AWS Certified CloudOps Engineer Associate SOA-C03 Practice Question
An operations team runs an HTTPS web application on Amazon EC2 instances behind an Application Load Balancer (ALB). The ALB terminates TLS but currently forwards traffic to the instances over HTTP. A new compliance control requires encryption on every network hop and public certificates that renew automatically, while minimizing ongoing maintenance for the instances. Which solution meets the requirements with the LEAST operational effort?
Create a private CA in AWS Certificate Manager, issue private certificates to each instance, keep the ALB forwarding traffic over HTTP, and rely on ACM to rotate the private certificates.
Install a Let's Encrypt certificate on each EC2 instance, change the ALB listener to TCP 443 for pass-through, and schedule certificate renewal scripts on every server.
Replace the ALB with a Network Load Balancer in TLS mode, import a public certificate on every EC2 instance, and configure cron jobs to renew and deploy the certificates.
Attach an ACM public certificate to the ALB HTTPS listener, change the target group protocol to HTTPS, keep the self-signed certificates on the instances, and allow the ALB to reach port 443 on the targets.
Using an ACM-issued public certificate on the ALB provides automatic renewal with no action required from the team. Switching the target group protocol from HTTP to HTTPS encrypts the connection between the ALB and the EC2 instances. The ALB does not validate the backend certificate chain, so the existing self-signed certificates on the instances can remain in place, avoiding any additional management work. The other options either remove the ALB's managed certificate, leave the ALB-to-instance hop unencrypted, or require the team to deploy and routinely renew certificates on every EC2 instance, all of which increase operational overhead.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is an Application Load Balancer (ALB) in AWS?
Open an interactive chat with Bash
What is AWS Certificate Manager (ACM), and how does it help with public certificates?
Open an interactive chat with Bash
Why does the ALB not validate the backend certificate chain?
Open an interactive chat with Bash
AWS Certified CloudOps Engineer Associate SOA-C03
Security and Compliance
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .