SCS-C02 Infrastructure Security Practice Question
A company wants to deploy a web application that must be accessible over HTTPS only. The application runs behind an Application Load Balancer (ALB). The security team wants to enforce HTTP Strict Transport Security (HSTS) to prevent downgrade attacks. Which configuration achieves this?
⚠ Common exam trap
Candidates often assume HSTS can be configured directly on the ALB (like a security policy or listener rule), when in fact it must be implemented at the application layer by setting the response header, and the ALB only handles traffic redirection.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Configure the ALB to redirect HTTP traffic to HTTPS and have the application set the Strict-Transport-Security header in the response
HSTS is enforced by the web application sending the `Strict-Transport-Security` header in HTTPS responses. By configuring the ALB to redirect HTTP to HTTPS, all traffic is forced over TLS, and the application can then set the HSTS header to instruct browsers to always use HTTPS for future requests. The ALB itself does not natively set HSTS headers; this must be done at the application layer.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Use AWS CloudFront with a custom header that enforces HSTS
Why it's wrong here
CloudFront's custom headers are added to the forwarded request sent to the origin, not to the response delivered to the viewer. Strict-Transport-Security is a response header that must be emitted by the backend or edge logic (e.g., Lambda@Edge), and simply attaching a custom header does not enforce HSTS or tell the browser to only use HTTPS. Even if CloudFront also redirects HTTP to HTTPS, the HSTS policy itself would be missing, so this approach fails the requirement.
- ✓
Configure the ALB to redirect HTTP traffic to HTTPS and have the application set the Strict-Transport-Security header in the response
Why this is correct
This is the correct architecture because it separates transport security into two complementary layers: the ALB listener uses a redirect action to convert any plain HTTP request to HTTPS, forcing TLS for every attempt, and the application returns the Strict-Transport-Security header in its response, which instructs browsers to automatically use HTTPS for the domain for the specified duration. ALB does not natively generate HSTS headers, so the application must supply it after a successful TLS connection. This satisfies both the immediate encryption requirement and the long-term HSTS enforcement.
- ✗
Configure the ALB listener to use HTTPS only and set a custom header via a listener rule
Why it's wrong here
ALB listener rules are for conditional routing—they match incoming request attributes and then forward, redirect, or return a fixed response, but they cannot add, remove, or rewrite response headers on behalf of the origin. A listener rule that sets a custom header is not a supported action; HSTS must be present in the HTTP response header from the backend application. Configuring the listener to HTTPS only prevents plaintext access but leaves the browser without the HSTS policy, so it does not meet the stated security goal.
- ✗
Enable HSTS on the ALB via the AWS Management Console
Why it's wrong here
The AWS Management Console provides no HSTS toggle or configuration for Application Load Balancers; ALB offers TLS termination and security policies but HSTS is not a load-balancer feature. HSTS is an HTTP response header (Strict-Transport-Security) that is defined by the application or web server, not by the gateway or proxy layer. Since the console cannot inject that header into responses, choosing this option means the browser would never receive the HSTS instruction, and the requirement would remain unmet.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SCS-C02 question from scratch — 1,205 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.