AWS Certified Advanced Networking – Specialty (ANS-C01)Network Security, Compliance, and GovernanceMedium

A company is deploying a new web application that will host sensitive customer data. The security team requires that all HTTP traffic be automatically redirected to HTTPS, and that only strong ciphers and TLS versions are allowed for secure communication. This policy must be enforced at the load balancer level to offload SSL/TLS processing from the backend servers. Which configuration on an Application Load Balancer (ALB) listener would achieve these goals?

  1. AUse a Network Load Balancer (NLB) with a TLS listener and configure the security policy on the target groups.
  2. BConfigure an HTTP listener with a redirect action to HTTPS, and an HTTPS listener with a custom security policy.
  3. CImplement AWS WAF rules to block HTTP traffic and enforce strong ciphers on the application.
  4. DConfigure an HTTP listener and an HTTPS listener, applying the strong ciphers and TLS versions to the EC2 instances.
Show answer & explanation

Correct answer: B. Configure an HTTP listener with a redirect action to HTTPS, and an HTTPS listener with a custom security policy.

An ALB can be configured with an HTTP listener to automatically redirect all incoming HTTP traffic to HTTPS. An HTTPS listener on the ALB can then be configured with a predefined or custom security policy to enforce specific TLS versions and strong ciphers, offloading this responsibility from the backend instances and ensuring secure communication at the load balancer level.

Why the other options are wrong

  • A. An NLB operates at Layer 4 and does not support HTTP to HTTPS redirection or custom security policies for TLS versions/ciphers in the same way an ALB does for application-layer requirements.
  • C. AWS WAF can block HTTP traffic (though redirection is better for user experience), but it does not enforce specific TLS versions or ciphers for the connection itself, which is handled at the load balancer or application layer.
  • D. Applying strong ciphers and TLS versions to EC2 instances does not offload SSL/TLS processing from backend servers and means the ALB isn't enforcing the policy.

ALB Listener Security Policies

Application Load Balancers (ALB) can be configured with HTTPS listeners and security policies to enforce TLS versions and ciphers, and HTTP listeners for redirection to HTTPS.

  • ALB HTTP listener can redirect to HTTPS.
  • ALB HTTPS listener supports predefined and custom security policies.
  • Security policies define allowed TLS versions and cipher suites.
  • ALB offloads SSL/TLS processing from backend instances.

Memory trick: Listeners redirect to HTTPS, policies secure the TLS handshake.

More Network Security, Compliance, and Governance questions