A network engineer must provide additional safeguards to protect encrypted data at Application Load Balancers (ALBs) through the use of a unique random session key. What should the network engineer do to meet this requirement?
A.
Change the ALB security policy to a policy that supports TLS 1.2 protocol only
B.
Use AWS Key Management Service (AWS KMS) to encrypt session keys
C.
Associate an AWS WAF web ACL with the ALBs. and create a security rule to enforce forward secrecy (FS)
D.
Change the ALB security policy to a policy that supports forward secrecy (FS)
Option D)
Use ELBSecurityPolicy-FS policies, if you require Forward Secrecy
• Provides additional safeguards against the eavesdropping of encrypted data • Using a unique random session key
Perfect Forward Secrecy is a feature that provides additional safeguards against the eavesdropping of encrypted data, through the use of a unique random session key. This prevents the decoding of captured data, even if the secret long-term key is compromised.
https://aws.amazon.com/about-aws/whats-new/2014/02/19/elastic-load-balancing-perfect-forward-secrecy-and-more-new-security-features/
https://aws.amazon.com/about-aws/whats-new/2018/06/application-load-balancer-adds-new-security-policies-including-policy-for-forward-secrecy/
D is the correct answer
Perfect Forward Secrecy is a feature that provides additional safeguards against the eavesdropping of encrypted data, through the use of a unique random session key. This prevents the decoding of captured data, even if the secret long-term key is compromised.
To provide additional safeguards to protect encrypted data at Amazon Application Load Balancers (ALBs) through the use of a unique random session key, the network engineer should use AWS Key Management Service (AWS KMS) to encrypt session keys. Therefore, the correct answer is B.
B - correct.
The requirement is to provide additional safeguards to protect encrypted data at Application Load Balancers (ALBs) through the use of a unique random session key. To meet this requirement, the network engineer should use AWS Key Management Service (AWS KMS) to encrypt session keys. Therefore, the correct answer is option B.
upvoted 1 times
...
Log in to ExamTopics
Sign in:
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one.
So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
study_aws1
Highly Voted 1 year, 9 months agotiti_r
Highly Voted 1 year, 8 months agobtech24
Most Recent 3 months, 1 week agoRaphaello
8 months, 2 weeks agomarfee
10 months, 2 weeks agoILOVEVODKA
1 year, 9 months agofojta
1 year, 9 months agohelloworldabc
1 year, 9 months agozaazanuna
1 year, 9 months ago