SCS-C02 exam dumps

SCS-C02 practice question 350 of 504

AWS Certified Security - Specialty. Expert level, Amazon Web Services. Free question with the correct answer and a full explanation.

SCS-C02 Question 350

Select 2

You are deploying a web application that uses HTTPS for secure communication. The application is fronted by an Application Load Balancer (ALB) and uses Amazon CloudFront for content delivery. Where should you configure the TLS/SSL certificates to ensure end-to-end encryption between the client and the backend instances?

  1. A

    Configure the TLS/SSL certificate on the Application Load Balancer (ALB).

  2. B

    Configure the TLS/SSL certificate on CloudFront.

  3. C

    Configure the TLS/SSL certificate on the backend instances.

  4. D

    Use AWS Certificate Manager (ACM) to manage the certificate and automatically distribute it across both CloudFront and the ALB.

  5. E

    Use a self-signed certificate on CloudFront and the ALB for testing purposes.

Show answer and explanation

Correct answers: A, B

Explanation

To ensure end-to-end encryption, you need to configure TLS/SSL certificates at each layer where secure communication is required. In this scenario, the TLS/SSL certificates need to be configured on both CloudFront (to handle encryption between the client and CloudFront) and the ALB (to handle encryption between CloudFront and the backend instances). Using AWS Certificate Manager (ACM) simplifies certificate management but does not eliminate the need to configure certificates on the individual services.

  • A. Correct.

    Correct: Configuring the TLS/SSL certificate on the Application Load Balancer ensures secure communication between the ALB and the backend instances.

  • B. Correct.

    Correct: Configuring the TLS/SSL certificate on CloudFront ensures secure communication between the client and CloudFront.

  • C. Incorrect.

    Incorrect: Configuring the TLS/SSL certificate on the backend instances is unnecessary when using an ALB for HTTPS termination. The ALB handles the encryption between itself and the backend.

  • D. Incorrect.

    Incorrect: AWS Certificate Manager (ACM) can manage certificates, but it does not automatically distribute them across services. Certificates must still be explicitly configured on CloudFront and the ALB.

  • E. Incorrect.

    Incorrect: Self-signed certificates are not suitable for production environments as they are not trusted by browsers and can lead to security warnings for users.

Timed practice exam

Take a SCS-C02 practice test under exam conditions

65 questions in 170 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam