SCS-C02 exam dumps

SCS-C02 practice question 334 of 504

AWS Certified Security - Specialty. Expert level, Amazon Web Services. Free question with the correct answer and a full explanation.

SCS-C02 Question 334

Select 2

Your company has an application running on Amazon EC2 instances behind an Application Load Balancer (ALB). The security team requires that all connections between the clients and the application use the latest TLS version supported by AWS. What steps should you take to enforce this requirement?

  1. A

    Use an HTTPS listener on the ALB and configure the security policy to use a predefined policy that supports the latest TLS version.

  2. B

    Manually configure the EC2 instances to enforce the latest TLS version by editing the application’s TLS settings.

  3. C

    Use an HTTPS listener on the ALB and configure a custom security policy that explicitly disables older TLS versions.

  4. D

    Terminate TLS at the EC2 instances instead of the ALB to ensure the latest TLS version is enforced.

  5. E

    Monitor and log TLS version usage in AWS CloudTrail to ensure compliance.

Show answer and explanation

Correct answers: A, C

Explanation

To enforce the latest TLS version, you should configure the ALB's HTTPS listener with a predefined or custom security policy that enforces the desired TLS versions. This centralizes TLS configuration and ensures compliance. Configuring TLS directly on EC2 instances or relying on monitoring does not actively enforce the use of the latest TLS version and adds operational overhead.

  • A. Correct.

    This is correct because AWS allows you to use predefined security policies on the ALB that automatically enforce supported TLS versions and ciphers, which is a best practice.

  • B. Incorrect.

    This is incorrect because managing TLS configurations directly on EC2 instances is error-prone and less centralized compared to using the ALB for TLS termination.

  • C. Correct.

    This is correct because creating a custom security policy on the ALB allows you to explicitly disable older TLS versions and enforce only the latest TLS version.

  • D. Incorrect.

    This is incorrect because terminating TLS at the EC2 level introduces additional complexity and does not utilize the ALB's capability to enforce TLS settings centrally.

  • E. Incorrect.

    This is incorrect because monitoring TLS versions via AWS CloudTrail does not actively enforce the use of the latest TLS version; it is primarily for auditing purposes.

Timed practice exam

Take a SCS-C02 practice test under exam conditions

65 questions in 170 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam