SCS-C02 Data Protection Practice Question
A security engineer is designing a solution to protect data in transit for a web application that uses an Application Load Balancer (ALB) and EC2 instances. The application must use TLS 1.2 or higher and must use a strong cipher suite. The engineer has configured the ALB with a security policy that includes TLS 1.2 and strong ciphers. However, the engineer notices that some clients are still able to connect using TLS 1.0. What is the most likely cause of this issue?
⚠ Common exam trap
The trap here is assuming that updating the security policy on one listener automatically applies to all listeners, but each listener must be configured separately.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The ALB listener is configured with a security policy that includes TLS 1.0, and the engineer's changes were not applied to the correct listener.
The most likely cause is that the security policy change was not applied to the correct listener. ALBs can have multiple listeners, and if the application uses a different listener that still has a permissive security policy, clients can connect with TLS 1.0. The engineer should verify all listeners and ensure the restrictive policy is applied to the one handling the traffic.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
The ALB listener is configured with a security policy that includes TLS 1.0, and the engineer's changes were not applied to the correct listener.
Why this is correct
If the engineer updated the security policy on one listener but the application uses another listener (e.g., a different port), clients connecting to the unchanged listener could still use TLS 1.0. This is a common misconfiguration where changes are applied to the wrong listener or the listener is not updated. The scenario states that some clients can use TLS 1.0, indicating that a listener with a permissive policy is still active.
- ✗
The EC2 instances behind the ALB are configured to allow TLS 1.0, and the ALB is passing through the TLS connection.
Why it's wrong here
An ALB terminates TLS connections and then establishes a new connection to the backend instances. It does not pass through the TLS connection. Therefore, the EC2 instances' TLS configuration does not affect the client-facing TLS version. The ALB's security policy is what determines the allowed TLS versions for clients.
- ✗
The clients are using a proxy that downgrades the TLS version, and the ALB cannot enforce the minimum TLS version.
Why it's wrong here
While a proxy could downgrade TLS, the ALB enforces the security policy based on the TLS handshake it receives. If the ALB is configured to require TLS 1.2, it will reject TLS 1.0 connections regardless of any proxy. The ALB cannot be bypassed in this manner. Thus, this is not a plausible cause if the ALB policy is correctly configured.
- ✗
The ALB is configured with a default security policy that allows TLS 1.0.
Why it's wrong here
If the ALB were using a default security policy that allows TLS 1.0, then all clients would be able to connect with TLS 1.0, not just some. The engineer explicitly configured a security policy with TLS 1.2 and strong ciphers, so the default policy is not in effect. This option does not explain why only some clients can use TLS 1.0.
Go deeper
Related to this question
About these practice questions
This SCS-C02 question is part of Courseiva's 1,205-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.