A CloudOps engineer is configuring an Amazon CloudFront distribution to use an SSL/TLS certificate. The CloudOps engineer must ensure automatic certificate renewal.
Which combination of steps will meet this requirement? (Select TWO.)
The AWS Cloud Operations and Security documentation specifies that for Amazon CloudFront, automatic certificate renewal is only supported for certificates issued by AWS Certificate Manager (ACM). When a certificate is managed by ACM and validated through DNS validation, ACM automatically renews the certificate before expiration without requiring manual intervention.
Option A ensures that the certificate is issued and managed by ACM, enabling full integration with CloudFront. Option E (DNS validation) is essential for automation; AWS performs revalidation automatically as long as the DNS validation record remains in place.
By contrast, email validation (Option D) requires manual user confirmation upon renewal, which prevents automatic renewals. Certificates issued by third-party certificate authorities (Option B) are manually managed and must be reimported into ACM after renewal. CloudFront does not have a direct feature (Option C) to renew certificates; it relies on ACM's lifecycle management.
Thus, combining ACM-issued certificates (A) with DNS validation (E) ensures continuous, automated renewal with no downtime or human action required.
Mabel
2 months agoAlexis
2 months agoCherelle
2 months agoVal
2 months agoLeonor
3 months agoLaticia
3 months agoMicaela
3 months agoCurtis
3 months agoCarla
3 months agoMignon
4 months agoRolf
4 months agoMarsha
4 months agoDexter
4 months agoLucy
4 months agoShonda
4 months agoJanessa
5 months agoCaitlin
5 months agoMy
5 months agoPaola
5 months agoSherly
6 months agoMarci
6 months agoLacey
6 months agoIra
6 months agoNadine
25 days agoBreana
1 month agoEmeline
1 month agoCeleste
1 month agoHelga
5 months ago