nerdexam
AmazonAmazon

SCS-C02 · Question #348

SCS-C02 Question #348: Real Exam Question with Answer & Explanation

Sign in or unlock SCS-C02 to reveal the answer and full explanation for question #348. The question stem and answer options stay visible for context.

Submitted by ravi_2018· Mar 6, 2026

Question

A company needs to use HTTPS when connecting to its web applications to meet compliance requirements. These web applications run in Amazon VPC on Amazon EC2 instances behind an Application Load Balancer (ALB). A security engineer wants to ensure that the load balancer will only accept connections over port 443, even if the ALB is mistakenly configured with an HTTP listener. Which configuration steps should the security engineer take to accomplish this task?

Options

  • ACreate a security group with a rule that denies Inbound connections from 0.0.0.0/0 on port 00
  • BCreate a network ACL that denies inbound connections from 0.0.0.0/0 on port 80
  • CCreate a network ACL that allows outbound connections to the VPC IP range on port 443 only.
  • DCreate a security group with a single inbound rule that allows connections from 0.0.0.0/0 on port

Unlock SCS-C02 to see the answer

You've previewed enough free SCS-C02 questions. Unlock SCS-C02 for full answers, explanations, the timed quiz mode, progress tracking, and the master PDF. Question stem and options stay visible so you can still see what's on the exam.

Full SCS-C02 PracticeBrowse All SCS-C02 Questions