exam questions

Exam AWS Certified Security - Specialty All Questions

View all questions & answers for the AWS Certified Security - Specialty exam

Exam AWS Certified Security - Specialty topic 1 question 500 discussion

Exam question from Amazon's AWS Certified Security - Specialty
Question #: 500
Topic #: 1
[All AWS Certified Security - Specialty Questions]

A company hosts an end user application on AWS. Currently, the company deploys the application on Amazon EC2 instances behind an Elastic Load Balancer. The company wants to configure end-to-end encryption between the Elastic Load Balancer and the EC2 instances.

Which solution will meet this requirement with the LEAST operational effort?

  • A. Use Amazon issued AWS Certificate Manager (ACM) certificates on the EC2 instances and the Elastic Load Balancer to configure end-to-end encryption.
  • B. Import a third-party SSL certificate to AWS Certificate Manager (ACM). Install the third-party certificate on the EC2 instances. Associate the ACM imported third-party certificate with the Elastic Load Balancer.
  • C. Deploy AWS CloudHSM. Import a third-party certificate. Configure the EC2 instances and the Elastic Load Balancer to use the CloudHSM imported certificate.
  • D. Import a third-party certificate bundle to AWS Certificate Manager (ACM). Install the third-party certificate on the EC2 instances. Associate the ACM imported third-party certificate with the Elastic Load Balancer.
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
6_8ftwin
Highly Voted 1 year, 10 months ago
Selected Answer: B
There is no mention of AWS Nitro Enclaves. EC2 is not integrated with ACM: https://docs.aws.amazon.com/acm/latest/userguide/acm-services.html A third party certificate must be used: https://www.youtube.com/watch?v=6Nz0RFfBqVE https://repost.aws/knowledge-center/configure-acm-certificates-ec2
upvoted 9 times
...
Mark1000
Highly Voted 1 year, 10 months ago
A Less effort AWS ACM certificates on ELB and EC2 instances
upvoted 9 times
p4v10
1 year, 10 months ago
Agree!
upvoted 4 times
...
Toptip
1 year, 10 months ago
Lol...
upvoted 1 times
...
Green53
1 year, 10 months ago
A can't be the answer, since it explictly states they want end-to-end encryption. You can't export the certificate or key from ACM, unless it's in Nitro Enclaves, so it can't be used on an EC2 instance (think IIS or Apache). The answer is B. See https://repost.aws/knowledge-center/configure-acm-certificates-ec2
upvoted 3 times
Noexperience
1 year, 8 months ago
The certificate is between the Elastic load balancer and EC2, not external facing. So option A is still valid, I believe.
upvoted 1 times
...
...
...
LazyAutonomy
Most Recent 1 year, 2 months ago
Selected Answer: D
Is everyone voting here that inexperienced? Importing the leaf cert usually won't be enough, the ELB will usually need to serve subs because client trust stores tend to only have root CAs. D is the same as B except it specially includes the step to also import the "bundle" - i.e. the subordinate CA issuer. This is necessary. The subordinate CA/chain isn't needed on the EC2 instance because, as others have pointed out, ELBs don't validate SSL certs against internal trust stores anyway.
upvoted 1 times
...
[Removed]
1 year, 6 months ago
Selected Answer: B
A is not correct. Configuring an Amazon Issued ACM public certificate for a website that's hosted on an EC2 instance requires exporting the certificate. However, you can't export the certificate because ACM manages the private key that signs and creates the certificate.
upvoted 1 times
...
Nuha_23
1 year, 8 months ago
Selected Answer: A
The load balancer doesn't care if your instance's certificate is self-signed or issued by a trusted certificate authority, and will accept any certificate presented to it. https://docs.aws.amazon.com/elasticbeanstalk/latest/dg/configuring-https-endtoend.html
upvoted 1 times
...
Noexperience
1 year, 8 months ago
Selected Answer: A
Use Amazon issued AWS Certificate Manager (ACM) certificates on the EC2 instances and the Elastic Load Balancer to configure end-to-end encryption. This option involves using AWS Certificate Manager (ACM) to issue and manage SSL/TLS certificates. By using ACM certificates, you can easily create, deploy, and renew certificates without the need for manual intervention. ACM automatically takes care of the certificate lifecycle management, including provisioning, renewal, and integration with services like Elastic Load Balancer.
upvoted 1 times
...
wmp7039
1 year, 9 months ago
Selected Answer: B
B : Public ACM certificates can be installed on Amazon EC2 instances that are connected to a Nitro Enclave, but not to other Amazon EC2 instances. https://docs.aws.amazon.com/acm/latest/userguide/acm-services.html
upvoted 3 times
...
rajkanch
1 year, 10 months ago
Answer B : https://docs.aws.amazon.com/elasticbeanstalk/latest/dg/configuring-https-endtoend.html
upvoted 2 times
rajkanch
1 year, 10 months ago
https://repost.aws/knowledge-center/configure-acm-certificates-ec2" you can understand acm cannot be used on ec2
upvoted 1 times
...
...
cloudenthusiast
1 year, 10 months ago
Selected Answer: A
option A: "Use Amazon issued AWS Certificate Manager (ACM) certificates on the EC2 instances and the Elastic Load Balancer to configure end-to-end encryption." Using Amazon-issued ACM certificates simplifies the certificate management process, as ACM takes care of certificate provisioning, renewal, and integration. By leveraging ACM certificates, the company can easily configure end-to-end encryption between the Elastic Load Balancer and the EC2 instances without the need to import third-party certificates or manage them separately. This option reduces operational effort because the company can rely on ACM's automation and integration with other AWS services to handle certificate management seamlessly.
upvoted 5 times
Toptip
1 year, 10 months ago
Be careful from this guy.. i think he's an AWS dude...
upvoted 5 times
yorkicurke
1 year, 3 months ago
No wonder he/she is so 'enthusiast ' :)
upvoted 1 times
...
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago