SCS-C02 exam dumps

SCS-C02 practice question 333 of 504

AWS Certified Security - Specialty. Expert level, Amazon Web Services. Free question with the correct answer and a full explanation.

SCS-C02 Question 333

Select 3

An organization is hosting a web application on Amazon EC2 instances behind an Application Load Balancer (ALB). The organization wants to ensure all data transmitted between users and the application is encrypted using TLS. They also want to use a custom domain name for the application. Which of the following steps should the organization take to achieve this?

  1. A

    Request and configure an SSL/TLS certificate in AWS Certificate Manager (ACM) for the custom domain name.

  2. B

    Configure the Application Load Balancer (ALB) to use the SSL/TLS certificate for HTTPS listeners.

  3. C

    Enable TLS on the Amazon EC2 instances hosting the application.

  4. D

    Use an Amazon-issued certificate by default without verifying domain ownership.

  5. E

    Redirect all HTTP traffic to HTTPS using the Application Load Balancer (ALB).

Show answer and explanation

Correct answers: A, B, E

Explanation

To establish secure communication using TLS, the organization must first request and configure an SSL/TLS certificate for their custom domain name through AWS Certificate Manager (ACM). This certificate is then associated with the Application Load Balancer (ALB) to handle HTTPS traffic. The ALB terminates TLS connections, so enabling TLS on EC2 instances is unnecessary. Additionally, redirecting HTTP traffic to HTTPS ensures all users connect securely. The option about using Amazon-issued certificates without domain verification is incorrect because domain ownership verification is mandatory.

  • A. Correct.

    Correct: Requesting and configuring an SSL/TLS certificate in AWS Certificate Manager (ACM) is required to enable TLS for the custom domain name. ACM generates and manages the certificate.

  • B. Correct.

    Correct: The ALB must be configured with the SSL/TLS certificate to handle HTTPS traffic for the application.

  • C. Incorrect.

    Incorrect: Enabling TLS on the EC2 instances is not required when the ALB is managing TLS termination. The ALB handles the decryption of traffic before forwarding it to EC2 instances.

  • D. Incorrect.

    Incorrect: While Amazon-issued certificates are supported, domain ownership must still be verified during the certificate request process. This option is incorrect as it implies no verification is needed.

  • E. Correct.

    Correct: Redirecting all HTTP traffic to HTTPS ensures secure communication by forcing users to connect over an encrypted channel.

Timed practice exam

Take a SCS-C02 practice test under exam conditions

65 questions in 170 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam