Skip to content
BytePatterns

SCS-C03 · Domain 5: Data Protection · 18% of the exam

Task 5.1: Design and implement controls for data in transit

Protecting data on the wire: requiring TLS through load balancer security policies and policy conditions, private paths with PrivateLink, VPC endpoints, Client VPN and Verified Access, and encryption between nodes inside EMR, EKS, SageMaker AI and Nitro instances.

Study it

  • Requiring TLS: load balancer security policies and policy conditions

    Lesson coming

  • Private access: VPC endpoints, PrivateLink, Client VPN and Verified Access

    Partly covered by: VPC: Subnets, NAT & Firewalls

  • Encryption between nodes: EMR, EKS, SageMaker AI and Nitro

    Lesson coming

Sample questions

Try each one before opening the answer. Every option is explained, with the AWS documentation page that proves it.

Question 1 · choose 1

A bucket holds payment files that are read and written by applications in several AWS accounts. A new standard requires that every request to the bucket, from any principal, uses HTTPS with TLS 1.2 or later. What should the security team implement?

  1. ATurn on S3 Block Public Access settings for the bucket and the account
  2. BSet default encryption to SSE-KMS with a customer managed key and S3 Bucket Keys
  3. CAttach an SCP that denies S3 actions whenever aws:SecureTransport is false
  4. DBucket policy denies if aws:SecureTransport is false or s3:TlsVersion is below 1.2
Show the answer and why
  • ATurn on S3 Block Public Access settings for the bucket and the account

    Incorrect

    Block Public Access limits public grants. It does not control which protocol or TLS version a request uses.

  • BSet default encryption to SSE-KMS with a customer managed key and S3 Bucket Keys

    Incorrect

    Default encryption protects objects at rest. It says nothing about how requests travel to the bucket.

  • CAttach an SCP that denies S3 actions whenever aws:SecureTransport is false

    Incorrect

    An SCP applies only to principals in the organization's member accounts, not to every principal that can reach the bucket.

  • DBucket policy denies if aws:SecureTransport is false or s3:TlsVersion is below 1.2

    Correct

    The bucket policy applies to every request to the bucket; one deny blocks plain HTTP and the other blocks TLS versions older than 1.2.

Enforce transport rules where every request is evaluated: the bucket policy. aws:SecureTransport rules out HTTP, and s3:TlsVersion sets the minimum TLS version.

Question 2 · choose 1

A team created an Application Load Balancer with an HTTPS listener through CloudFormation, giving only the protocol, port and ACM certificate. A security scan reports that the listener accepts TLS 1.0 connections. The standard requires TLS 1.2 or later. What explains the finding, and what fixes it?

  1. ARequest a new ACM certificate, because the current one was issued for TLS 1.0
  2. BSet SslPolicy to a TLS13-1-2 policy; the template's default allows older TLS
  3. CChange the target group protocol from HTTP to HTTPS so that TLS 1.2 is used end to end
  4. DAssociate an AWS WAF web ACL with a rule that blocks requests that use TLS 1.0
Show the answer and why
  • ARequest a new ACM certificate, because the current one was issued for TLS 1.0

    Incorrect

    A certificate does not decide which TLS versions a listener accepts; the listener's security policy does.

  • BSet SslPolicy to a TLS13-1-2 policy; the template's default allows older TLS

    Correct

    Outside the console the default policy is ELBSecurityPolicy-2016-08, which still allows older protocols. Naming a TLS13-1-2 policy limits clients to TLS 1.2 and 1.3.

  • CChange the target group protocol from HTTP to HTTPS so that TLS 1.2 is used end to end

    Incorrect

    The target group protocol governs load balancer to target traffic, not the TLS versions that clients can negotiate with the listener.

  • DAssociate an AWS WAF web ACL with a rule that blocks requests that use TLS 1.0

    Incorrect

    The listener's security policy decides which TLS versions are negotiated. Web ACL rules inspect web requests and are not where allowed protocols are set.

The console and the API have different default security policies. Always set the policy explicitly in templates; AWS recommends the TLS 1.3 policies, including the post-quantum ones.

Question 3 · choose 2

EC2 instances in private subnets with no internet access must upload files to an S3 bucket. The traffic must stay on the AWS network, the endpoint must add no hourly charge, and the bucket must reject any request that does not arrive through that endpoint. Which actions meet these requirements? (Choose TWO.)

  1. AAdd a NAT gateway and a default route to it from the private subnets
  2. BBucket policy that allows only the private subnets' CIDR ranges in aws:SourceIp
  3. CCreate a gateway VPC endpoint for S3 on the private subnets' route tables
  4. DBucket policy that denies requests unless aws:SourceVpce is the endpoint ID
  5. ECreate an interface VPC endpoint for S3 with private DNS turned on
Show the answer and why
  • AAdd a NAT gateway and a default route to it from the private subnets

    Incorrect

    A NAT gateway sends traffic to S3's public endpoint and adds hourly and data processing charges.

  • BBucket policy that allows only the private subnets' CIDR ranges in aws:SourceIp

    Incorrect

    For requests through a VPC endpoint, aws:SourceIp is not available; VPC-specific keys must be used instead.

  • CCreate a gateway VPC endpoint for S3 on the private subnets' route tables

    Correct

    A gateway endpoint adds a route to S3 through a prefix list, and there is no additional charge for gateway endpoints.

  • DBucket policy that denies requests unless aws:SourceVpce is the endpoint ID

    Correct

    aws:SourceVpce names the endpoint the request came through, so the deny blocks every other path.

  • ECreate an interface VPC endpoint for S3 with private DNS turned on

    Incorrect

    Interface endpoints are billed per hour and per GB, which the requirement rules out.

Gateway endpoints are free and route by prefix list. Lock the bucket to the endpoint with aws:SourceVpce, and remember that this also blocks console access that does not come through the endpoint.

Question 4 · choose 1

A tightly coupled simulation runs on Hpc7a instances that exchange data constantly. Security requires that this traffic is encrypted in transit, with no application changes and no loss of network performance. Which deployment keeps the instances' automatic encryption in effect?

  1. AInstances in the same VPC that communicate directly with each other
  2. BInstances in two VPCs connected through a transit gateway
  3. CInstances in the same VPC that send traffic through a Network Load Balancer
  4. DInstances of any instance type placed in the same Availability Zone
Show the answer and why
  • AInstances in the same VPC that communicate directly with each other

    Correct

    Supported Nitro instance types encrypt traffic between instances in the same VPC or peered VPCs, with no impact on network performance.

  • BInstances in two VPCs connected through a transit gateway

    Incorrect

    Automatic encryption between instances does not apply when traffic passes through a transit gateway.

  • CInstances in the same VPC that send traffic through a Network Load Balancer

    Incorrect

    Traffic that passes through a load balancer is not covered by the automatic encryption between instances.

  • DInstances of any instance type placed in the same Availability Zone

    Incorrect

    Only listed instance types encrypt traffic between instances; the Availability Zone does not decide it.

Nitro-based in-transit encryption has three conditions: supported instance types, the same Region, and the same or peered VPCs with no virtual network device in the path.

Question 5 · choose 1

A web application behind an Application Load Balancer must serve HTTPS to its users. What does the load balancer need to terminate TLS for them?

  1. AAn HTTPS listener with a server certificate
  2. BA TCP listener on port 443 with no certificate
  3. CAn HTTP listener on port 443 with a security group rule
  4. DA KMS key attached to the load balancer
Show the answer and why
  • AAn HTTPS listener with a server certificate

    Correct

    An HTTPS listener needs at least one server certificate, which the load balancer uses to terminate the client connection.

  • BA TCP listener on port 443 with no certificate

    Incorrect

    Application Load Balancers do not offer TCP listeners; that design passes traffic through instead of terminating TLS.

  • CAn HTTP listener on port 443 with a security group rule

    Incorrect

    An HTTP listener does not use TLS, whatever its port.

  • DA KMS key attached to the load balancer

    Incorrect

    Load balancers do not use KMS keys to terminate TLS.

ACM certificates on load balancers renew automatically, which removes a common cause of outages.

Question 6 · choose 1

A branch office without Direct Connect must reach a VPC over an encrypted connection across the internet, using its existing router. What should the team set up?

  1. AVPC peering between the office and the VPC
  2. BA Site-to-Site VPN connection using IPsec
  3. CA NAT gateway in the VPC
  4. DAn internet gateway with an open security group
Show the answer and why
  • AVPC peering between the office and the VPC

    Incorrect

    VPC peering connects VPCs, not on-premises networks.

  • BA Site-to-Site VPN connection using IPsec

    Correct

    Site-to-Site VPN supports IPsec VPN connections between your network and your VPC.

  • CA NAT gateway in the VPC

    Incorrect

    NAT gives private resources outbound access; it is not a site link.

  • DAn internet gateway with an open security group

    Incorrect

    That exposes resources to the internet without encryption.

Each Site-to-Site VPN connection has two tunnels for redundancy.

Question 7 · choose 1

Partners upload files to the company with plain FTP today. The company wants a managed service that receives the files into Amazon S3 over an encrypted protocol. What should it use?

  1. AAWS Transfer Family with an SFTP endpoint
  2. BAWS Transfer Family with an FTP endpoint only
  3. CS3 Transfer Acceleration on the bucket
  4. DAn EC2 instance running an FTP server
Show the answer and why
  • AAWS Transfer Family with an SFTP endpoint

    Correct

    Transfer Family is a managed service for file transfers over SFTP and other protocols directly into AWS storage.

  • BAWS Transfer Family with an FTP endpoint only

    Incorrect

    FTP sends data and credentials unencrypted.

  • CS3 Transfer Acceleration on the bucket

    Incorrect

    Acceleration speeds up uploads; partners would still need S3 access and tools.

  • DAn EC2 instance running an FTP server

    Incorrect

    That is self-managed and still unencrypted.

Transfer Family also supports FTPS and AS2 when partners need those protocols.

Question 8 · choose 1

A data science team runs a distributed Amazon SageMaker AI training job on four ML compute instances in a private VPC. A compliance review requires SageMaker AI to encrypt all communication between those instances during training. What should the team set when it creates the job?

  1. AA KMS key in VolumeKmsKeyId of the job's resource configuration
  2. BEnableNetworkIsolation set to True for the training job
  3. CEnableInterContainerTrafficEncryption set to True for the job
  4. DA KMS key in the job's output data configuration
Show the answer and why
  • AA KMS key in VolumeKmsKeyId of the job's resource configuration

    Incorrect

    This key encrypts data on the storage volumes attached to the training instances, which is data at rest.

  • BEnableNetworkIsolation set to True for the training job

    Incorrect

    Network isolation blocks the container's other network calls but still allows calls between peers in the cluster; it does not encrypt them.

  • CEnableInterContainerTrafficEncryption set to True for the job

    Correct

    This setting encrypts all communications between the ML compute instances in distributed training.

  • DA KMS key in the job's output data configuration

    Incorrect

    This key encrypts the model artifacts at rest in Amazon S3.

Inter-container traffic encryption can lengthen training for deep learning jobs that exchange a lot of data, and the VPC security group must allow UDP 500 and ESP between the instances.

Question 9 · choose 1

A team is choosing an Amazon ElastiCache for Valkey deployment and requires in-transit encryption from day one without managing extra settings. Which statement is correct?

  1. AIn-transit encryption is never available for Valkey
  2. BNode-based clusters encrypt in transit unless turned off
  3. CEncryption at rest also encrypts client traffic
  4. DServerless caches always have in-transit encryption
Show the answer and why
  • AIn-transit encryption is never available for Valkey

    Incorrect

    ElastiCache supports TLS for Valkey and Redis OSS.

  • BNode-based clusters encrypt in transit unless turned off

    Incorrect

    For node-based clusters you turn it on when creating the replication group.

  • CEncryption at rest also encrypts client traffic

    Incorrect

    At-rest encryption does not protect data in transit.

  • DServerless caches always have in-transit encryption

    Correct

    All Valkey or Redis OSS serverless caches have in-transit encryption enabled.

Clients must connect with TLS once in-transit encryption is on.

Practise domain 5 →Practise all domains →