Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.
exam questions

Exam AWS Certified Solutions Architect - Associate SAA-C03 All Questions

View all questions & answers for the AWS Certified Solutions Architect - Associate SAA-C03 exam

Exam AWS Certified Solutions Architect - Associate SAA-C03 topic 1 question 577 discussion

A company uses an Amazon CloudFront distribution to serve content pages for its website. The company needs to ensure that clients use a TLS certificate when accessing the company's website. The company wants to automate the creation and renewal of the TLS certificates.

Which solution will meet these requirements with the MOST operational efficiency?

  • A. Use a CloudFront security policy to create a certificate.
  • B. Use a CloudFront origin access control (OAC) to create a certificate.
  • C. Use AWS Certificate Manager (ACM) to create a certificate. Use DNS validation for the domain.
  • D. Use AWS Certificate Manager (ACM) to create a certificate. Use email validation for the domain.
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
Bmaster
Highly Voted 1 year, 3 months ago
C is correct. "ACM provides managed renewal for your Amazon-issued SSL/TLS certificates. This means that ACM will either renew your certificates automatically (if you are using DNS validation), or it will send you email notices when expiration is approaching. These services are provided for both public and private ACM certificates." https://docs.aws.amazon.com/acm/latest/userguide/managed-renewal.html
upvoted 9 times
...
Guru4Cloud
Highly Voted 1 year, 3 months ago
Selected Answer: C
The key reasons are: AWS Certificate Manager (ACM) provides free public TLS/SSL certificates and handles certificate renewals automatically. Using DNS validation with ACM is operationally efficient since it automatically makes changes to Route 53 rather than requiring manual validation steps. ACM integrates natively with CloudFront distributions for delivering HTTPS content. CloudFront security policies and origin access controls do not issue TLS certificates. Email validation requires manual steps to approve the domain validation emails for each renewal.
upvoted 5 times
...
awsgeek75
Most Recent 10 months, 2 weeks ago
Selected Answer: C
For me, C is the only realistic option as I don't think you can do AB without a lot of complexity. D just makes no sense.
upvoted 1 times
...
ibu007
1 year, 2 months ago
Selected Answer: C
Use AWS Certificate Manager (ACM) to create a certificate. Use DNS validation for the domain
upvoted 3 times
...
chen0305_099
1 year, 2 months ago
Selected Answer: C
C 似乎是正確的
upvoted 3 times
...
Kiki_Pass
1 year, 3 months ago
Selected Answer: C
"DNS Validation is preferred for automation purposes" -- Stephane's course on Udemy
upvoted 2 times
...
mrsoa
1 year, 3 months ago
Selected Answer: C
C seems to be correct
upvoted 1 times
...
nananashi
1 year, 3 months ago
I think the general product uses DNS rather than email to automate, is the given answer correct?
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...