Use an ALB HTTPS listener security policy with a PFS cipher suite

Answer Correct answer: B — an ALB HTTPS listener with a PFS cipher-suite security policy keeps sessions secure even if the private key leaks.

A company deploys a distributed web application on a fleet of Amazon EC2 instances. The fleet is behind an Application Load Balancer (ALB) that will be configured to terminate the TLS connection. All TLS traffic to the ALB must stay secure, even if the certificate private key is compromised. How can a security engineer meet this requirement?

  1. Create an HTTPS listener that uses a certificate that is managed by AWS Certificate Manager (ACM).
  2. Create an HTTPS listener that uses a security policy that uses a cipher suite with perfect forward secrecy (PFS). Correct Answer
  3. Create an HTTPS listener that uses the Server Order Preference security feature.
  4. Create a TCP listener that uses a custom security policy that allows only cipher suites with perfect forward secrecy (PFS).

Community Votes

B
100%

100% of anonymous learners picked answer B. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

PFS (via ECDHE/DHE ephemeral key exchange) means the long-term private key is never used to derive session keys; compromising it later does not expose past traffic. Server Order Preference (C) only controls cipher negotiation order, not PFS; a TCP listener (D) would bypass TLS termination/ALB cert handling entirely; an ACM-managed cert (A) alone does not guarantee PFS.

TLS terminates at an ALB and must remain secure even if the certificate's private key is compromised. A listener security policy that enforces a Perfect Forward Secrecy (PFS) cipher suite ensures each session uses a unique ephemeral key, so a future private-key compromise cannot decrypt previously captured TLS sessions.

Choosing Server Order Preference (C)—it affects which cipher the server picks but does not by itself enforce PFS. Using a TCP listener (D) breaks ALB TLS termination (no cert/PFS at the ALB). Assuming an ACM cert (A) is sufficient—certificate management does not equal forward-secret ciphers.

Community Discussion (3 comments)

heatblur 👍 2 Selected: B
Perfect Forward Secrecy (PFS): This is the key feature that addresses the security requirement. PFS ensures that even if the private key is compromised in the future, past communications cannot be decrypted. This meets the requirement that "All TLS traffic to the ALB must stay secure, even if the certificate private key is compromised."
Certified101 👍 3 Selected: B
B as Zek mentioned
Zek 👍 4
B - correct answer https://aws.amazon.com/blogs/aws/elastic-load-balancing-perfect-forward-secrecy-and-other-security-enhancements/

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

A PFS-capable cipher suite (e.g., ECDHE) on the ALB HTTPS listener uses a unique ephemeral key per session, so the long-term certificate private key is never used to derive session keys. If that private key is later compromised, past captured TLS sessions cannot be decrypted—directly meeting the requirement.

Why the Other Options Are Wrong

C (Server Order Preference) only sets negotiation order and does not guarantee PFS ciphers. D (TCP listener) bypasses ALB TLS termination entirely, defeating certificate/PFS handling at the load balancer. A (ACM cert) manages the certificate but does not by itself enforce forward secrecy. B is the correct control.

Community Comment Notes

Community voted B (100). Commenters explained PFS ensures a future private-key compromise cannot decrypt past sessions, and noted B as the correct answer with the ELB PFS blog. C was distinguished as order-preference only.

Official Reference

Related Analysis

← Back to SCS-C02 Study Guide