DVA-C02 Security Practice Question
A developer is building a web application that must encrypt data in transit between the client and the server. Which AWS service should be used to offload SSL/TLS termination?
⚠ Common exam trap
Candidates often confuse the use cases of ALB and NLB for SSL/TLS termination. While both can terminate SSL/TLS, ALB operates at Layer 7 (HTTP/HTTPS) and is the standard choice for web applications requiring content-based routing, whereas NLB operates at Layer 4 (TCP/UDP/TLS) for ultra-high performance or static IP requirements.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Application Load Balancer (ALB)
An Application Load Balancer (ALB) is ideal for web applications (HTTP/HTTPS) to offload SSL/TLS termination. It decrypts HTTPS traffic from clients at Layer 7 and forwards it to backend targets, reducing CPU load on application servers and centralizing certificate management via AWS Certificate Manager (ACM). While Network Load Balancer (NLB) also supports TLS termination at Layer 4, ALB is specifically designed for HTTP/HTTPS application-level routing and features.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Application Load Balancer (ALB)
Why this is correct
An Application Load Balancer (ALB) operates at Layer 7 (application layer) and is specifically designed to handle HTTP/HTTPS traffic, making it ideal for web applications. It can offload the CPU-intensive SSL/TLS encryption and decryption process from backend instances, significantly improving their performance and simplifying certificate management. By configuring HTTPS listeners and associating an SSL/TLS certificate, typically from AWS Certificate Manager (ACM), the ALB terminates the secure connection from clients and forwards unencrypted or re-encrypted traffic to targets.
- ✗
Amazon CloudFront
Why it's wrong here
Amazon CloudFront is primarily a Content Delivery Network (CDN) service that caches content at edge locations globally to reduce latency for end-users. While CloudFront does support SSL/TLS termination at the edge, its main purpose is content distribution and caching, not acting as the primary load balancer for an application's origin servers within a specific AWS region. It terminates SSL for content delivery, but it doesn't balance incoming requests across multiple backend application instances in the same way a regional load balancer does.
- ✗
Network Load Balancer (NLB)
Why it's wrong here
A Network Load Balancer (NLB) operates at Layer 4 (transport layer) and is optimized for extreme performance and handling millions of requests per second with very low latency. By default, an NLB passes traffic directly to its targets without inspecting or modifying the packet headers, meaning it does not terminate SSL/TLS connections itself. For an NLB, the SSL/TLS termination would need to occur on the backend instances or a proxy layer behind the NLB, which contradicts the goal of offloading encryption at the load balancer.
- ✗
Amazon Route 53
Why it's wrong here
Amazon Route 53 is a highly available and scalable cloud Domain Name System (DNS) web service, acting as the internet's phone book by translating human-readable domain names into numerical IP addresses. Its core function is to direct traffic to appropriate resources based on DNS records. Route 53 does not handle network traffic directly, nor does it perform any form of encryption, decryption, or load balancing; it simply provides the initial lookup service to resolve domain names.
Go deeper
Related to this question
About these practice questions
One of 1,135 original DVA-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This DVA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DVA-C02 exam.