How to Enforce TLS 1.2 on an AWS Transfer Family Server?
A company is using an AWS Transfer Family server to migrate data from an on-premises environment to AWS. Company policy mandates the use of TLS 1.2 or above to encrypt the data in transit. Which solution will meet these requirements?
Community Votes
100% of anonymous learners picked answer C. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
The question tests whether you know that TLS protocol versions on AWS Transfer Family are governed by the server security policy; the trap is reaching for certificates, SSH keys, or security groups, none of which can constrain the negotiated TLS version.
AWS Transfer Family servers enforce encryption-in-transit standards through the server's security policy, not through certificates or network ACLs. This page confirms that updating the Transfer Family server security policy to require a minimum TLS 1.2 protocol version is what satisfies the company's policy mandate.
The most tempting wrong answer is D — installing an SSL certificate on the Transfer Family server — because it sounds like it 'enables TLS 1.2.' In reality a certificate only supplies the key material for the endpoint; the server will still negotiate older protocol versions unless the security policy sets a minimum TLS version.
Community Discussion (4 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
AWS Transfer Family exposes a SecurityPolicyName setting on every server, and the bundled security policies (for example TransferSecurityPolicy-2024-01 and the FIPS variants) define exactly which TLS protocol versions and ciphers the endpoint will accept during the handshake. When a company mandate requires TLS 1.2 or above, the supported and auditable fix is to update the server's security policy so the minimum accepted protocol version is TLS 1.2, which can be done in the console or with update-server --security-policy-name. Option C describes precisely that action, so it is the only choice that actually changes what protocol versions the SFTP/FTPS/AS2 endpoint will negotiate with on-premises clients. Because the control lives on the server itself, it applies to every connection regardless of source network, which is what a policy mandate demands.
Why the Other Options Are Wrong
Option A rotates SSH host keys, which is an authentication and host-identity concern, not a transport-encryption or protocol-version control; keeping old keys alongside new ones changes nothing about which TLS version is negotiated. Option B tries to enforce an application-layer protocol version with security group rules, but security groups operate at Layers 3 and 4 — they match IP addresses, ports, and protocols like TCP, and they cannot inspect or restrict the TLS version inside the handshake. Option D installs a certificate, which provides the server's identity and the public key used for encryption, but a certificate does not restrict which protocol versions the listener will accept; without a security policy setting a minimum TLS version, legacy clients could still complete a TLS 1.0 or 1.1 handshake.
Community Comment Notes
Community sentiment is unanimous here, and it aligns with the AWS documentation. Bmaster points to the AWS Transfer Family security policies documentation page as the authoritative source, which is the correct reference for this control. Ja13 restates the scenario and lands on C, while HunkyBunky says simply "Only C is good" and Palee states "C is correct." With the vote distribution at 100% for C, this is one of the rare questions where the crowd, the source key, and the vendor documentation all agree.
Official Reference
Exam Strategy
When a requirement names a specific protocol version (TLS 1.2, TLS 1.3) for a managed AWS service, look for the service's own policy or protocol-setting resource rather than network-layer or certificate-based answers. Certificates enable encryption; policies decide which versions are permitted — DEA-C01 repeatedly rewards that distinction.
Frequently Asked Questions
Why doesn't installing an SSL certificate (option D) enforce TLS 1.2?
A certificate supplies the identity and key material for the endpoint, but it does not restrict which protocol versions the server accepts. Only the Transfer Family security policy sets the minimum TLS version.
Can security group rules restrict connections to TLS 1.2 or above?
No. Security groups filter traffic at Layers 3 and 4 using IPs, ports, and protocols such as TCP, so they cannot inspect or limit the TLS version negotiated inside a connection.
Related Analysis
Practice All DEA-C01 Questions
Access 100 questions with complete answers and detailed explanations.
View Full DEA-C01 Practice Test →