SCS-C02 Data Protection Practice Question
A company wants to encrypt data in transit between an Application Load Balancer (ALB) and its targets. Which configuration should be used?
⚠ Common exam trap
SCS-C02 often tests the difference between encryption in transit and network security controls, and candidates may incorrectly assume that security groups can enforce encryption or confuse ALB with NLB capabilities.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Configure the ALB with an HTTPS listener and use HTTPS as the protocol for the target group.
To encrypt data in transit between an ALB and its targets, you must configure the ALB listener to use HTTPS and set the target group protocol to HTTPS. This ensures that traffic from the ALB to the targets is encrypted using TLS. The ALB terminates the client-side TLS and establishes a new TLS connection to the targets.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Configure the ALB with a TCP listener and use Network Load Balancer.
Why it's wrong here
A TCP listener bypasses ALB Layer 7 processing, and an NLB cannot terminate or originate TLS to ALB targets. It is tempting because NLB supports TLS listeners, but that encrypts client-to-NLB traffic, not the ALB-to-target hop the scenario specifies.
- ✓
Configure the ALB with an HTTPS listener and use HTTPS as the protocol for the target group.
Why this is correct
Configuring an HTTPS listener and an HTTPS target group encrypts traffic at both hops, including the ALB-to-target leg. This satisfies the requirement for in-transit encryption between load balancer and targets, since the default HTTP target protocol leaves that segment unencrypted.
- ✗
Configure the ALB security group to allow only encrypted traffic.
Why it's wrong here
Security groups are stateful packet filters; permitting only port 443 does not encrypt anything, so plaintext still reaches targets. It is tempting because port-based rules look like enforcement, but an HTTPS listener with a certificate is what actually encrypts the ALB-to-target connection.
- ✗
Configure the ALB with an HTTP listener and use a security group to enforce encryption.
Why it's wrong here
Security groups filter traffic; they do not encrypt it, so an HTTP listener still carries cleartext to targets. It is tempting because SG rules appear to enforce policy, but encryption requires an HTTPS listener with a certificate, which is the actual mechanism.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SCS-C02 question from scratch — 1,205 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.