Courseiva
Security and Compliance →mediumMultiple Choice

SOA-C02 Security and Compliance Practice Question

A SysOps administrator needs to ensure that all traffic to an Application Load Balancer (ALB) uses encryption. How can this be enforced?

⚠ Common exam trap

Test-takers frequently confuse security group rules with application-layer behavior, mistakenly believing that restricting the security group to port 443 alone will enforce encryption, when in fact it only controls network access and does not prevent unencrypted traffic on that port.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Create a listener that redirects HTTP requests (port 80) to HTTPS (port 443).

An Application Load Balancer can be configured with a listener rule that redirects incoming HTTP (port 80) requests to HTTPS (port 443). This ensures that all traffic to the ALB is encrypted in transit, as any unencrypted HTTP request is automatically redirected to the secure HTTPS protocol. The redirect action is a native ALB feature and does not require additional services or complex configurations.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Configure the security group to allow only HTTPS traffic (port 443).

    Why it's wrong here

    Editing the security group to allow only port 443 would drop all inbound HTTP traffic at the network layer. Because security groups operate at the instance/ENI level and are not application-aware, clients would receive a timeout or connection reset instead of being redirected. This approach prevents access but does not satisfy the intent of moving users from HTTP to HTTPS gracefully.

  • ✓

    Create a listener that redirects HTTP requests (port 80) to HTTPS (port 443).

    Why this is correct

    An Application Load Balancer listener rule can define a redirect action that responds to every HTTP (port 80) request with a 301 or 302 status and the corresponding HTTPS URL, preserving the path and query parameters. This is the native, supported pattern to force HTTPS because it transparently upgrades the client before the request reaches any target. The redirect action is evaluated before routing to target groups, so no compute resources are needed to enforce the policy.

  • ✗

    Use AWS WAF to block HTTP requests.

    Why it's wrong here

    AWS WAF is a web application firewall that inspects HTTP/HTTPS requests and can match rules such as IP sets or SQL injection patterns, returning a custom response (e.g., 403) for blocked requests. It does not have a built-in redirect action, so using it to block HTTP traffic would terminate the user's connection rather than forwarding them to the HTTPS equivalent. In addition to being the wrong tool for a redirect requirement, WAF adds hourly costs and rule overhead that are unnecessary for simple port redirection.

  • ✗

    Configure the ALB to use a custom SSL certificate.

    Why it's wrong here

    Importing or configuring a custom SSL certificate on the ALB enables TLS termination and makes HTTPS available, but it does not automatically disable or redirect the HTTP listener. The ALB will continue accepting plaintext traffic on port 80 unless you delete that listener, change its protocol, or create a redirect rule on it. Therefore, a certificate alone leaves HTTP endpoints open and fails to enforce encryption for all clients.

About these practice questions

This SOA-C02 question is part of Courseiva's 1,169-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SOA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SOA-C02 exam.