SOA-C02 TLS/SSL Encryption Practice Question
Which TWO are valid methods to secure traffic between a client and an Application Load Balancer?
⚠ Common exam trap
The trap is that candidates often think only option A (SSL termination) secures traffic, but using a security group to allow only HTTPS (option B) also ensures encryption by blocking unencrypted traffic.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Configure a listener on port 443 with an SSL certificate from AWS Certificate Manager.
Configuring a listener on port 443 with an SSL certificate from ACM enables TLS encryption between the client and the ALB. Option B is also correct: using a security group that only allows HTTPS traffic enforces that all traffic must be encrypted, securing the communication by blocking unencrypted HTTP traffic. Options C, D, and E are incorrect: IPsec VPN is not terminated on an ALB (C), network ACLs do not provide encryption (D), and SSL/TLS encryption requires a valid certificate (E).
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Configure a listener on port 443 with an SSL certificate from AWS Certificate Manager.
Why this is correct
An Application Load Balancer (ALB) can terminate TLS by configuring an HTTPS listener on port 443. You must associate a valid SSL/TLS certificate, such as one issued by AWS Certificate Manager (ACM), which the ALB uses to decrypt incoming traffic and establish encrypted sessions with clients. This ensures data in transit is protected against eavesdropping and tampering. ACM integrates natively with ALB, handling certificate renewal automatically.
- ✓
Use a security group that only allows HTTPS traffic from the client's IP.
Why this is correct
A security group functions as a stateful virtual firewall at the ALB level. Allowing inbound traffic only on port 443 (HTTPS) from the client's IP address ensures that any request reaching the load balancer must be TLS-encrypted, as plain HTTP on port 80 is blocked. This effectively restricts the client to using HTTPS only, complementing the listener's TLS termination. However, note that a security group merely filters traffic; it does not itself encrypt anything, which is why it must be paired with a proper HTTPS listener configuration.
- ✗
Set up an IPsec VPN connection between the client and the ALB.
Why it's wrong here
An Application Load Balancer operates at Layer 7 (HTTP/HTTPS) and does not possess any capability to terminate IPsec VPN tunnels. IPsec is a network-layer (Layer 3) protocol used to build secure site-to-site or client-to-site VPNs, typically terminated on AWS customer gateways, VPN endpoints, or EC2 instances with VPN software. An ALB has no such endpoint for IPsec, so it cannot establish an encrypted tunnel with a client. Thus, this is an invalid method for securing client-to-ALB traffic.
- ✗
Configure a network ACL to allow only port 443.
Why it's wrong here
Network ACLs are stateless filters that operate at the subnet boundary, controlling traffic to and from all resources within that subnet. While configuring a NACL to allow only port 443 would restrict the permitted port, it does not introduce encryption; it merely permits packets with destination port 443, regardless of whether the payload is genuinely TLS or plaintext sent to port 443. Also, because NACLs are stateless, you must separately configure outbound rules for return traffic, and they cannot distinguish valid HTTPS sessions from other traffic. Therefore, this measure alone does not secure communication between a client and the ALB.
- ✗
Enable the ALB's built-in SSL/TLS encryption without a certificate.
Why it's wrong here
SSL/TLS encryption is fundamentally dependent on a cryptographic certificate to establish trust and negotiate session keys. An ALB has no 'built-in' encryption that can operate without a certificate; the HTTPS listener specifically requires a certificate to be configured. The certificate is used to prove the server's identity and to encrypt the TLS handshake. Without a valid certificate, the ALB cannot perform TLS termination, so this option is not a valid method.
Quick reference
VPN Protocol Comparison
| Protocol | Port | Encryption | Authentication | Use Case |
|---|---|---|---|---|
| IKEv2 / IPsec | UDP 500 / 4500 | AES-256 | Certificates / PSK | Site-to-site & remote access |
| SSL / TLS VPN | TCP 443 | TLS 1.3 | Certificates / MFA | Clientless remote access |
| L2TP / IPsec | UDP 1701 | AES (IPsec) | PSK / Certificates | Legacy remote access |
| WireGuard | UDP 51820 | ChaCha20 | Public keys | Modern high-performance VPN |
| PPTP | TCP 1723 | MPPE (weak) | MS-CHAPv2 | Legacy — avoid in production |
PPTP is considered insecure. IKEv2/IPsec and SSL VPN are the current recommended options.
Go deeper
Related to this question
About these practice questions
This SOA-C02 question is part of Courseiva's 1,169-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SOA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SOA-C02 exam.