SCS-C02 exam dumps

SCS-C02 practice question 262 of 504

AWS Certified Security - Specialty. Expert level, Amazon Web Services. Free question with the correct answer and a full explanation.

SCS-C02 Question 262

Select 3

Your organization runs a web application on Amazon EC2 instances behind an Application Load Balancer (ALB). The application processes sensitive customer data, and you are tasked with ensuring that all network traffic to the application is encrypted. Additionally, your organization wants to enforce HTTPS-only access and ensure that no insecure HTTP traffic reaches the application. Which combination of steps should you take to meet these requirements?

  1. A

    Create an SSL/TLS certificate using AWS Certificate Manager (ACM) and associate it with the ALB.

  2. B

    Configure an ALB listener to redirect HTTP traffic (port 80) to HTTPS (port 443).

  3. C

    Install an SSL/TLS certificate on each EC2 instance hosting the application.

  4. D

    Restrict the ALB security group to only allow inbound traffic on port 443.

  5. E

    Create a WAF rule to block HTTP traffic to the application.

Show answer and explanation

Correct answers: A, B, D

Explanation

To enforce HTTPS-only access and encrypt all traffic to the application, you should use an SSL/TLS certificate with the ALB, configure the ALB listener to redirect HTTP to HTTPS, and restrict the ALB security group to only allow HTTPS traffic. These steps ensure that all network communication is secure and compliant with your organization's requirements. Installing SSL/TLS certificates on individual EC2 instances is unnecessary since the ALB handles SSL termination, and creating a WAF rule is not the most efficient method for enforcing HTTPS.

  • A. Correct.

    Correct: Associating an SSL/TLS certificate with the ALB ensures that HTTPS traffic is properly secured and terminated at the ALB.

  • B. Correct.

    Correct: Configuring the ALB listener to redirect HTTP traffic to HTTPS enforces HTTPS-only access by redirecting any insecure traffic to the secure protocol.

  • C. Incorrect.

    Incorrect: Installing SSL/TLS certificates on the EC2 instances is unnecessary because the ALB handles SSL termination. This approach would add unnecessary complexity.

  • D. Correct.

    Correct: Restricting the ALB security group to allow only inbound traffic on port 443 ensures that no unencrypted HTTP traffic (port 80) can reach the ALB.

  • E. Incorrect.

    Incorrect: While WAF can block certain types of HTTP requests, it is not the appropriate solution for enforcing HTTPS-only access in this scenario.

Timed practice exam

Take a SCS-C02 practice test under exam conditions

65 questions in 170 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam