Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Amazon DVA-C02 Exam - Topic 3 Question 67 Discussion

A developer wants to use an Amazon CloudFront distribution to deliver a web application to users. Users will access the application through the internet.The developer needs to create an SSL/TLS certificate to use with the CloudFront distribution. The developer wants to minimize operational overhead by ensuring that the certificate is renewed automatically.Which solution will meet these requirements?
C) Create a public certificate that uses DNS validation in AWS Certificate Manager (ACM).
A) Create a public certificate that uses DNS validation in IAM.
B) Import a certificate into IAM. Configure managed renewal for the certificate.
D) Create a public certificate that uses email validation in AWS Certificate Manager (ACM).

Amazon DVA-C02 Exam - Topic 3 Question 67 Discussion

Actual exam question for Amazon's DVA-C02 exam
Question #: 67
Topic #: 3
[All DVA-C02 Questions]

A developer wants to use an Amazon CloudFront distribution to deliver a web application to users. Users will access the application through the internet.

The developer needs to create an SSL/TLS certificate to use with the CloudFront distribution. The developer wants to minimize operational overhead by ensuring that the certificate is renewed automatically.

Which solution will meet these requirements?

Show Suggested Answer Hide Answer
Suggested Answer: C

The best answer is to request a public certificate in AWS Certificate Manager and validate it with DNS. ACM manages public certificate renewal automatically when validation remains in place, which minimizes operational overhead. DNS validation is preferable to email validation because it does not require manual approval emails during renewal workflows. IAM server certificates are legacy-style certificate storage and do not provide the same managed lifecycle experience as ACM. Imported certificates are not automatically renewed by ACM because ACM does not control their issuance lifecycle. For CloudFront, AWS recommends ACM certificates, and CloudFront certificates must be requested or imported in the US East (N. Virginia) Region, although the option's key point is ACM public certificate with DNS validation. (AWS Documentation)

===============


Contribute your Thoughts:

0/2000 characters
Halina
2 days ago
Wait, can you really use DNS validation for automatic renewals?
upvoted 0 times
...
Dexter
7 days ago
I agree, ACM makes it super easy.
upvoted 0 times
...
Cecilia
12 days ago
Option C is the best choice for automatic renewal!
upvoted 0 times
...
Lorita
17 days ago
I vaguely recall that email validation can be a hassle for renewals, so I would lean away from option D.
upvoted 0 times
...
Maia
23 days ago
I practiced a similar question, and I feel like option C makes the most sense since it mentions automatic renewal with ACM.
upvoted 0 times
...
Mabel
28 days ago
I think using DNS validation is the best way to go for automatic renewals, but I'm not sure if it's specifically tied to IAM or ACM.
upvoted 0 times
...
Alfreda
1 month ago
I remember studying that AWS Certificate Manager (ACM) is the go-to for managing SSL/TLS certificates, especially for CloudFront.
upvoted 0 times
...

Save Cancel