A company requires end-to-end encryption for traffic between external clients and an application hosted on Amazon EC2 instances in an Auto Scaling group behind an Application Load Balancer (ALB). How should a security engineer meet this requirement?
Choose an answer
Tap an option to check your answer.
Correct answer: Import a third-party certificate into AWS Certificate Manager (ACM), associate it with the ALB, and install the certificate on the EC2 instances..
Why this is the answer
The correct solution involves importing a third-party certificate into ACM for the ALB and installing it directly on the EC2 instances. This ensures end-to-end encryption. The ALB will use the certificate from ACM to encrypt traffic from the client to the ALB, and the EC2 instances will use the same certificate to encrypt traffic from the ALB to the application. Incorrect options: Amazon-issued certificates from ACM cannot be exported, making the first two options unfeasible for installation on EC2 instances. Importing a certificate into IAM is an older method and doesn't offer the same lifecycle management benefits as ACM. Also, exporting from IAM is not a standard or recommended practice for certificate management.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed