🔥 40% Off Crucial Exams Memberships — This Week Only

2 days, 12 hours remaining!

ISC2 Systems Security Certified Practitioner (SSCP) Practice Question

An Amazon Application Load Balancer (ALB) terminates HTTPS for a public REST API backed by EC2 instances. A security scan shows the ALB still offers TLS 1.0 cipher suites that use 3DES, exposing the site to SWEET32. Corporate policy now demands that Internet clients use TLS 1.2 or later, but legacy on-prem controllers (from a known CIDR) can only connect with TLS 1.0 using AES128-SHA. Without adding new AWS services, which change best mitigates the vulnerability while keeping all clients operational?

  • Move TLS termination to the EC2 instances and configure their web servers to disable 3DES while keeping TLS 1.0 enabled, leaving the ALB to forward TCP traffic.

  • Create an additional HTTPS listener on port 8443 with a custom SSL policy that allows only TLS 1.0/AES128-SHA, update the ALB's security group to permit port 8443 only from the corporate CIDR, and set the 443 listener to a TLS 1.2-only policy.

  • Enable AWS WAF on the ALB and create a rule to block any requests that use 3DES cipher suites, leaving the existing listener configuration unchanged.

  • Replace the ALB's current SSL policy with the predefined ELBSecurityPolicy-TLS-1-2-2017-01 so only TLS 1.2 cipher suites are offered to every client.

ISC2 Systems Security Certified Practitioner (SSCP)
Cryptography
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot