SCS-C02 Management and Security Governance Practice Question
A startup is deploying a web application on AWS. The application runs on EC2 instances behind an Application Load Balancer (ALB). The security team wants to ensure that all traffic to the EC2 instances is encrypted. They configure the ALB to listen on HTTPS (port 443) and forward traffic to the EC2 instances on HTTP (port 80). Additionally, they create a security group for the EC2 instances that only allows inbound traffic from the ALB's security group on port 80. However, a security audit reveals that the traffic between the ALB and EC2 instances is not encrypted. Which step should the security team take to encrypt the traffic between the ALB and EC2 instances?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Configure the target group to use HTTPS protocol and install a certificate on the EC2 instances.
To encrypt traffic between the ALB and EC2 instances, configure the target group to use HTTPS protocol and install a certificate on the EC2 instances. This ensures the ALB sends HTTPS requests to the instances, encrypting the traffic. Option A is wrong because opening port 443 on the EC2 security group alone does not enable encryption; the listener must also use HTTPS for target traffic. Option B is wrong because encryption at rest protects data stored on disk, not data in transit. Option D is wrong because changing the ALB listener to TCP would terminate TLS at the ALB and forward unencrypted traffic to the targets, which defeats the purpose.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Update the EC2 security group to allow traffic on port 443 from the ALB.
Why it's wrong here
Allowing inbound 443 from the ALB in the EC2 security group is necessary if you later switch the target group to HTTPS, but by itself it does not alter the ALB's forwarding behavior. The target group still defines the protocol and port between ALB and instances; until that is changed to HTTPS, traffic will continue to flow as HTTP. It also fails to address the need for a server certificate on the instance.
- ✗
Enable encryption at rest on the EC2 instances.
Why it's wrong here
Enabling encryption at rest on EC2 instance volumes (EBS encryption) protects data written to disk, such as application files and logs, but has no effect on network traffic. Encryption in transit requires TLS on the connection between the ALB and the target, which is governed by the target group protocol and certificates, not by storage encryption settings.
- ✓
Configure the target group to use HTTPS protocol and install a certificate on the EC2 instances.
Why this is correct
Changing the target group protocol to HTTPS instructs the ALB to establish TLS connections to the EC2 instances. To complete a TLS handshake, each instance must present a valid certificate (for the domain or IP) trusted by the client, so you must install and configure a certificate on the instances. This ensures that traffic between the ALB and instances is encrypted, closing the gap where plaintext HTTP might otherwise travel inside the VPC.
- ✗
Change the ALB listener to use TCP instead of HTTPS.
Why it's wrong here
Switching the ALB listener from HTTPS to TCP disables TLS termination at the load balancer. TCP listeners pass client bytes through unchanged; they do not add encryption to the connection between the ALB and the instances. Consequently, the application would either handle its own TLS directly to the client or continue to use plaintext—and you lose HTTP-specific features such as host/path routing and sticky sessions based on cookies.
Go deeper
Related to this question
About these practice questions
This SCS-C02 question is part of Courseiva's 1,205-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.