SCS-C02 exam dumps

SCS-C02 practice question 326 of 504

AWS Certified Security - Specialty. Expert level, Amazon Web Services. Free question with the correct answer and a full explanation.

SCS-C02 Question 326

Select 2

Your company hosts a web application on Amazon EC2 instances behind an Application Load Balancer (ALB). To ensure the confidentiality and integrity of data in transit between clients and the application, you are tasked with designing a secure solution. Which of the following steps should you take? (Select TWO)

  1. A

    Configure the ALB to use an HTTPS listener with a valid SSL/TLS certificate.

  2. B

    Enable HTTP-to-HTTPS redirection on the ALB to enforce secure connections.

  3. C

    Use AWS KMS to encrypt the data being transmitted between the client's browser and the ALB.

  4. D

    Configure the EC2 instances to accept traffic on port 80 to reduce latency.

  5. E

    Use a security group to block all traffic except HTTPS (port 443) to the ALB.

Show answer and explanation

Correct answers: A, B

Explanation

To ensure confidentiality and integrity for data in transit, it is essential to encrypt the communication channel. Configuring the ALB to use HTTPS with a valid SSL/TLS certificate ensures secure communication between the client and the ALB. Additionally, enabling HTTP-to-HTTPS redirection ensures that clients who initially attempt an HTTP connection are redirected to a secure HTTPS connection. These steps together provide robust protection for data in transit.

  • A. Correct.

    Configuring the ALB to use an HTTPS listener with a valid SSL/TLS certificate ensures that communication between the client and the ALB is encrypted, protecting data in transit.

  • B. Correct.

    Enabling HTTP-to-HTTPS redirection on the ALB ensures that all traffic is encrypted, even if the client initially makes an unencrypted HTTP request.

  • C. Incorrect.

    AWS KMS is used for encrypting data at rest or managing encryption keys, not for encrypting data in transit. This option is not applicable to the scenario.

  • D. Incorrect.

    Accepting traffic on port 80 (HTTP) would allow unencrypted communication, which does not meet the requirement of ensuring confidentiality and integrity for data in transit.

  • E. Incorrect.

    Blocking all traffic except HTTPS to the ALB using a security group is a good security practice, but it does not specifically address designing or implementing controls for data in transit.

Timed practice exam

Take a SCS-C02 practice test under exam conditions

65 questions in 170 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam