of the following actions should you take to meet these requirements?

  1. A

    Configure HTTPS listeners on the Application Load Balancer and use an SSL/TLS certificate to encrypt traffic between users and the ALB.

  2. B

    Enable encryption at rest for the RDS database using an AWS KMS-managed key.

  3. C

    Modify the application code to implement end-to-end encryption for all communication.

  4. D

    Enable SSL/TLS for database connections and update the application configuration to use the RDS database's SSL endpoint.

  5. E

    Create a VPC endpoint for RDS to ensure all communication between the application and the database remains within the AWS network.

Show answer and explanation

Correct answers: A, D

Explanation

To address the security review finding, both communication channels (users to ALB and application to RDS) must be encrypted in transit. Configuring HTTPS listeners on the ALB secures the connection between users and the application. Enabling SSL/TLS for RDS database connections ensures the connection between the application and the database is encrypted. Other options either address unrelated issues (e.g., encryption at rest) or involve significant infrastructure changes, which are not suitable for the scenario.

  • A. Correct.

    Correct. Configuring HTTPS on the ALB ensures that the communication between users and the ALB is encrypted, securing data in transit from the client to the load balancer.

  • B. Incorrect.

    Incorrect. While enabling encryption at rest for the RDS database is a good practice, it does not address the issue of data encryption in transit.

  • C. Incorrect.

    Incorrect. While modifying the application code for end-to-end encryption could achieve the goal, it involves significant changes to the infrastructure, which contradicts the requirement.

  • D. Correct.

    Correct. Enabling SSL/TLS for database connections ensures that communication between the application and the RDS database is encrypted, addressing the requirement for data in transit security.

  • E. Incorrect.

    Incorrect. While creating a VPC endpoint for RDS ensures private connectivity, it does not encrypt the data in transit between the application and the database.

Timed practice exam

Take a SCS-C02 practice test under exam conditions

65 questions in 170 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam