Use an ALB HTTPS listener security policy with a PFS cipher suite
A company deploys a distributed web application on a fleet of Amazon EC2 instances. The fleet is behind an Application Load Balancer (ALB) that will be configured to terminate the TLS connection. All TLS traffic to the ALB must stay secure, even if the certificate private key is compromised. How can a security engineer meet this requirement?
Community Votes
100% of anonymous learners picked answer B. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
PFS (via ECDHE/DHE ephemeral key exchange) means the long-term private key is never used to derive session keys; compromising it later does not expose past traffic. Server Order Preference (C) only controls cipher negotiation order, not PFS; a TCP listener (D) would bypass TLS termination/ALB cert handling entirely; an ACM-managed cert (A) alone does not guarantee PFS.
TLS terminates at an ALB and must remain secure even if the certificate's private key is compromised. A listener security policy that enforces a Perfect Forward Secrecy (PFS) cipher suite ensures each session uses a unique ephemeral key, so a future private-key compromise cannot decrypt previously captured TLS sessions.
Choosing Server Order Preference (C)—it affects which cipher the server picks but does not by itself enforce PFS. Using a TCP listener (D) breaks ALB TLS termination (no cert/PFS at the ALB). Assuming an ACM cert (A) is sufficient—certificate management does not equal forward-secret ciphers.
Community Discussion (3 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.