SCS-C02 Data Protection Practice Question
A company runs a web application on Amazon EC2 behind an Application Load Balancer (ALB). The application handles payment card information (PCI) and must comply with PCI DSS. The security team wants to ensure that all data in transit between the client and the ALB is encrypted using TLS 1.2 or higher. The ALB currently uses a default certificate from AWS Certificate Manager (ACM) that was issued by Amazon. The compliance team has flagged that the certificate must be issued by a public Certificate Authority (CA) that is trusted by major browsers. The company wants to minimize operational overhead. What should the security team do?
⚠ Common exam trap
The trap is overcomplicating the solution with CloudHSM or self-signed certs — candidates forget that ACM-issued public certificates are already signed by a browser-trusted public CA, making them the lowest-overhead compliant choice.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Request a public certificate from ACM and associate it with the ALB
AWS Certificate Manager (ACM) can issue public certificates that are signed by Amazon's public CA, which is trusted by all major browsers and operating systems. Requesting a public certificate in ACM and associating it with the ALB listener satisfies the PCI DSS requirement for TLS 1.2+ encryption with a publicly trusted CA, while ACM handles renewal automatically — minimising operational overhead. This is the canonical AWS-recommended approach for ALB TLS termination.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Use AWS CloudHSM to generate a certificate and import it into ACM
Why it's wrong here
The AWS CloudHSM service provides hardware-backed key storage and is intended for workloads that require using an HSM for private key operations or to meet compliance mandates. Although you can generate a key pair in CloudHSM and use a CSR to obtain a publicly trusted certificate to import into ACM, doing so adds significant operational overhead: you must manage the HSM cluster, handle CA submission, and manually track rotation. Furthermore, ACM-managed certificates issued directly by ACM are renewed automatically, whereas imported certificates are not, so the HSM-based approach only creates unnecessary complexity without improving security for a standard public web application.
- ✗
Configure CloudFront in front of the ALB and use a CloudFront default certificate
Why it's wrong here
Putting CloudFront in front of the ALB works for CDN use cases, but the CloudFront default certificate is a shared `*.cloudfront.net` certificate that will not match your own domain name (e.g., `www.example.com`), so browsers would still see a certificate name mismatch. To use your domain with CloudFront, you would still need to request or upload a certificate for that domain into ACM in the US East (N. Virginia) Region and attach it to the distribution. This adds an extra network hop, extra latency, and more moving parts when the ALB alone can terminate HTTPS with an ACM certificate, making it an unnecessarily complicated architecture for this scenario.
- ✗
Generate a self-signed certificate on the EC2 instance and upload it to ACM, then associate it with the ALB
Why it's wrong here
A self-signed certificate does not come from a publicly trusted certificate authority, so when your ALB presents it, browsers and other clients will show a warning or refuse the connection entirely. Uploading that cert to ACM and associating it with the ALB does not change the client's trust decision — the ALB still presents the same untrusted chain. Additionally, self-signed certificates often have short validity, and you would have to manually repeat the generation/upload/association process on every rotation, whereas an ACM-issued public certificate is automatically renewed and trusted by every modern browser.
- ✓
Request a public certificate from ACM and associate it with the ALB
Why this is correct
Requesting a public certificate from AWS Certificate Manager is the correct, fully managed way to implement HTTPS on an Application Load Balancer. ACM's public certificates are issued by trusted CAs (such as Amazon Trust Services), are free of charge, and are automatically renewed as long as you maintain the required DNS validation or email validation records. After ACM validates your domain, you simply attach the certificate to the ALB's HTTPS listener, and the ALB handles TLS termination. This avoids any self-managed CA infrastructure and is aligned with AWS best practices for securing a web application.
Go deeper
Related to this question
About these practice questions
One of 1,205 original SCS-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.