For IndividualsFor Educators
ExpertMinds LogoExpertMinds
ExpertMinds

Ace your certifications with Practice Exams and AI assistance.

  • Browse Exams
  • For Educators
  • Blog
  • Privacy Policy
  • Terms of Service
  • Cookie Policy
  • Support
  • AWS SAA Exam Prep
  • PMI PMP Exam Prep
  • CPA Exam Prep
  • GCP PCA Exam Prep

© 2026 TinyHive Labs. Company number 16262776.

    PracticeAWS Solutions Architect Professional (SAP-C02)AWS Solutions Architect Professional SAP-C02 Practice Exam 7Question 09
    Medium1 markMultiple Choice
    Domain 2.3: Security ControlsSecurityEncryptionALBRDS

    AWS SAP-C02 · Question 09 · Domain 2.3: Security Controls

    A healthcare company is building a new patient portal on AWS. The application uses an Application Load Balancer (ALB), Amazon EC2 instances in an Auto Scaling group, and an Amazon RDS for MySQL database. To meet HIPAA compliance, all data must be encrypted at rest and in transit. How should the architect ensure end-to-end encryption in transit from the user to the database?

    Answer options:

    A.

    Configure an HTTPS listener on the ALB. Terminate SSL at the ALB and route traffic to EC2 over HTTP. Use AWS KMS to encrypt the RDS database.

    B.

    Configure an HTTPS listener on the ALB with an ACM certificate. Configure the ALB to route traffic to EC2 instances over HTTPS. Enforce SSL/TLS connections in the RDS parameter group.

    C.

    Use a Network Load Balancer (NLB) with TCP passthrough to the EC2 instances. Use AWS Certificate Manager to deploy certificates directly to the RDS instance.

    D.

    Enable AWS Shield Advanced on the ALB to automatically encrypt all incoming and outgoing traffic.

    How to approach this question

    Ensure every network hop is encrypted.

    Full Answer

    B.Configure an HTTPS listener on the ALB with an ACM certificate. Configure the ALB to route traffic to EC2 instances over HTTPS. Enforce SSL/TLS connections in the RDS parameter group.✓ Correct
    To achieve end-to-end encryption, SSL/TLS must be used from the client to the ALB, from the ALB to the EC2 instances, and from the EC2 instances to the RDS database.

    Common mistakes

    Terminating SSL at the ALB and using HTTP to the backend targets.
    Question 08All questionsQuestion 10

    Practice the full AWS Solutions Architect Professional SAP-C02 Practice Exam 7

    75 questions · hints · full answers · grading

    Sign up freeTake the exam

    More questions from this exam

    Q01A global enterprise is designing a multi-region network architecture connecting 50 AWS accounts a...HardQ02A company is migrating its hybrid network to AWS. They have two 10 Gbps AWS Direct Connect connec...HardQ03An enterprise has 100 AWS accounts in AWS Organizations. The security team mandates that all Amaz...MediumQ04A financial company requires that all EBS volumes, S3 buckets, and RDS databases be encrypted usi...EasyQ05An enterprise is designing a disaster recovery strategy for a critical application running on Ama...Hard
    View all 75 questions →