AmazonAmazon
SCS-C02 · Question #155
SCS-C02 Question #155: Real Exam Question with Answer & Explanation
Sign in or unlock SCS-C02 to reveal the answer and full explanation for question #155. The question stem and answer options stay visible for context.
Submitted by packet_pusher· Mar 6, 2026
Question
A company deploys a distributed web application on a fleet of Amazon EC2 instances. The fleet is behind an Application Load Balancer (ALB) that will be configured to terminate the TLS connection. All TLS traffic to the ALB must stay secure, even if the certificate private key is compromised. How can a security engineer meet this requirement?
Options
- ACreate an HTTPS listener that uses a certificate that is managed by AWS Certificate Manager
- BCreate an HTTPS listener that uses a security policy that uses a cipher suite with perfect forward
- CCreate an HTTPS listener that uses the Server Order Preference security feature.
- DCreate a TCP listener that uses a custom security policy that allows only cipher suites with perfect
Unlock SCS-C02 to see the answer
You've previewed enough free SCS-C02 questions. Unlock SCS-C02 for full answers, explanations, the timed quiz mode, progress tracking, and the master PDF. Question stem and options stay visible so you can still see what's on the exam.