A security team must ensure that an internet-facing Application Load Balancer negotiates only TLS 1.2 or TLS 1.3 with clients. Customers who still open the site from old http:// bookmarks must arrive at the HTTPS version of the page instead of receiving an error. Which listener configuration meets both requirements?
Choose one.
On an ALB, the HTTPS listener's security policy sets the minimum TLS version and cipher list, and moving HTTP users to HTTPS is a redirect action on a separate HTTP:80 listener.
Two controls are needed: a TLS 1.2+ security policy on the HTTPS listener (ELBSecurityPolicy-TLS13-1-2-2021-06 offers TLS 1.3 and 1.2 only) and a port-80 listener with a redirect action. Deleting the port-80 listener enforces HTTPS but turns bookmark visits into errors. ELBSecurityPolicy-2016-08 keeps the redirect but still negotiates TLS 1.0/1.1. Forwarding port 80 to an HTTPS target group encrypts the back-end hop while the client keeps using HTTP.
- Split the requirement into the client TLS version and the treatment of plaintext requests.
- The TLS version is set by the security policy on the HTTPS listener, so pick a TLS 1.2+ policy.
- Plaintext requests need a listener on port 80 that answers with a redirect, not a forward and not a missing listener.
- Check that the chosen policy name does not still allow TLS 1.0/1.1.
Exam tip: ALB TLS minimum = listener security policy; HTTP to HTTPS = a redirect action on the port-80 listener.
Data in Transit on AWS: TLS, ACM, and End-to-End Encryption Design — the lesson that teaches this.