exam questions

Exam AWS Certified Developer Associate All Questions

View all questions & answers for the AWS Certified Developer Associate exam

Exam AWS Certified Developer Associate topic 1 question 6 discussion

Exam question from Amazon's AWS Certified Developer Associate
Question #: 6
Topic #: 1
[All AWS Certified Developer Associate Questions]

A developer is configuring an Amazon CloudFront distribution for a new application to provide encryption in transit. The application is running in the eu-west-1
Region. The developer creates a new certificate in AWS Certificate Manager (ACM) in eu-west-1, but the certificate is not visible in the CloudFront distribution settings.
What should the developer do to fix this problem?

  • A. Create the certificate for the domain in the same Region as the application. Ensure that the alternate domain name (CNAME) in the distribution settings matches the domain name in the certificate.
  • B. Create the certificate in the eu-west-1 Region. Ensure that the alternate domain name (CNAME) in the distribution settings matches the domain name in the certificate.
  • C. Recreate the CloudFront distribution in the same Region as the certificate.
  • D. Specify the ACM certificate name as the default root object of the CloudFront distribution.
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Spamuel
Highly Voted 2 years, 7 months ago
Selected Answer: B
Agreed with PVR that it's a typo. Option B changed to "us-east-1"
upvoted 15 times
AWSdeveloper08
1 year, 9 months ago
yes, this should be eu-east-1
upvoted 1 times
RaidenKurosaki
1 year, 8 months ago
us-east-1 not eu-east-1
upvoted 2 times
...
...
...
JOL86
Highly Voted 2 years, 7 months ago
Part of me thinks there is a typo somewhere. To import an ACM into Cloudfront, the ACM needs to be in the us-east-1 region: https://docs.aws.amazon.com/AmazonCloudFront/latest/DeveloperGuide/cnames-and-https-requirements.html#https-requirements-aws-region None of these answers make sense at the moment
upvoted 12 times
...
sumanshu
Most Recent 4 months, 1 week ago
Selected Answer: B
A) Eliminated - ACM certificate must be created in the us-east-1 Region, not eu-west-1. B) Probably Typo in region name -If it is us-east-1. Then correct C) Eliminated - CloudFront is a global service, so its distributions are not tied to a specific region. D) Eliminated- The default root object specifies which file (e.g., index.html) is served when the user accesses the distribution's root URL. It has nothing to do with certificates or encryption.
upvoted 1 times
...
JonasKahnwald
5 months, 1 week ago
Selected Answer: B
B has a typo and should be changed to "us-east-1": https://docs.aws.amazon.com/AmazonCloudFront/latest/DeveloperGuide/cnames-and-https-requirements.html#https-requirements-aws-region
upvoted 1 times
...
LaHi
1 year, 2 months ago
As of now, I think the question lost it's meaning, as there is 3 times 'eu-west-1' (including in answer B) mentioned. I think, the actual problem given in the question to resolve got lost.
upvoted 1 times
...
SD_CS
1 year, 3 months ago
Selected Answer: B
It should be B with the typo that the region where the cert should be installed is us-east-1
upvoted 1 times
...
rcaliandro
1 year, 10 months ago
Selected Answer: B
Guys I read many times the questions and the answers but I can't find any correct answer. I'm voting B as long as in the answer we change "us-west-1" to "us-east-1" (also because it is wrtitten that the user already created the certificate in us-west-1 and it is not working. According to AWS, to install a certficate to a CloudFront distribution, you need to: - request or import a certificate to ACM - You must request the certificate in the US East (N. Virginia) Region (i.e. us-east-1) - have the rigth permissions - key length must be 1024 or 2048 bits and cannot exceed 2048 bits. (https://repost.aws/knowledge-center/install-ssl-cloudfront)
upvoted 2 times
...
rcaliandro
1 year, 10 months ago
Selected Answer: B
Guys I read many times the questions and the answers but I can't find any correct answer. I'm voting B
upvoted 1 times
...
Krt5894
2 years, 2 months ago
Selected Answer: B
It should be B
upvoted 1 times
...
Tera_911
2 years, 5 months ago
It's B (typo ---> us -east-1). Explanation: To use an ACM certificate with Amazon CloudFront, you must request or import the certificate in the US East (N. Virginia) region. ACM certificates in this region that are associated with a CloudFront distribution are distributed to all the geographic locations configured for that distribution. Reference: https://docs.aws.amazon.com/acm/latest/userguide/acm-regions.html?opt_id=undefined
upvoted 4 times
...
dark_cherrymon
2 years, 5 months ago
Selected Answer: B
there's a typo here "To use an ACM certificate with CloudFront, you must request or import the certificate in the US East (N. Virginia) region."- https://docs.aws.amazon.com/acm/latest/userguide/acm-services.html
upvoted 1 times
...
cloud_collector
2 years, 5 months ago
Selected Answer: B
To add an alternate domain name (CNAME) to a CloudFront distribution, you must attach to your distribution a trusted, valid SSL/TLS certificate that covers the alternate domain name. This ensures that only people with access to your domain’s certificate can associate with CloudFront a CNAME related to your domain. https://docs.aws.amazon.com/AmazonCloudFront/latest/DeveloperGuide/CNAMEs.html#alternate-domain-names-requirements
upvoted 1 times
...
PVR
2 years, 7 months ago
Looks like the second option has a typo. If it were changed to us-east-1, then it would be correct answer.
upvoted 6 times
peyto
2 years, 7 months ago
correct
upvoted 1 times
...
...
sidvic
2 years, 7 months ago
Selected Answer: C
Very Tricky question for me. I found this https://www.radishlogic.com/aws/cloudfront/how-to-solve-ssl-certificate-not-showing-in-aws-cloudfront/ but in the question already says that the certification in in the same region of cloudfront. I vote for c
upvoted 3 times
SuperPiski
2 years, 7 months ago
But cloudfront is a global service...so no region is needed.
upvoted 4 times
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago