exam questions

Exam AWS Certified Advanced Networking - Specialty ANS-C01 All Questions

View all questions & answers for the AWS Certified Advanced Networking - Specialty ANS-C01 exam

Exam AWS Certified Advanced Networking - Specialty ANS-C01 topic 1 question 37 discussion

A network engineer must provide additional safeguards to protect encrypted data at Application Load Balancers (ALBs) through the use of a unique random session key.
What should the network engineer do to meet this requirement?

  • A. Change the ALB security policy to a policy that supports TLS 1.2 protocol only
  • B. Use AWS Key Management Service (AWS KMS) to encrypt session keys
  • C. Associate an AWS WAF web ACL with the ALBs. and create a security rule to enforce forward secrecy (FS)
  • D. Change the ALB security policy to a policy that supports forward secrecy (FS)
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
study_aws1
Highly Voted 1 year, 9 months ago
Option D) Use ELBSecurityPolicy-FS policies, if you require Forward Secrecy • Provides additional safeguards against the eavesdropping of encrypted data • Using a unique random session key
upvoted 14 times
...
titi_r
Highly Voted 1 year, 8 months ago
Selected Answer: D
Perfect Forward Secrecy is a feature that provides additional safeguards against the eavesdropping of encrypted data, through the use of a unique random session key. This prevents the decoding of captured data, even if the secret long-term key is compromised. https://aws.amazon.com/about-aws/whats-new/2014/02/19/elastic-load-balancing-perfect-forward-secrecy-and-more-new-security-features/ https://aws.amazon.com/about-aws/whats-new/2018/06/application-load-balancer-adds-new-security-policies-including-policy-for-forward-secrecy/
upvoted 8 times
...
btech24
Most Recent 3 months, 1 week ago
D is the correct answer Perfect Forward Secrecy is a feature that provides additional safeguards against the eavesdropping of encrypted data, through the use of a unique random session key. This prevents the decoding of captured data, even if the secret long-term key is compromised.
upvoted 2 times
...
Raphaello
8 months, 2 weeks ago
Selected Answer: D
Select Security Policy that support FS algorithms. D is the correct answer.
upvoted 2 times
...
marfee
10 months, 2 weeks ago
I think that it's correcty answer is D.
upvoted 1 times
...
ILOVEVODKA
1 year, 9 months ago
Correct is either C or D, bur prob D. B is for sure wrong.
upvoted 1 times
...
fojta
1 year, 9 months ago
To provide additional safeguards to protect encrypted data at Amazon Application Load Balancers (ALBs) through the use of a unique random session key, the network engineer should use AWS Key Management Service (AWS KMS) to encrypt session keys. Therefore, the correct answer is B.
upvoted 1 times
...
helloworldabc
1 year, 9 months ago
BBBBBBBBB
upvoted 1 times
...
zaazanuna
1 year, 9 months ago
B - correct. The requirement is to provide additional safeguards to protect encrypted data at Application Load Balancers (ALBs) through the use of a unique random session key. To meet this requirement, the network engineer should use AWS Key Management Service (AWS KMS) to encrypt session keys. Therefore, the correct answer is option B.
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago