Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Amazon ANS-C01 Exam - Topic 2 Question 70 Discussion

A company deploys a new web application on Amazon EC2 instances. The application runs in private subnets in three Availability Zones behind an Application Load Balancer (ALB). Security auditors require encryption of all connections. The company uses Amazon Route 53 for DNS and uses AWS Certificate Manager (ACM) to automate SSL/TLS certificate provisioning. SSL/TLS connections are terminated on the ALB.The company tests the application with a single EC2 instance and does not observe any problems. However, after production deployment, users report that they can log in but that they cannot use the application. Every new web request restarts the login process.What should a network engineer do to resolve this issue?
C) Modify the ALB target group configuration by enabling the stickiness attribute. Use an application-based cookie. Set the duration to the maximum application session length.
A) Modify the ALB listener configuration. Edit the rule that forwards traffic to the target group. Change the rule to enable group-level stickiness. Set the duration to the maximum application session length.
B) Replace the ALB with a Network Load Balancer. Create a TLS listener. Create a new target group with the protocol type set to TLS Register the EC2 instances. Modify the target group configuration by enabling the stickiness attribute.
D) Remove the ALB. Create an Amazon Route 53 rule with a failover routing policy for the application name. Configure ACM to issue certificates for each EC2 instance.

Amazon ANS-C01 Exam - Topic 2 Question 70 Discussion

Actual exam question for Amazon's ANS-C01 exam
Question #: 70
Topic #: 2
[All ANS-C01 Questions]

A company deploys a new web application on Amazon EC2 instances. The application runs in private subnets in three Availability Zones behind an Application Load Balancer (ALB). Security auditors require encryption of all connections. The company uses Amazon Route 53 for DNS and uses AWS Certificate Manager (ACM) to automate SSL/TLS certificate provisioning. SSL/TLS connections are terminated on the ALB.

The company tests the application with a single EC2 instance and does not observe any problems. However, after production deployment, users report that they can log in but that they cannot use the application. Every new web request restarts the login process.

What should a network engineer do to resolve this issue?

Show Suggested Answer Hide Answer
Suggested Answer: C

Contribute your Thoughts:

0/2000 characters
Adelina
3 days ago
Is it really that simple? I’m surprised they didn’t catch this in testing.
upvoted 0 times
...
Stephanie
8 days ago
Definitely need stickiness for user sessions.
upvoted 0 times
...
Isidra
13 days ago
Wait, why would you remove the ALB? That seems risky.
upvoted 0 times
...
Lizette
19 days ago
I think option C is the way to go!
upvoted 0 times
...
Miriam
24 days ago
Sounds like a classic session stickiness issue.
upvoted 0 times
...
Erinn
29 days ago
I recall that removing the ALB entirely seems drastic. I don't think that's the right approach, especially since the ALB handles SSL termination.
upvoted 0 times
...
Mitsue
1 month ago
I think option C sounds right, but I'm a bit confused about whether to use application-based cookies or not. We didn't cover that in depth.
upvoted 0 times
...
Hayley
1 month ago
I'm not entirely sure, but I feel like modifying the ALB listener could also be a solution. We did a similar question where listener rules were key.
upvoted 0 times
...
Gussie
1 month ago
I remember we discussed stickiness in our last practice session. I think enabling it on the ALB target group might help with the session issues.
upvoted 0 times
...

Save Cancel