Courseiva

DOP-C02 ALB Security Policy Practice Question

An organization runs a critical application on Amazon EC2 instances in an Auto Scaling group behind an Application Load Balancer. The application requires that all traffic be encrypted in transit. The security team mandates the use of TLS 1.2 or higher and specific ciphers. What is the MOST efficient way to enforce this requirement?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Configure the ALB with a security policy that enforces TLS 1.2 and the required ciphers.

The Application Load Balancer (ALB) supports predefined security policies that enforce TLS version and cipher requirements at the load balancer level, providing centralized control. Option D is correct because configuring the ALB with a security policy that mandates TLS 1.2 and specific ciphers meets the requirement efficiently without modifying individual instances. Option A is incorrect because a Network Load Balancer (NLB) with TLS listeners does not offer the same granular security policy options as ALB and is less efficient for this requirement. Option B is incorrect because CloudFront is a CDN service; placing it in front of the ALB does not directly enforce TLS settings on the ALB itself and adds unnecessary complexity. Option C is incorrect because installing self-signed certificates on each EC2 instance is inefficient, not centralized, and does not enforce consistent TLS version and cipher requirements across all traffic.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Use a Network Load Balancer with TLS listeners and target groups.

    Why it's wrong here

    Incorrect. A Network Load Balancer (NLB) with TLS listeners does not provide a security policy to enforce specific TLS versions and ciphers; it only supports basic TLS termination. ALB offers predefined security policies for granular control.

  • ✗

    Place a CloudFront distribution in front of the ALB and configure the origin protocol policy.

    Why it's wrong here

    Incorrect. CloudFront is used for content delivery and caching; it can be placed in front of an ALB, but its origin protocol policy only controls encryption between CloudFront and the ALB, not the overall TLS version and cipher enforcement. This approach is less efficient and adds latency.

  • ✗

    Install a self-signed certificate on each EC2 instance and configure the web server.

    Why it's wrong here

    Installing a self-signed certificate on each instance encrypts only the instance-to-client leg and cannot enforce TLS 1.2 or specific ciphers at the load balancer, which terminates client connections. Self-signed certificates suit internal testing or isolated environments where no trusted CA validation is required.

  • ✓

    Configure the ALB with a security policy that enforces TLS 1.2 and the required ciphers.

    Why this is correct

    ALB security policies terminate TLS at the load balancer and enforce the minimum protocol version and cipher suite list, satisfying the TLS 1.2 requirement without modifying each EC2 instance. This centralises enforcement at the single ingress point.

About these practice questions

One of 1,298 original DOP-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.