SCS-C02 exam dumps

SCS-C02 practice question 327 of 504

AWS Certified Security - Specialty. Expert level, Amazon Web Services. Free question with the correct answer and a full explanation.

SCS-C02 Question 327

Select 3

Your company runs a web application on Amazon EC2 instances behind an ALB (Application Load Balancer) and uses Amazon RDS for storing sensitive customer data. The application handles financial transactions and must comply with strict regulations requiring the confidentiality and integrity of data in transit. What actions should you take to meet these requirements?

  1. A

    Use HTTPS for communication between clients and the ALB with an SSL/TLS certificate.

  2. B

    Configure the ALB to use a self-signed certificate for HTTPS traffic.

  3. C

    Enable encryption in transit for connections between the EC2 instances and the RDS database.

  4. D

    Enable the default security group on the EC2 instances to allow unrestricted traffic.

  5. E

    Use AWS Certificate Manager (ACM) to provision and manage the SSL/TLS certificate for the ALB.

Show answer and explanation

Correct answers: A, C, E

Explanation

To ensure confidentiality and integrity for data in transit, you must use HTTPS for client communication with the ALB and enable encryption for connections between the EC2 instances and the RDS database. Additionally, using AWS Certificate Manager (ACM) simplifies certificate management and ensures compliance with secure communication standards. Avoid using self-signed certificates, as they are not trusted by clients, and ensure that security groups strictly follow the principle of least privilege.

  • A. Correct.

    This is correct. HTTPS ensures that data transmitted between the clients and the ALB is encrypted, protecting its confidentiality and integrity during transit.

  • B. Incorrect.

    This is incorrect. While a self-signed certificate may provide encryption, it does not meet the compliance requirements for secure communication since it is not trusted by clients.

  • C. Correct.

    This is correct. Enabling encryption in transit for the connection between the EC2 instances and the RDS instance ensures the confidentiality and integrity of data moving between the application and the database.

  • D. Incorrect.

    This is incorrect. Allowing unrestricted traffic in the default security group violates the principle of least privilege and exposes the application to security risks.

  • E. Correct.

    This is correct. AWS ACM simplifies the management of SSL/TLS certificates and ensures they are properly provisioned and maintained for secure communication.

Timed practice exam

Take a SCS-C02 practice test under exam conditions

65 questions in 170 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam