SCS-C02 exam dumps

SCS-C02 practice question 351 of 504

AWS Certified Security - Specialty. Expert level, Amazon Web Services. Free question with the correct answer and a full explanation.

SCS-C02 Question 351

Select 3

Your organization is hosting a web application behind an Application Load Balancer (ALB) in AWS. To enhance security, you want to ensure that all traffic between your clients and the ALB is encrypted using TLS. The application also uses Amazon CloudFront as a content delivery network (CDN) for caching static assets. Which of the following configurations are necessary to properly set up TLS for this architecture?

  1. A

    Attach an SSL/TLS certificate to the Application Load Balancer using AWS Certificate Manager (ACM).

  2. B

    Configure Amazon CloudFront to use an SSL/TLS certificate by attaching a custom certificate in ACM or using the default CloudFront certificate.

  3. C

    Enable HTTP listener on the Application Load Balancer to redirect traffic from HTTP to HTTPS.

  4. D

    Use an SSL/TLS certificate from ACM for your backend instances behind the ALB.

  5. E

    Configure a custom SSL/TLS certificate for communication between Amazon CloudFront and the Application Load Balancer.

Show answer and explanation

Correct answers: A, B, C

Explanation

To configure TLS for this architecture, you need to attach an SSL/TLS certificate to the ALB for secure communication with clients. Additionally, CloudFront must have its own certificate to establish HTTPS connections with clients. Enabling an HTTP listener with redirection to HTTPS ensures that all traffic is encrypted. Backend instances behind the ALB generally do not require ACM certificates unless you are implementing end-to-end encryption. CloudFront and the ALB can securely communicate without a custom SSL/TLS certificate.

  • A. Correct.

    Correct. To enable secure communication between the client and the Application Load Balancer, you must attach an SSL/TLS certificate to the ALB using AWS Certificate Manager (ACM).

  • B. Correct.

    Correct. Amazon CloudFront requires an SSL/TLS certificate to establish HTTPS communication with clients. You can use either a custom certificate in ACM or the default CloudFront certificate.

  • C. Correct.

    Correct. It's recommended to enable an HTTP listener on the ALB to automatically redirect traffic from HTTP to HTTPS, ensuring security by enforcing encrypted connections.

  • D. Incorrect.

    Incorrect. While SSL/TLS certificates are critical for client-facing communication, backend instances typically do not require an ACM certificate unless end-to-end encryption is explicitly needed.

  • E. Incorrect.

    Incorrect. CloudFront automatically establishes a secure connection with the ALB using its own TLS settings, and no custom SSL/TLS certificate is required for this interaction.

Timed practice exam

Take a SCS-C02 practice test under exam conditions

65 questions in 170 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam