Courseiva
Security →mediumMultiple Choice

DVA-C02 Security Practice Question

A company's security policy requires that all data in transit between an Application Load Balancer (ALB) and its backend EC2 instances be encrypted. The ALB currently uses HTTPS listeners. What configuration ensures encryption between the ALB and targets?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Configure the target group to use HTTPS protocol.

To encrypt traffic between the ALB and backend EC2 instances, the target group protocol must be set to HTTPS, which uses TLS encryption. Option A is incorrect: security group rules control access but do not encrypt traffic. Option C is incorrect: while a Network Load Balancer with a TLS listener encrypts client-to-ALB traffic, it does not affect ALB-to-target encryption, and the question specifically asks about an Application Load Balancer. Option D is incorrect: setting the listener protocol to HTTPS with a certificate encrypts client-to-ALB traffic, not the traffic between ALB and targets.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Add a security group rule allowing port 443 from the ALB to the instances.

    Why it's wrong here

    Adding a security group rule allowing port 443 from the ALB to the instances merely opens the necessary network port for HTTPS traffic to pass through. Security groups function as stateful firewalls, controlling ingress and egress traffic based on specified rules, but they do not inherently encrypt data. While essential for network connectivity, this action alone does not configure or enforce the use of HTTPS for data in transit between the ALB and the backend instances; it only permits the traffic if it were already encrypted.

  • ✓

    Configure the target group to use HTTPS protocol.

    Why this is correct

    Configuring the target group to use HTTPS protocol explicitly instructs the Application Load Balancer (ALB) to establish a TLS-encrypted connection when forwarding requests to its registered backend instances. This setting ensures that all data transmitted from the ALB to the instances is encrypted in transit, directly fulfilling the security policy requirement. It offloads the initial client-side TLS termination to the ALB while maintaining a secure communication channel to the backend.

  • ✗

    Use a Network Load Balancer with a TLS listener.

    Why it's wrong here

    Using a Network Load Balancer (NLB) with a TLS listener primarily encrypts traffic between the client and the NLB itself, operating at Layer 4. Unlike an ALB, an NLB typically passes traffic through to targets without re-encryption unless specifically configured for TLS passthrough, which still relies on the backend instances handling TLS. This option does not inherently provide or configure encryption for the backend communication path from the load balancer to the instances in the same manner or at the same application layer as an ALB target group.

  • ✗

    Set the listener protocol to HTTPS with a certificate.

    Why it's wrong here

    Setting the ALB listener protocol to HTTPS with a certificate secures the communication path between the client and the Application Load Balancer. This configuration handles TLS termination for incoming client requests, ensuring client-side data in transit is encrypted. However, the listener protocol does not govern the communication protocol or encryption status for traffic flowing from the ALB to the backend instances; that specific aspect is controlled by the target group settings.

About these practice questions

One of 1,135 original DVA-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This DVA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DVA-C02 exam.