A healthcare startup encrypts data at rest in Amazon S3 using SSE-KMS and now wants to ensure that data is also protected while traveling between clients and the Application Load Balancer over the internet. Which combination of AWS services best addresses encryption in transit for this scenario?
- AAmazon Macie to scan traffic and automatically encrypt data packets
- BAWS Certificate Manager to provision a TLS certificate attached to an HTTPS listener on the ALB
- CAWS KMS to generate a symmetric key applied directly to the ALB listener
- DAWS Config to enforce a rule requiring HTTPS on all EC2 instances
Show answer & explanationAnswer & explanation
Correct answer: B. AWS Certificate Manager to provision a TLS certificate attached to an HTTPS listener on the ALB
Encryption in transit for web traffic is achieved using TLS/SSL certificates. AWS Certificate Manager (ACM) provisions and manages public/private TLS certificates that can be attached to an HTTPS listener on an Application Load Balancer, encrypting data between clients and the ALB. KMS manages encryption keys for data at rest (and some in-transit key operations) but does not directly secure ALB listener traffic; Macie discovers sensitive data patterns, not transit encryption; and AWS Config evaluates configuration compliance but does not itself implement encryption.
Why the other options are wrong
- A. Macie is a data discovery/classification service for sensitive data in S3, not a transit encryption tool.
- C. KMS keys handle data-at-rest and some cryptographic operations, not TLS listener encryption directly.
- D. AWS Config can check for HTTPS usage compliance but does not implement or enable encryption itself.
Encryption in Transit with ACM
AWS Certificate Manager provisions TLS/SSL certificates that can be attached to load balancer listeners to encrypt data between clients and AWS resources.
- ACM certificates are free for use with integrated AWS services like ALB and CloudFront
- Encryption in transit protects data as it moves over networks
- Complements at-rest encryption like SSE-KMS for full data protection
Memory trick: ACM = the padlock icon in your browser's address bar