Courseiva
Security and Compliance →mediumMultiple Select

SOA-C02 Security and Compliance Practice Question

An organization needs to encrypt data in transit between an Amazon EC2 instance and an Application Load Balancer (ALB). Which THREE actions should be taken?

⚠ Common exam trap

Many exam-takers confuse encryption at rest (EBS encryption) with encryption in transit, or mistakenly believe security groups can filter based on encryption status, when in reality they only filter at the network layer.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Ensure the EC2 instance has a valid SSL/TLS certificate installed.

Encrypting data in transit between an EC2 instance and an Application Load Balancer requires the EC2 instance to present a valid SSL/TLS certificate. This allows the ALB to establish a secure HTTPS connection with the instance over the backend (target group) port, ensuring that traffic between the ALB and the instance is encrypted using TLS.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Enable encryption at rest on the EC2 instance's EBS volumes.

    Why it's wrong here

    Enabling EBS encryption on the EC2 instance's volumes protects data at the storage layer, but it does absolutely nothing for data moving across the network. Encryption in transit between the client, ALB, and EC2 instance is handled by TLS/HTTPS, not by block-level volume encryption. Therefore, this measure cannot satisfy the requirement to encrypt traffic in transit.

  • ✓

    Ensure the EC2 instance has a valid SSL/TLS certificate installed.

    Why this is correct

    If the Application Load Balancer is configured to forward traffic to the target group using HTTPS, the EC2 instance must have a valid SSL/TLS certificate installed to complete the TLS handshake. The instance presents this certificate to the ALB so that the session between them is encrypted, ensuring end-to-end protection from the client to the backend. Without a trusted, valid certificate matching the target's hostname, the ALB cannot establish the encrypted connection.

  • ✗

    Configure the security group to allow only encrypted traffic.

    Why it's wrong here

    Security groups act as a stateful virtual firewall, controlling traffic based on source IP, destination IP, protocol, and port; they have no ability to inspect payload content or determine whether traffic is encrypted. Configuring a rule that 'allows only encrypted traffic' is impossible because security groups cannot read TLS metadata or require encryption. Encryption must be implemented at a higher layer, such as HTTPS/TLS, not through a security group rule.

  • ✓

    Configure the ALB listener to use HTTPS protocol.

    Why this is correct

    Setting the ALB listener to the HTTPS protocol on port 443 causes the load balancer to negotiate TLS and encrypt all data transmitted from clients to the ALB. This step is essential for protecting traffic at the internet-facing edge, and it is the first half of an encrypted transit path. However, it alone does not ensure encryption beyond the ALB unless the target group or instance is also configured for HTTPS.

  • ✓

    Install an SSL/TLS certificate on the Application Load Balancer.

    Why this is correct

    An HTTPS listener on an Application Load Balancer requires a valid SSL/TLS certificate to be installed on the ALB so it can present to clients during the handshake. The certificate, typically stored in AWS Certificate Manager, must cover the exact DNS name clients use to reach the application and be unexpired. Without it, clients would get certificate errors and the encrypted listener cannot be used.

About these practice questions

One of 1,169 original SOA-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SOA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SOA-C02 exam.