Encryption in transit protects data as it moves between clients and services, and between services themselves, so that anyone who can observe the network cannot read or alter it. On AWS that almost always means Transport Layer Security (TLS), the protocol behind HTTPS. To offer TLS you need an X.509 certificate for your domain, and AWS Certificate Manager (ACM) is the service that provides and manages them. The exam tests where certificates can live, where TLS is terminated, and how to force clients to use it.
Keep reading for free
Create a free StudyToCert account to read the rest of this lesson: 7 more sections, 6 key terms, a real-world example, an exam tip and self-check questions. Every lesson, lab and practice test is free with an account.