Courseiva
Network Security, Compliance and GovernanceeasyMultiple ChoiceObjective-mapped

ANS-C01 Network Security, Compliance and Governance Practice Question

A company runs a web application on Amazon EC2 instances in an Auto Scaling group behind an Application Load Balancer (ALB) across multiple Availability Zones. The application uses a MySQL database on an RDS instance in a private subnet. Security compliance requires that all traffic between the ALB and EC2 instances must be encrypted. The security team finds that the ALB currently sends traffic to the EC2 instances using HTTP on port 80. The EC2 security group allows inbound HTTP traffic from the ALB security group. The team needs to implement encryption with minimal changes and without disrupting the application. Which solution meets these requirements?

⚠ Common exam trap

Many exam-takers think simply changing the ALB listener to HTTPS is enough, but they overlook the requirement to create a new target group with HTTPS protocol and install certificates on the EC2 instances to encrypt the traffic between the ALB and the instances, not just the client-to-ALB leg.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Modify the ALB listener to use HTTPS on port 443. Create a new target group with protocol HTTPS on port 443. Install a valid SSL/TLS certificate on each EC2 instance. Update the EC2 security group to allow inbound HTTPS from the ALB security group.

It directly modifies the existing ALB to use an HTTPS listener on port 443, creates a new target group with HTTPS on port 443, and requires installing a valid SSL/TLS certificate on each EC2 instance. This ensures all traffic between the ALB and EC2 instances is encrypted with TLS, meeting the security requirement with minimal changes and no disruption to the application. The EC2 security group update to allow inbound HTTPS from the ALB security group completes the configuration.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Set up an AWS Client VPN endpoint and have the ALB send traffic through the VPN to the EC2 instances.

    Why it's wrong here

    This is overly complex and not designed for ALB-to-instance encryption.

  • Deploy an internal ALB in front of the EC2 instances and configure it with an HTTPS listener. Route traffic from the public ALB to the internal ALB.

    Why it's wrong here

    This adds complexity and still requires TLS termination on the internal ALB or EC2 instances.

  • Modify the ALB listener to use HTTPS on port 443. Create a new target group with protocol HTTPS on port 443. Install a valid SSL/TLS certificate on each EC2 instance. Update the EC2 security group to allow inbound HTTPS from the ALB security group.

    Why this is correct

    This encrypts traffic between ALB and EC2 with minimal changes.

  • Replace the ALB with a Network Load Balancer (NLB) and use TLS listeners to the EC2 instances.

    Why it's wrong here

    NLB does not terminate TLS; it just passes through encrypted traffic, requiring the instances to handle TLS.

Visual reference

192.168.1.0 /24 256 addresses (254 usable) 192.168.1.0 /25 Subnet A 128 addr (126 usable) 192.168.1.128 /25 Subnet B 128 addr (126 usable) Borrowing 1 bit from host portion creates 2 subnets (/25)

About these practice questions

This ANS-C01 question is part of Courseiva's 1,621-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This ANS-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the ANS-C01 exam.