AWS Certified DevOps Engineer – ProfessionalSecurity and ComplianceEasy

A DevOps team is deploying a new web application behind an Application Load Balancer (ALB) and needs to ensure that all traffic between the ALB and the EC2 instances is encrypted. The application uses HTTPS, and the EC2 instances are running Apache. Which configuration step is MOST critical to achieve this requirement?

  1. AConfigure the ALB listener to use HTTP and redirect traffic to HTTPS on the EC2 instances.
  2. BInstall valid SSL/TLS certificates on each EC2 instance and configure the ALB target group to use HTTPS.
  3. CEnable AWS WAF on the ALB to inspect and encrypt traffic before forwarding it to the instances.
  4. DSet up a VPN tunnel between the ALB and the EC2 instances to secure the communication channel.
Show answer & explanation

Correct answer: B. Install valid SSL/TLS certificates on each EC2 instance and configure the ALB target group to use HTTPS.

To ensure traffic between the ALB and EC2 instances is encrypted, both ends of this connection must use HTTPS. This requires installing certificates on the EC2 instances and configuring the target group to use HTTPS for health checks and forwarding.

Why the other options are wrong

  • A. This would decrypt traffic at the ALB and send it unencrypted to the instances, failing the requirement.
  • C. AWS WAF is for web application firewalling and does not inherently encrypt traffic between the ALB and instances.
  • D. A VPN tunnel is overly complex and unnecessary for securing intra-VPC traffic between an ALB and EC2 instances; native TLS is sufficient.

ALB-to-EC2 Encryption

To encrypt traffic between an Application Load Balancer and its backend EC2 instances, the backend instances must have SSL/TLS certificates installed and the ALB's target group must be configured to use HTTPS.

  • ALB can terminate SSL/TLS, but this doesn't encrypt to instances.
  • Target group protocol determines ALB-to-instance communication.
  • Instances need certs if the target group uses HTTPS.

Memory trick: ALB needs a 'cert' to talk 'securely' to 'servers'.

More Security and Compliance questions