How to Enforce TLS Encryption Between ALB and EC2
A security engineer needs to ensure that all data in transit between an Application Load Balancer and EC2 instances is encrypted using TLS. Which configuration is required?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Configure the ALB with an HTTPS listener and the target group with HTTPS protocol.
To encrypt data in transit between the Application Load Balancer and EC2 instances, the ALB must have an HTTPS listener and the target group must use HTTPS protocol. This ensures end-to-end TLS encryption from client to ALB and from ALB to EC2 instances. Option A correctly specifies this configuration.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Configure the ALB with an HTTPS listener and the target group with HTTPS protocol.
Why this is correct
To encrypt traffic for the entire path, the ALB must terminate the client-facing TLS connection on an HTTPS listener and then originate a new TLS session to each registered target using an HTTPS target group. This ensures the request is decrypted only inside the ALB and re-encrypted before traversing any network segments to the EC2 instances. Both the listener and the target group certificate must be trusted, and health checks also run over HTTPS, maintaining encryption from edge to backend.
- ✗
Configure the ALB with an HTTPS listener and the target group with HTTP protocol.
Why it's wrong here
An HTTPS listener only protects the client-to-ALB segment; if the target group uses HTTP, the ALB forwards the request to the EC2 instances as plaintext. The traffic between the ALB and the instances traverses private subnets or VPC links and could be exposed to network inspection, so the requirement for all data in transit is not satisfied. Even though the front-end is encrypted, the backend hop remains unencrypted HTTP.
- ✗
Configure the ALB with a TLS listener and the target group with TCP protocol.
Why it's wrong here
A TLS listener is a Network Load Balancer feature, not supported on an Application Load Balancer, whose listeners operate at Layer 7 with HTTP/HTTPS. Additionally, a target group with TCP protocol is not valid for an ALB because ALB target groups only support HTTP and HTTPS for routing decisions. Even if this configuration were allowed, TCP target groups do not apply TLS encryption, so the path would remain unencrypted.
- ✗
Configure the ALB with a TCP listener and the target group with HTTP protocol.
Why it's wrong here
ALB only accepts HTTP and HTTPS listeners; a TCP listener is available only on Network Load Balancers and cannot be configured on an ALB. Furthermore, an HTTP target group means traffic is sent from the listener to the instances without TLS, leaving the backend traffic in plaintext. This combination is not only invalid for an ALB but also fails to provide encryption for the client-to-load-balancer leg or the load-balancer-to-instance leg.
Go deeper
Related to this question
About these practice questions
This SCS-C02 question is part of Courseiva's 1,205-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.