ISC2 Systems Security Certified Practitioner (SSCP) Practice Question
An online retailer is deploying a public-facing web application on Amazon EC2 instances behind an Application Load Balancer (ALB). Compliance mandates that every customer connection must use HTTPS with TLS 1.2 or later only and that server certificates be issued and renewed automatically with no downtime or manual effort. Which solution best meets these requirements?
Terminate TLS at an Amazon CloudFront distribution using an ACM certificate, then forward traffic over HTTP to the ALB listening on port 80 to reduce latency.
Request a public certificate from AWS Certificate Manager, attach it to an ALB HTTPS listener configured with an AWS security policy that permits only TLS 1.2+, and add an ALB rule that redirects HTTP requests to HTTPS.
Install self-signed certificates on every EC2 instance and configure a TCP listener on the ALB that forwards port 443 traffic directly to the instances.
Purchase a public TLS certificate, import it into AWS Certificate Manager, and attach it to an ALB HTTPS listener that enforces the ELBSecurityPolicy-TLS-1-2-Ext-2018-06 cipher suite.
Requesting a public certificate from AWS Certificate Manager (ACM) satisfies the automatic provisioning and renewal requirement because ACM handles renewal and transparent deployment without operator action. Associating that certificate with an ALB HTTPS listener and selecting an AWS predefined security policy that allows only TLS 1.2 (or newer) ensures that inbound traffic uses strong protocols and ciphers. An ALB listener rule that redirects HTTP to HTTPS guarantees all client traffic is encrypted. Importing a third-party certificate into ACM still leaves renewal tasks to administrators. Using self-signed certificates requires manual distribution and renewal and provides no public trust, while terminating TLS at CloudFront but sending traffic unencrypted to the ALB breaks the end-to-end encryption requirement.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is AWS Certificate Manager (ACM)?
Open an interactive chat with Bash
What is an Application Load Balancer (ALB)?
Open an interactive chat with Bash
What does ELBSecurityPolicy-TLS-1-2-Ext-2018-06 mean?
Open an interactive chat with Bash
ISC2 Systems Security Certified Practitioner (SSCP)
Cryptography
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99 $11.99
$11.99/mo
Billed monthly, Cancel any time.
$19.99 after promotion ends
3 Month Pass
$44.99 $26.99
$8.99/mo
One time purchase of $26.99, Does not auto-renew.
$44.99 after promotion ends
Save $18!
MOST POPULAR
Annual Pass
$119.99 $71.99
$5.99/mo
One time purchase of $71.99, Does not auto-renew.
$119.99 after promotion ends
Save $48!
BEST DEAL
Lifetime Pass
$189.99 $113.99
One time purchase, Good for life.
Save $76!
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .