Medium1 markMultiple Choice
Domain 1.3: Data SecurityACMSecurityCertificates

AWS SAA-C03 · Question 20 · Domain 1.3: Data Security

A company uses AWS Certificate Manager (ACM) to provision SSL/TLS certificates for their Application Load Balancers. The security team wants to ensure that certificates are automatically renewed before they expire. What must the solutions architect do to enable this?

Answer options:

A.

Write a Lambda function to trigger the renewal API call.

B.

Ensure the certificates are validated via DNS validation.

C.

Configure an EventBridge rule to notify administrators to manually renew.

D.

Use AWS Config to automatically remediate expired certificates.

How to approach this question

Recall the requirement for ACM automatic renewal.

Full Answer

B.Ensure the certificates are validated via DNS validation.✓ Correct
AWS Certificate Manager (ACM) provides managed renewal for Amazon-issued SSL/TLS certificates. If you use DNS validation, ACM can automatically renew your certificates as long as the DNS record remains in place.

Common mistakes

Thinking email validation supports fully automated, hands-off renewal.

Practice the full AWS SAA-C03 Practice Exam 5

65 questions · hints · full answers · grading

More questions from this exam