AWS Certified Advanced Networking – Specialty (ANS-C01)Network Security, Compliance, and GovernanceEasy
A company is deploying a new web application that will handle sensitive customer data. They need to ensure that all data in transit between the client browser and the application's Elastic Load Balancer (ELB) is encrypted using TLS 1.2 or higher. Additionally, they must prevent any connections using older, less secure TLS versions. How can this be achieved using AWS services?
- AInstall a custom Nginx configuration on the EC2 instances behind the ELB to enforce TLS 1.2.
- BImplement AWS WAF rules to block requests that negotiate TLS versions older than 1.2.
- CConfigure the ELB listener to use a custom security policy that specifies TLS 1.2 and later, and disable older protocols.
- DUse Security Groups to block incoming traffic on ports associated with older TLS versions.
Show answer & explanationAnswer & explanation
Correct answer: C. Configure the ELB listener to use a custom security policy that specifies TLS 1.2 and later, and disable older protocols.
Elastic Load Balancers (both Application Load Balancer and Classic Load Balancer) allow you to configure listener security policies. These policies define the SSL/TLS protocols and ciphers that the load balancer uses for frontend connections, enabling you to enforce TLS 1.2 or higher.
Why the other options are wrong
- A. While Nginx can enforce TLS versions, configuring it on backend instances doesn't enforce it for the client-to-ELB connection, which is the primary focus here. The ELB handles the frontend TLS termination.
- B. AWS WAF operates at the application layer and cannot directly enforce TLS version negotiation. TLS is handled at a lower layer (transport layer).
- D. Security Groups operate at the port and protocol level (Layer 4) and cannot distinguish between different TLS versions negotiating on the same port (e.g., 443).
ELB Listener Security Policies
ELB listener security policies define the SSL/TLS protocols and ciphers that the load balancer uses when negotiating connections with clients, allowing for enforcement of specific TLS versions.
- Configured on ELB listeners (e.g., HTTPS listener).
- Controls accepted TLS protocols (e.g., TLS 1.2, 1.3).
- Controls accepted cipher suites.
Memory trick: ELB's Listener Policy: Your TLS Bouncer at the Door.