Courseiva
Infrastructure Security →hardMultiple Choice

SCS-C02 Infrastructure Security Practice Question

A security engineer needs to ensure that all data in transit between an Application Load Balancer (ALB) and EC2 instances is encrypted. What configuration is required?

⚠ Common exam trap

The trap is assuming that configuring the ALB listener for HTTPS automatically encrypts the backend leg — candidates forget that the target group protocol is a separate setting that controls ALB-to-instance encryption.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Configure the target group to use HTTPS protocol.

Encryption in transit between an ALB and its targets is controlled by the target group protocol, not the listener. Setting the target group to HTTPS makes the ALB initiate TLS connections to the EC2 instances, encrypting the backend leg. The listener protocol only governs the client-to-ALB leg.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Configure the security group to allow traffic on port 443.

    Why it's wrong here

    A security group rule permitting TCP 443 only authorizes traffic to reach the target on that port; it does not introduce TLS, encryption, or authentication. Security groups are stateful network firewalls that filter by IP and port, not cryptographic mechanisms. While opening port 443 could be necessary for an HTTPS target group or its health checks, the rule does not by itself encrypt any backend traffic.

  • ✗

    Configure the ALB listener with HTTPS protocol.

    Why it's wrong here

    A listener with HTTPS protocol terminates the TLS session at the load balancer, encrypting only the client-to-ALB segment. If the target group continues to use HTTP, the traffic between the ALB and the EC2 instances remains unencrypted, violating the all data in transit requirement. Therefore, configuring the listener alone is insufficient; the backend hop also needs encryption.

  • ✗

    Configure the ALB to terminate TLS connections.

    Why it's wrong here

    Terminating TLS refers to the listener decrypting client traffic and passing it unencrypted to the backend, so while it handles front-end certificates it does nothing to protect the ALB-to-target segment. The action of terminating TLS on the ALB actually implies that plaintext will be forwarded unless the target group overrides it with its own TLS. Thus this option is about listener-side certificate handling, not about securing data beyond the load balancer.

  • ✓

    Configure the target group to use HTTPS protocol.

    Why this is correct

    Setting the target group protocol to HTTPS instructs the ALB to establish a new TLS session with each registered EC2 target rather than forwarding plaintext HTTP. This encrypts the second segment of the request path, so combined with an HTTPS listener the data is encrypted end to end. It directly addresses the missing encryption between the load balancer and the instances, making it the correct action.

About these practice questions

One of 1,205 original SCS-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.