A CloudOps engineer is configuring an Amazon CloudFront distribution to use an SSL/TLS certificate. The CloudOps engineer must ensure automatic certificate renewal.
Which combination of steps will meet this requirement? (Select TWO.)
The AWS Cloud Operations and Security documentation specifies that for Amazon CloudFront, automatic certificate renewal is only supported for certificates issued by AWS Certificate Manager (ACM). When a certificate is managed by ACM and validated through DNS validation, ACM automatically renews the certificate before expiration without requiring manual intervention.
Option A ensures that the certificate is issued and managed by ACM, enabling full integration with CloudFront. Option E (DNS validation) is essential for automation; AWS performs revalidation automatically as long as the DNS validation record remains in place.
By contrast, email validation (Option D) requires manual user confirmation upon renewal, which prevents automatic renewals. Certificates issued by third-party certificate authorities (Option B) are manually managed and must be reimported into ACM after renewal. CloudFront does not have a direct feature (Option C) to renew certificates; it relies on ACM's lifecycle management.
Thus, combining ACM-issued certificates (A) with DNS validation (E) ensures continuous, automated renewal with no downtime or human action required.
Mabel
6 months agoAlexis
6 months agoCherelle
7 months agoVal
7 months agoLeonor
7 months agoLaticia
7 months agoMicaela
7 months agoCurtis
7 months agoCarla
8 months agoMignon
8 months agoRolf
8 months agoMarsha
8 months agoDexter
8 months agoLucy
8 months agoShonda
9 months agoJanessa
9 months agoCaitlin
9 months agoMy
9 months agoPaola
10 months agoSherly
10 months agoMarci
10 months agoLacey
10 months agoIra
10 months agoNadine
5 months agoBreana
5 months agoEmeline
5 months agoCeleste
6 months agoHelga
9 months ago