ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 514 - SCS-C01 discussion

Report
Export

A company deploys a distributed web application on a fleet of Amazon EC2 instances. The fleet is behind an Application Load Balancer (ALB) that will be configured to terminate the TLS connection. All TLS traffic to the ALB must stay secure, even if the certificate private key is compromised.

How can a security engineer meet this requirement?

A.
Create an HTTPS listener that uses a certificate that is managed by AWS Certificate Manager (ACM).
Answers
A.
Create an HTTPS listener that uses a certificate that is managed by AWS Certificate Manager (ACM).
B.
Create an HTTPS listener that uses a security policy that uses a cipher suite with perfect towardsecrecy (PFS).
Answers
B.
Create an HTTPS listener that uses a security policy that uses a cipher suite with perfect towardsecrecy (PFS).
C.
Create an HTTPS listener that uses the Server Order Preference security feature.
Answers
C.
Create an HTTPS listener that uses the Server Order Preference security feature.
D.
Create a TCP listener that uses a custom security policy that allows only cipher suites with perfect forward secrecy (PFS).
Answers
D.
Create a TCP listener that uses a custom security policy that allows only cipher suites with perfect forward secrecy (PFS).
Suggested answer: A
asked 16/09/2024
Ferran Ortega Torrabadell
36 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first