Courseiva
Security and Compliance →mediumMultiple Choice

DOP-C02 Security and Compliance Practice Question

A DevOps engineer needs to enforce encryption in transit for all traffic between a fleet of EC2 instances and an Application Load Balancer (ALB). The ALB is configured with a TLS listener. Which step should the engineer take to ensure end-to-end encryption?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Configure the target group to use HTTPS protocol and install a certificate on each EC2 instance

To enforce end-to-end encryption between the ALB and EC2 instances, the target group must use HTTPS protocol. This requires each EC2 instance to have a TLS certificate installed so that traffic from the ALB to the instances is encrypted. Option A is incorrect because HTTP does not encrypt traffic. Option C is incorrect because security groups control network access but do not enforce encryption. Option D is incorrect because terminating TLS at the ALB and using HTTP to instances would leave the traffic between ALB and instances unencrypted.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Configure the target group to use HTTP protocol

    Why it's wrong here

    Switching the target group to HTTP does not enforce any encryption between the Application Load Balancer and the EC2 instances. Even though the client-to-ALB connection may use HTTPS, the ALB-to-instance hop would be transmitted in plaintext over the network, exposing payloads to sniffing or tampering within the VPC. This fails the requirement for encryption in transit for end-to-end traffic.

  • ✓

    Configure the target group to use HTTPS protocol and install a certificate on each EC2 instance

    Why this is correct

    Configuring the target group for HTTPS forces the ALB to negotiate a TLS session with each EC2 instance, so backend traffic is encrypted as well. Each instance must present a valid certificate that the ALB trusts, typically installed on the instance's web server or TLS terminator, to complete the handshake. This provides encryption in transit across both the client-to-ALB and ALB-to-instance segments.

  • ✗

    Use security group rules to enforce encryption

    Why it's wrong here

    Security group rules are stateful packet filters that permit or deny traffic based on IP addresses, ports, and protocols; they do not perform encryption or inspect payload content. While a security group can restrict HTTPS (port 443) access, it cannot enforce TLS handshakes or protect data from being sent in plaintext if the application decides to use HTTP. Therefore, relying solely on security groups cannot fulfill an encryption-in-transit requirement.

  • ✗

    Terminate TLS at the ALB and use HTTP to instances

    Why it's wrong here

    Terminating TLS at the ALB and then using plain HTTP to the instances leaves the internal hop unprotected. The client-facing connection is encrypted, but the traffic between the ALB and the EC2 instances is sent unencrypted over the VPC network. This is a common misconfiguration because it appears to satisfy 'encryption in transit' from the client's perspective, but it fails the stricter requirement of encrypting all hops.

About these practice questions

Courseiva writes every DOP-C02 question from scratch — 1,298 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.