SAP-C02 Design for New Solutions Practice Question
A company is migrating a monolithic application to microservices on Amazon ECS. The application needs to communicate with external partners via HTTPS. The company wants to use mTLS for mutual authentication. Which AWS service should be used to handle the mTLS termination?
⚠ Common exam trap
It's easy for candidates to confuse ALB mTLS with NLB TLS termination or assuming API Gateway HTTP API supports mTLS, when in fact only ALB and API Gateway REST API (not HTTP API) offer mutual TLS termination for incoming client connections.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Application Load Balancer (ALB) with mutual TLS
Application Load Balancer (ALB) supports mutual TLS (mTLS) natively by configuring a trust store on the listener that validates client certificates against a Certificate Authority (CA) bundle you upload. This allows the ALB to terminate the HTTPS connection and perform client certificate authentication before forwarding traffic to the ECS service, meeting the requirement for mTLS termination without custom proxy logic.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Application Load Balancer (ALB) with mutual TLS
Why this is correct
ALB supports mutual TLS termination natively, validating client certificates against a trust store before forwarding traffic. This satisfies the mutual authentication requirement for partner HTTPS connections without running certificate handling on the ECS tasks themselves, simplifying the microservice architecture.
- ✗
Amazon CloudFront with a custom origin
Why it's wrong here
CloudFront terminates TLS at edge locations and supports client certificates only for viewer mTLS, not mutual authentication between ECS microservices and external partners over arbitrary HTTPS origins. It is tempting because CloudFront offloads TLS and integrates with custom origins, but it suits content delivery and edge termination, not service-to-service mTLS within a VPC.
- ✗
Network Load Balancer (NLB) with TLS termination
Why it's wrong here
An NLB with TLS termination validates only the server certificate; it does not request or verify client certificates, so mutual authentication fails. Tempting because NLBs terminate TLS and pass through TCP, and would suit server-only TLS or passthrough scenarios rather than mTLS.
- ✗
Amazon API Gateway HTTP API
Why it's wrong here
API Gateway HTTP APIs support mutual TLS only for outbound calls to backend integrations, not for authenticating inbound partner clients. Tempting because HTTP APIs are lightweight and HTTPS-native, and would be correct when the requirement is verifying the backend's certificate rather than the caller's.
Go deeper
Related to this question
About these practice questions
One of 984 original SAP-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SAP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAP-C02 exam.