Courseiva
Security →mediumMultiple Choice

DVA-C02 Security Practice Question

A developer is building a web application that stores user session data in an ElastiCache Redis cluster. The cluster is in a VPC and is not publicly accessible. The developer needs to ensure that data in transit is encrypted. What should the developer do?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Enable encryption in transit on the ElastiCache Redis cluster.

ElastiCache for Redis supports encryption in transit, which encrypts data between the client and the Redis cluster. Placing an Application Load Balancer in front of the Redis cluster (Option B) is not supported; Redis uses a custom protocol that ALB cannot handle. Configuring security groups (Option C) controls network traffic but does not encrypt data. VPC peering (Option D) allows network connectivity but does not provide encryption in transit.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Enable encryption in transit on the ElastiCache Redis cluster.

    Why this is correct

    Enabling in-transit encryption on the ElastiCache Redis cluster makes clients negotiate TLS, protecting session data as it moves between the application and the cluster. The VPC isolation already handles network reachability, so no security group change is required.

  • ✗

    Place an Application Load Balancer in front of the Redis cluster and enable TLS termination.

    Why it's wrong here

    An Application Load Balancer terminates TLS at the load balancer, leaving the connection to Redis unencrypted; ElastiCache supports in-transit encryption natively via TLS. It is tempting because ALBs commonly front web tiers, but they cannot proxy the Redis protocol or secure that backend hop.

  • ✗

    Configure the security group to only allow traffic from the application servers.

    Why it's wrong here

    Security groups are stateful network-layer firewalls that control which sources can reach the cluster's port, but they operate purely on IP/port filtering and provide zero cryptographic protection for the data as it traverses the network.

  • ✗

    Use VPC peering to connect the application VPC to the ElastiCache VPC.

    Why it's wrong here

    VPC peering provides network routing between VPCs but does not encrypt traffic; ElastiCache in-transit encryption must be enabled on the cluster itself. Peering is tempting because it addresses private connectivity, yet encryption is a separate configuration independent of the network path.

About these practice questions

This DVA-C02 question is part of Courseiva's 1,135-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This DVA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DVA-C02 exam.