Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Amazon Exam SOA-C03 Topic 3 Question 4 Discussion

Actual exam question for Amazon's SOA-C03 exam
Question #: 4
Topic #: 3
[All SOA-C03 Questions]

A CloudOps engineer is configuring an Amazon CloudFront distribution to use an SSL/TLS certificate. The CloudOps engineer must ensure automatic certificate renewal.

Which combination of steps will meet this requirement? (Select TWO.)

Show Suggested Answer Hide Answer
Suggested Answer: A, E

The AWS Cloud Operations and Security documentation specifies that for Amazon CloudFront, automatic certificate renewal is only supported for certificates issued by AWS Certificate Manager (ACM). When a certificate is managed by ACM and validated through DNS validation, ACM automatically renews the certificate before expiration without requiring manual intervention.

Option A ensures that the certificate is issued and managed by ACM, enabling full integration with CloudFront. Option E (DNS validation) is essential for automation; AWS performs revalidation automatically as long as the DNS validation record remains in place.

By contrast, email validation (Option D) requires manual user confirmation upon renewal, which prevents automatic renewals. Certificates issued by third-party certificate authorities (Option B) are manually managed and must be reimported into ACM after renewal. CloudFront does not have a direct feature (Option C) to renew certificates; it relies on ACM's lifecycle management.

Thus, combining ACM-issued certificates (A) with DNS validation (E) ensures continuous, automated renewal with no downtime or human action required.


Contribute your Thoughts:

Sherly
2 hours ago
I'm pretty confident that A and E are the way to go. Using an ACM certificate and configuring DNS validation should cover the automatic renewal requirement.
upvoted 0 times
...
Marci
6 days ago
I'm a bit confused about the difference between options C and D. Do I need to configure both email and DNS validation?
upvoted 0 times
...
Lacey
11 days ago
Okay, I think I've got this. A and E seem like the right combination to ensure automatic renewal.
upvoted 0 times
...
Ira
17 days ago
Hmm, this one seems tricky. I'll need to think through the options carefully.
upvoted 0 times
...

Save Cancel