Courseiva
Design for New Solutions →hardMultiple Choice

SAP-C02 Design for New Solutions Practice Question

A financial services firm runs a payment API on Amazon EC2 instances behind a Network Load Balancer. Regulators require that all data be encrypted in transit using certificates the firm controls, that the backend instances see the original client IP address, and that no TLS termination occur on the load balancer. Which configuration meets these requirements?

⚠ Common exam trap

The trap here is equating end-to-end encryption with a TLS listener, when attaching any certificate to the load balancer actually forces termination there.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Configure a TCP listener on port 443 without a certificate, and enable client IP preservation on the target group so instances handle TLS themselves.

Passing TLS through a Network Load Balancer requires a TCP listener with no certificate attached, letting the EC2 instances perform the handshake with firm-managed certificates. Client IP preservation, which is on by default for instance targets on TCP listeners, keeps the original client address visible to the backend, avoiding the need for Proxy Protocol parsing.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Configure a TCP listener on port 443 without a certificate, and enable client IP preservation on the target group so instances handle TLS themselves.

    Why this is correct

    A Network Load Balancer TCP listener passes encrypted traffic straight through, so the instances terminate TLS with certificates the firm fully controls. Client IP preservation is enabled by default for instance target groups on TCP listeners, letting the application read the original source address and satisfy the regulatory logging and access-control requirements.

  • ✗

    Configure a UDP listener on port 443 and enable Proxy Protocol v2, then install the firm's certificates on the EC2 instances.

    Why it's wrong here

    Payment API traffic is TCP-based HTTP, so a UDP listener would not carry it correctly. Proxy Protocol v2 prepends a header to the connection, which forces the application to be rewritten to parse it and means the original client IP is not available in the usual socket address.

  • ✗

    Configure a TLS listener on port 443 with a security policy, and register the instances as IP targets with client IP preservation turned off.

    Why it's wrong here

    A TLS listener means the Network Load Balancer decrypts and re-encrypts traffic, which directly contradicts the no-termination requirement. Disabling client IP preservation also masks the original source address unless the application parses Proxy Protocol headers, which the scenario does not permit.

  • ✗

    Configure a TCP listener on port 443 with a TLS certificate imported into AWS Certificate Manager, and enable Proxy Protocol v2 on the target group.

    Why it's wrong here

    Importing a certificate into ACM and attaching it to a TCP listener causes the Network Load Balancer to terminate TLS, which violates the requirement that no TLS termination occur at the load balancer. Enabling Proxy Protocol also changes the packet header, so the backend no longer reads the true client IP from the standard TCP header.

Visual reference

Client Server SYN (seq=100) SYN-ACK (seq=200, ack=101) ACK (ack=201) Connection established — data transfer begins

About these practice questions

One of 984 original SAP-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This SAP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAP-C02 exam.