A company is migrating data from on-premises to AWS using an AWS Transfer Family server. Company policy requires using TLS 1.2 or later to encrypt data in transit. Which action satisfies this requirement?
Choose an answer
Tap an option to check your answer.
Correct answer: Update the security policy of the Transfer Family server to specify a minimum protocol version of TLS 1.2.
Why this is the answer
Updating the security policy of the AWS Transfer Family server to specify a minimum protocol version of TLS 1.2 directly enforces the company's requirement for data in transit encryption. AWS Transfer Family allows you to configure security policies that dictate the allowed cryptographic protocols and ciphers. Generating new SSH keys is irrelevant as SSH keys are used for authentication, not for enforcing TLS versions. Updating security group rules on the on-premises network controls network access, but doesn't enforce the TLS version used by the Transfer Family server itself. Installing an SSL certificate is necessary for TLS, but the security policy is the mechanism to specify the minimum TLS version required for connections.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed