What the exam asks
- HTTPS on CloudFront with a custom domain → an ACM certificate in us-east-1.
- Certificates that renew themselves → ACM-issued with DNS validation. Imported certificates never renew automatically.
- End-to-end encryption through a load balancer → an HTTPS listener plus an HTTPS target group. If the load balancer must not decrypt → NLB TCP pass-through.
- Require TLS to a service → aws:SecureTransport (S3), rds.force_ssl / require_secure_transport (RDS), the viewer protocol policy (CloudFront).
- “Who did what, and when” → CloudTrail. “What did it look like, and is it compliant” → AWS Config. “AWS’s own compliance reports” → AWS Artifact.
- Tamper-proof logs → integrity validation + Object Lock. Ransomware-proof backups → AWS Backup Vault Lock in compliance mode with cross-account copies.
Core ideas
Where TLS terminates
| Component | Terminates TLS? | Notes |
|---|---|---|
| CloudFront | Yes, at the edge | The viewer protocol policy redirects HTTP to HTTPS or allows HTTPS only. Set the origin protocol policy to HTTPS only to encrypt traffic to the origin as well. |
| ALB | Yes | HTTPS listener with an ACM certificate. An HTTPS target group re-encrypts traffic to the targets. The ALB does not validate target certificates, so self-signed ones work. A listener rule redirects HTTP to HTTPS. |
| NLB with a TLS listener | Yes | ACM certificate on the NLB, which offloads TLS from the targets. |
| NLB with a TCP listener on 443 | No | Pass-through. The targets terminate TLS and can inspect client certificates. |
| API Gateway | Yes | HTTPS endpoints only. Custom domains use ACM certificates. |