SCS-C02 exam dumps

SCS-C02 practice question 325 of 504

AWS Certified Security - Specialty. Expert level, Amazon Web Services. Free question with the correct answer and a full explanation.

SCS-C02 Question 325

Select 3

An organization is building a financial application that manages sensitive customer data. To comply with regulatory requirements, the organization must ensure the confidentiality and integrity of data transmitted between the application and its clients over the internet. Which of the following actions should you take to meet these requirements?

  1. A

    Use an Application Load Balancer and enforce HTTPS for all incoming connections.

  2. B

    Implement server-side encryption with AWS Key Management Service (KMS).

  3. C

    Use AWS Certificate Manager (ACM) to provision SSL/TLS certificates for the application.

  4. D

    Enable Perfect Forward Secrecy (PFS) for SSL/TLS connections.

  5. E

    Use a Network Load Balancer and enforce HTTP for all incoming connections.

Show answer and explanation

Correct answers: A, C, D

Explanation

To ensure confidentiality and integrity for data in transit, you must encrypt the data using protocols like HTTPS, which relies on SSL/TLS. AWS Certificate Manager (ACM) simplifies the management of SSL/TLS certificates, while Perfect Forward Secrecy (PFS) adds an additional layer of security by preventing the compromise of past communications. Server-side encryption and using HTTP do not meet the requirements for securing data in transit.

  • A. Correct.

    Correct: Enforcing HTTPS ensures that data is encrypted in transit, protecting its confidentiality and integrity.

  • B. Incorrect.

    Incorrect: Server-side encryption with KMS is used to encrypt data at rest, not in transit. It does not address the requirements for data transmission over the internet.

  • C. Correct.

    Correct: Using AWS Certificate Manager (ACM) to manage SSL/TLS certificates simplifies the process of securing HTTPS connections and ensures encryption during data transmission.

  • D. Correct.

    Correct: Perfect Forward Secrecy (PFS) ensures that even if the secret key is compromised in the future, previous communications remain secure, enhancing the confidentiality and integrity of data in transit.

  • E. Incorrect.

    Incorrect: Using HTTP does not encrypt data in transit and fails to provide confidentiality or integrity for transmitted data.

Timed practice exam

Take a SCS-C02 practice test under exam conditions

65 questions in 170 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam